
Senior Infrastructure Endpoint Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Design, implement, and oversee endpoint platforms utilizing Microsoft Intune, Kandji (Iru), and Fleet across diverse macOS and Windows environments.
• Manage the complete device lifecycle including onboarding, offboarding, compliance, and refresh across all supported MDM platforms.
• Set up automated provisioning using Autopilot and Apple Business Manager (DEP).
• Configure and enforce industry-standard hardening baselines for both macOS and Windows through Intune, Kandji/Iru, and Fleet.
• Administer EDR/XDR platforms including CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint, which encompasses sensor/agent deployment, policy configuration, policy tuning, and exclusion management.
• Oversee vulnerability exposure management utilizing CrowdStrike Spotlight, SentinelOne Vulnerability Management, or Microsoft Defender Vulnerability Management, while driving remediation SLAs.
• Lead alert triage and investigation processes across EDR platforms, collaborating with the security team on escalations and responses.
• Develop and maintain host groups, device policies, and containment workflows across any EDR platform utilized by customers.
• Drive the endpoint and security tooling roadmap, assessing, consolidating, and transitioning between EDR/MDM platforms as necessary.
• Make and justify platform and architecture choices (build vs. buy, consolidate vs. diversify) supported by data - including cost, risk reduction, and operational impact.
• Administer Server Patch and Policy Management via WSUS/AWS SSM.
• Integrate endpoint platforms with Okta, Entra ID, and other identity providers.
• Automate endpoint configuration and application lifecycle through scripting (PowerShell, Bash, Python).
• Troubleshoot intricate endpoint issues spanning OS, network, and identity layers.
• Support secure access workflows including VPN and certificate-based Wi-Fi authentication.
• Create and uphold documentation, runbooks, and standards.
• Collaborate with Security, IAM, and Cloud teams to ensure alignment of endpoint strategy with broader platform architecture.
• Present technical recommendations and roadmap considerations to both customer and internal leadership, supported by metrics and data.
• Contribute to ongoing improvements within your team and throughout EverOps’ customer base.
• A minimum of 6 years of experience in endpoint engineering, IT infrastructure, or a related field, demonstrating seniority in managing roadmaps and making technical decisions.
• Extensive hands-on expertise across MDM platforms, including:
• Microsoft Intune
• Kandji (Iru), JAMF
• Fleet
• Enterprise-scale macOS and Windows administration.
• Profound hands-on experience with EDR/XDR platforms, including:
• CrowdStrike Falcon - administration, policy tuning, and Falcon modules beyond EDR such as identity and vulnerability management.
• SentinelOne - agent deployment, policy configuration, and Singularity platform administration.
• Microsoft Defender for Endpoint - onboarding, policy management, and integration with the Microsoft 365 Defender ecosystem.
• Strong understanding of endpoint security encompassing patching, compliance, EDR, vulnerability management, and alert triage.
• Familiarity with identity platforms such as Okta, Entra ID (Azure AD), or similar.
• Understanding of Zero Trust principles and conditional access.
• Experience in scripting (PowerShell, Bash, or Python).
• Excellent troubleshooting capabilities across endpoint, identity, and network layers.
• Working knowledge of AWS and/or Azure environments.
• Experience with Microsoft Autopilot and Apple Business Manager.
• Familiarity with hybrid identity setups (Active Directory + Entra ID, GPOs).
• Proven ability to assess, compare, and recommend endpoint/security platform choices based on data - including cost, risk, and operational metrics - rather than personal preference alone.
• Experience in presenting technical strategies and tradeoffs to leadership or customer stakeholders.
• Fully Remote Workplace: We have embraced remote work since Day 1!
• Unlimited Paid Time Off.
• Equity: Become a genuine owner of the company.
• 401k plan with company contributions and sponsored healthcare.
• Professional Growth: Access to training and certification programs to propel your career.
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.