
Endpoint Engineer – Tier 2
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in United States.
• Oversee Configuration Manager collections, applications, packages, and task sequences, which include OS deployment and driver management.
• Manage Intune device compliance policies, configuration profiles, and security baselines across Windows, iOS, Android, and macOS platforms.
• Administer application deployment and lifecycle processes, including app protection policies and the availability of the Company Portal.
• Maintain certificate profiles (SCEP/PKCS) and VPN configurations, while monitoring certificate health, expiration, and renewal.
• Oversee Conditional Access and multifactor authentication compliance, investigating policy enforcement and configuration drift issues.
• Support the integration of Microsoft Defender for Endpoint and engage in security response activities, including selective device wipe.
• Resolve assigned tickets within the SLA, escalate as necessary, and adhere to change management procedures within client environments.
• Create and maintain as-built documentation and standard operating procedures for the environments being supported.
• Contribute technical insights to quarterly client reviews regarding compliance posture, policy effectiveness, and operational trends.
• Identify configuration gaps, operational risks, and supportability issues, providing recommendations for optimization or remediation.
• Act as the escalation point for endpoint issues that exceed Tier 1 scope.
• Identify when client requests exceed managed services scope and direct them appropriately.
• 3–5 years of practical experience in administering Microsoft Configuration Manager (SCCM/MECM) in a production setting, including software update management and client health troubleshooting.
• Familiarity with Configuration Manager site infrastructure, including management points, distribution points, software update points, and boundary groups.
• Proven experience in administering Microsoft Intune, covering enrollment, compliance policies, configuration profiles, and application management across diverse device platforms.
• Practical knowledge of Conditional Access, multifactor authentication, and their relationship with device compliance.
• Experience with certificate-based authentication (SCEP/PKCS) and VPN profile configuration.
• Capability to diagnose endpoint issues through log analysis and structured troubleshooting instead of default escalation.
• Experience providing support in a managed services or multi-client environment, including ticket queue management, SLA adherence, and change management.
• Strong written communication skills sufficient for producing client-facing documentation and remediation recommendations.
• Good judgment in differentiating between routine operational tasks and requests necessitating separately scoped professional services.
• Microsoft certifications such as MD-102 (Endpoint Administrator) or equivalent demonstrated experience are preferred.
• All Sparkhound employees are expected to manage client and company data responsibly, adhere to information security policies, complete necessary security training, and promptly report any suspected incidents or policy violations.
• Employees are responsible for maintaining accurate documentation and following change management procedures while working in client environments.
• Competitive salary and performance-based incentives.
• Comprehensive health, dental, and vision insurance.
• Flexible work hours and remote work options.
• Opportunities for professional development and certification reimbursement.
• Supportive and inclusive work environment.
Northrop Grumman
Thermo Systems
Thermo Systems
Thermo Systems
Get handpicked remote jobs straight to your inbox weekly.