
Intune Architect
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in United States.
• Design and spearhead the comprehensive Microsoft Intune architecture for a substantial federal enterprise.
• Implement secure modern management frameworks across Windows, iOS/iPadOS, and Android platforms.
• Establish security baselines and conditional access protocols.
• Develop a migration and co-management strategy for Blackberry UEM to Intune utilizing SCCM/Configuration Manager.
• Set up technical governance, standards, frameworks, and protocols.
• Collaborate with Security, Identity, Networking, Client Engineering, and PMO teams.
• Deliver an endpoint platform aligned with Zero Trust principles.
• Oversee pilots, wave plans, and presentations for executives.
• Create thorough technical documentation and effectively manage stakeholders.
• At least 8 years of experience in a relevant field.
• 7–10+ years in endpoint management.
• 3–5+ years of experience architecting Intune at an enterprise scale, including programs with over 10,000 devices or federal initiatives.
• Expert understanding of Intune and modern management, covering Autopilot, device compliance, configuration profiles, Win32/MSIX/MAM, update rings, and RBAC/scopes.
• Experience in designing Conditional Access, governing BitLocker, implementing Microsoft Security Baselines, integrating Defender for Endpoint, and managing threat and vulnerability workflows.
• Proficient in Azure AD/Entra ID tenant administration, user/group design, SSO utilizing SAML/OIDC, device identities, and certificate/PKI integration.
• Skills in PowerShell scripting, configuration-as-code approach, reusable modules, and reporting.
• Familiarity with MAM/app protection policies and conditional launch controls.
• Practical experience in transitioning SCCM/Configuration Manager to cloud-based Intune, defining co-management workloads, and executing phased cutovers.
• Capability to lead pilots, wave plans, and executive-level presentations.
• Strong documentation and stakeholder management abilities.
• Preferred: Knowledge of Zero Trust architecture and NIST 800-53 endpoint control mapping; familiarity with FedRAMP/ATO processes.
• Preferred: Experience in Win32 packaging at scale, app remediation, and Autopatch/update-ring optimization.
• Preferred: Advanced skills in Conditional Access design and Entra ID P2 features.
• Preferred: Expertise in Defender for Endpoint advanced hunting using KQL, ASR, tamper protection, and automated response playbooks.
• Preferred: Experience with enterprise certificate management, SCEP/PKCS, Wi-Fi/VPN profiles, and network prerequisites.
• Preferred: Knowledge of Terraform/Bicep or pipeline-driven deployments and Git-based governance.
• Preferred: Experience in incident response and disaster-recovery runbooks, executive communications, and change management.
• Eligibility for Public Trust or higher clearance.
• Previous experience with federal clients.
• 401(k) matching.
• Dental insurance.
• Health insurance.
• Paid time off.
• Parental leave.
• Vision insurance.
Illumination Works
Salesforce
Climb Channel Solutions NA
Get handpicked remote jobs straight to your inbox weekly.