
Endpoint Engineer – AI Desktop Deployment
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in United States.
• Execute enterprise desktop engineering for Windows 10 and Windows 11, which includes operating system configuration, deployment, lifecycle management, and troubleshooting.
• Manage and design Microsoft Intune / Microsoft Endpoint Manager environments for device enrollment, configuration, application deployment, compliance, and endpoint security.
• Create, implement, maintain, and resolve issues with Group Policy Objects (GPOs) that support enterprise security, configuration, and operational needs.
• Develop and uphold standardized Windows endpoint configurations, deployment methodologies, and engineering documentation.
• Design and sustain Windows provisioning and deployment solutions, such as Autopilot and automated device enrollment when applicable.
• Assess Windows updates, feature releases, drivers, firmware, and endpoint configuration changes prior to production deployment.
• Assist with endpoint modernization initiatives and transition from legacy endpoint-management technologies to cloud-managed or hybrid-management structures.
• Automate repetitive endpoint administration and configuration tasks through PowerShell and other authorized scripting tools.
• Enforce and maintain device compliance and Conditional Access controls that align with the Zero Trust device framework.
• Engineer, deploy, and maintain STIG-compliant endpoint security baselines for Windows systems.
• Implement and uphold DISA STIG, organizational security baselines, and relevant federal endpoint-hardening standards.
• Configure Intune compliance policies, configuration profiles, endpoint security policies, and security baselines for government settings.
• Support endpoint management functionalities within Microsoft Government Cloud environments, including GCC, GCC High, or similar environments as necessary.
• Integrate endpoint posture and device-compliance signals with identity and access control solutions.
• Ensure that only authorized, managed, compliant, and securely configured devices can access protected enterprise resources.
• Implement endpoint controls that support Zero Trust principles, including device identity, continuous verification, least privilege, and risk-based access.
• Collaborate with identity teams on Microsoft Entra ID device registration, join models, Conditional Access, and authentication requirements.
• Support Microsoft Defender for Endpoint or comparable endpoint detection, security telemetry, vulnerability management, and response capabilities.
• Address endpoint vulnerabilities, configuration findings, compliance exceptions, and deficiencies in security controls.
• Assist in collecting evidence and preparing technical documentation for security assessments, audits, authorization activities, and continuous monitoring.
• Support endpoint configurations that align with relevant NIST, FISMA, FedRAMP, CISA, DoD, or agency-specific security requirements, as applicable to the environment.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical field.
• Experience in deploying Microsoft Copilot, AI assistants, or other enterprise AI desktop applications.
• Understanding of enterprise AI governance, data-loss prevention, information protection, and access-control considerations for generative AI tools.
• Experience in evaluating endpoint hardware and software readiness for AI-enabled workloads.
• Familiarity with Windows AI capabilities, AI-enabled productivity platforms, or locally executed AI workloads.
• Experience in integrating endpoint-management telemetry with security, identity, IT operations, or SIEM platforms.
• Proficient in Windows Autopilot, Microsoft Graph, PowerShell automation, or proactive remediation technologies.
• Experience with Microsoft Intune and Microsoft Endpoint Manager.
• Familiarity with Windows 10/11, Group Policy, application packaging, and Zero Trust endpoint controls.
• Knowledge of device compliance and Conditional Access mechanisms.
• Experience in engineering STIG-compliant Windows endpoint security baselines.
• Understanding of DISA STIG, organizational security baselines, and applicable federal endpoint-hardening standards.
• Experience with Microsoft Government Cloud environments, including GCC or GCC High, as necessary.
• Knowledge of Microsoft Entra ID device registration, join models, Conditional Access, and authentication requirements.
• Experience with Microsoft Defender for Endpoint or equivalent endpoint detection, security telemetry, vulnerability management, and response capabilities.
• Preferred: Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) — highly desired.
• Preferred: AWS Certified Cloud Practitioner — desired only if the role supports or integrates with AWS environments.
• Competitive salary, paid bi-monthly.
• Comprehensive medical coverage.
• Full coverage of medical premiums by True Zero.
• Company-wide incentives for new business initiatives.
• Contribution incentives (e.g., white papers, blog posts, internal webinars, etc.).
• Three weeks of PTO plus 11 paid holidays annually.
• 401k program with a 100% company match on the first 4%.
• Monthly reimbursement for cell phone and home internet expenses.
• Paternity and maternity leave.
• Investment in training and certifications to enhance and expand your technical abilities.
Creative Chaos
WCG
Ford Motor Company
Carbon60
Get handpicked remote jobs straight to your inbox weekly.