
Principal Architect, IT Corporate Services
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in Florida, +7 more states.
• Develop and implement a comprehensive enterprise endpoint architecture strategy, governance standards, and technology roadmaps for Windows, macOS, and mobile platforms.
• Take ownership of operating system standards for Windows and macOS, including upgrade planning, feature adoption, and establishing endpoint configuration baselines.
• Lead the planning and execution of endpoint technology for acquisitions, divestitures, new office openings and consolidations, migrations, and significant device refresh initiatives.
• Act as the technical authority for Microsoft Intune and the Modern Endpoint Management strategy, covering architecture, design, implementation, governance, optimization, and operational management.
• Manage technologies related to Windows Autopilot, Apple Business Manager, Entra ID device registration, NinjaOne, Addigy, and other endpoint management solutions.
• Design and maintain processes for endpoint enrollment, zero-touch provisioning, imaging, software distribution, patching, and device management.
• Drive the management and automation of cloud-based endpoints.
• Design, test, implement, and govern Group Policies in Active Directory and establish endpoint configuration standards.
• Serve as the final technical escalation point for intricate issues related to desktop engineering, application packaging, imaging, patching, Group Policy, software distribution, device enrollment, and endpoint management.
• Provide technical guidance to internal teams and service providers without direct supervisory responsibilities.
• Establish and uphold an enterprise mobility strategy, standards, governance, and technology roadmap.
• Function as the primary technology and vendor owner for T-Mobile.
• Define standards for mobile devices, operating systems, accessories, enrollment, eSIM, provisioning, refresh, replacement, recovery, and retirement.
• Collaborate with Cybersecurity and operational teams on security, compliance, risk, and business continuity requirements.
• Coordinate endpoint security controls through Group Policy, Intune, and operating system configurations.
• Manage BitLocker administration and governance and collaborate on vulnerability remediation and Zero Trust initiatives.
• Participate in major endpoint-related and security incidents, leading efforts in investigation, containment, remediation, and recovery.
• Contribute to endpoint observability, compliance reporting, audit support, and operational metrics.
• Lead the evaluation, testing, selection, standardization, and lifecycle planning for enterprise end-user technologies.
• Oversee strategic endpoint hardware vendors, including Dell and Apple, and engage in vendor evaluations and contract negotiations.
• Manage the complete endpoint lifecycle, encompassing deployment, refresh, recovery, secure disposition, asset recovery, and eWaste vendors.
• Administer licensing and technology governance for endpoint software such as Adobe Acrobat and Snagit.
• Develop and maintain scripting solutions in PowerShell and other languages for provisioning, administration, software deployment, patching, remediation, and automation.
• Enhance automation and standardization to optimize endpoint operations.
• Evaluate new endpoint and mobility technologies, lead pilot projects, and recommend solutions.
• Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent relevant experience.
• A minimum of 10 years in progressive information technology roles, with significant experience in endpoint architecture, desktop engineering, endpoint management, or technical leadership in End User Computing.
• Proficient in supporting large enterprise environments across Windows, macOS, and mobile platforms, including endpoint standards, operating system lifecycle management, configuration baselines, application packaging, software distribution, patching, imaging, and provisioning.
• Extensive hands-on expertise with Microsoft Intune, Windows Autopilot, Apple Business Manager, Entra ID device registration, Group Policy, BitLocker, NinjaOne, and Addigy.
• Strong skills in PowerShell scripting.
• Experience with APIs and other automation frameworks is preferred.
• Proven track record in establishing mobile device standards and managing relationships with carriers and vendors.
• Experience in governing mobile enrollment, provisioning, lifecycle, and support technologies.
• Experience in acting as a technology owner for strategic vendors and managing hardware standards, refresh programs, software licensing, asset recovery, secure disposition, and eWaste services.
• Experience in implementing endpoint security controls and collaborating with Cybersecurity on vulnerability remediation, encryption, security incidents, audits, and Zero Trust initiatives.
• Exceptional organizational, analytical, decision-making, communication, and interpersonal skills.
• Ability to influence technical direction, coordinate across teams and service providers, and articulate complex concepts to both technical and business stakeholders.
• Relevant certifications in endpoint administration and management are preferred but not mandatory.
• Willingness to participate in scheduled non-business hours for implementation and maintenance activities, as well as major incident or security incident responses when necessary.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance plans.
• Opportunities for professional development and career advancement.
• Flexible work arrangements and a supportive work environment.
Backblaze
CVS Health
Muck Rack
Get handpicked remote jobs straight to your inbox weekly.