eTeam Inc. logo

End Point SME/Engineer - Microsoft Intune

eTeam Inc.
  • Weymouth, MA
  • Instant Apply
3 days ago
eTeam Inc.

Job Description

Title: End Point SME/Engineer - Microsoft Intune
Location: Boston, MA - Remote/Hybrid/Onsite
Duration: 6+ Months of Contract


Must Have:
Microsoft Configuration Manager (SCCM) Deep Hands-On Experience
Microsoft Intune / Modern Endpoint Management
Windows OS Deployment & Imaging
Advanced PowerShell Automation

Position Summary
The Senior Windows Endpoint Engineer owns the Windows client end to end, from the bare-metal build to the experience the user has on the first morning and every morning after. The role is accountable for the image and task sequence architecture in Microsoft Configuration Manager, the Group Policy and configuration estate that governs the desktop, and the PowerShell that automates, hardens and self-heals it. The role spans both management planes: the on-premises ConfigMgr estate that builds the device today, and the Microsoft Intune and cloud-native stack the estate is moving to, provisioning, policy, application delivery and patching from the cloud. This is a hands-on build engineering role, not console administration: success is a device that provisions predictably, applies its configuration without conflict, performs well on day one, and stays that way through patch, upgrade and refresh cycles, regardless of which plane manages it.
Key Responsibilities

  • Operating system deployment and task sequence engineering. Own Windows build design across imaging, drivers, WinPE, task sequences, upgrades, state migration, BitLocker and firmware integration. Troubleshoot deployment failures from logs and make fixes repeatable.
  • Configuration Manager platform engineering. Engineer and maintain ConfigMgr site health, roles, boundaries, distribution points, PXE, boot images, client settings, collections, software updates and reporting. Manage co-management and workload transition to Intune.
  • Modern endpoint management with Intune and cloud management. Build and manage Intune capabilities for Autopilot, enrollment, Windows policy, compliance, security baselines, scripts and proactive remediations. Migrate GPO and ConfigMgr workloads to cloud management with clear validation.
  • Cloud patch and update management. Own Windows servicing through Windows Update for Business, Autopatch where adopted, update rings, deferrals, expedited updates, feature updates, driver policy and compliance reporting. Optimize update delivery for remote and bandwidth-constrained sites.
  • Cloud application delivery. Package and deploy Intune Win32, Microsoft Store, Enterprise App Catalog and Microsoft 365 Apps with reliable detection, requirements, dependencies, supersedence and assignment strategy. Convert ConfigMgr applications to cloud-ready equivalents.
  • Group Policy and configuration management. Own the GPO estate, including OU structure, filtering, precedence, ADMX, preferences and documented baselines. Rationalize legacy policy, resolve conflicts, and map policies to Intune where appropriate.
  • PowerShell automation and configuration scripting. Build production-grade PowerShell for provisioning, configuration, detection, remediation, reporting and drift control. Ensure scripts are logged, error-handled, idempotent, signed and source-controlled.
  • Application packaging and delivery. Own application packaging across MSI, MSIX, App-V where required, and Intune Win32 apps. Standardize silent installs, transforms, uninstall logic, rollback testing, catalog quality and self-service delivery.
  • Windows platform, identity and backend integration. Engineer endpoint dependencies including Active Directory, Entra ID, domain join, DNS, DHCP, PKI, WSUS, activation, Windows Hello for Business and LAPS. Understand network and content-delivery behavior supporting branch and remote builds.
  • Security, hardening and patch engineering. Implement Windows security baselines, BitLocker, ASR, WDAC or AppLocker, Credential Guard, exploit protection and local admin controls. Maintain patch compliance, feature update readiness and remediation of non-compliant devices.
  • End-user experience engineering. Measure and improve provisioning, OOBE, boot, sign-in, policy processing, application reliability and profile performance. Use telemetry, targets and proactive remediation to reduce tickets and technician touch.
  • Operations, change and technical leadership. Lead change, pilot planning, validation, backout, Tier 3/4 escalation and root-cause analysis. Maintain clear documentation, runbooks, design records, roadmaps and technical debt priorities.
  1. Required Qualifications
  • 7+ years in Windows endpoint or desktop engineering, with significant ownership of the build and configuration estate in a large or complex environment.
  • Deep hands-on Microsoft Configuration Manager engineering: site administration, OS deployment, task sequence authoring and debugging, application and update deployment, collections, boundaries and content distribution.
  • Demonstrable mastery of Windows OS deployment imaging and image servicing, WinPE and boot image customization, driver management, USMT, and in-place upgrade at scale.
  • Hands-on Microsoft Intune engineering for Windows: Autopilot provisioning, settings catalog and ADMX-backed policy, compliance policies, platform scripts and proactive remediations, filters and scope tags.
  • Cloud patch and update management with Windows Update for Business ring and deferral design, feature update control, expedited updates, and compliance reporting and familiarity with Windows Autopatch.
  • Cloud application delivery through Intune Win32 apps, including packaging, detection and requirement rules, supersedence, and assignment strategy.
  • Advanced Group Policy engineering: policy architecture, filtering, precedence and conflict resolution, ADMX central store, preferences, and systematic rationalization of legacy policy.
  • Production-grade PowerShell scripting for configuration, automation, detection and remediation, including error handling, logging, code signing and source control.
  • Strong Windows client internals and troubleshooting: registry, services, WMI, event and setup logs, performance analysis, profile and logon behavior.
  • Application packaging across MSI, Win32 and MSIX, including detection logic, transforms and supersedence.
  • Working knowledge of the supporting backend: Active Directory, Entra ID, DNS, DHCP, PKI and certificate autoenrollment, WSUS and update infrastructure, and activation services.
  • Windows security baseline and hardening experience, including BitLocker, application control, ASR and patch compliance management.
  • Enterprise change, incident and problem discipline, high-quality technical documentation, and clear communication to technical and nontechnical audiences.

Numbers & Facts

LocationWeymouth, MA
IndustryOther/Not Classified
Company Size100 to 499 employees
Year Founded1998
Websitewww.eteaminc.com

About Company

Looking for a great job? Join eTeam. We’re looking for talented staffing professionals to join our staff. We also provide contract assignments and full-time jobs at Fortune 2000 Companies. We’ve been named one of the best companies to work for by Staffing Industry Analysts and New Jersey Business.

Skills

  • Automationunmatched
  • Build Managementunmatched
  • Cloud Applicationsunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Firmwareunmatched
  • Configuration Managementunmatched
  • Conflict Resolutionunmatched
  • Content Delivery/Distributionunmatched
  • DHCP (Dynamic Host Configuration Protocol)unmatched
  • DNS (Domain Name System)unmatched
  • Debugging Skillsunmatched
  • Desktop PCunmatched
  • Device Driversunmatched
  • Digital Certificatesunmatched
  • Documentationunmatched
  • Engineering Managementunmatched
  • Enterprise Applicationsunmatched
  • Error Handlingunmatched
  • Identify Issuesunmatched
  • Logic Testingunmatched
  • Maintain Complianceunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Operating Systemunmatched
  • Microsoft Windows System Internals/Programmingunmatched
  • Operating Systemsunmatched
  • Performance Analysisunmatched
  • Public Key Infrastructure (PKI)unmatched
  • Root Cause Analysisunmatched
  • Scripting (Scripting Languages)unmatched
  • Service Deliveryunmatched
  • Software Administrationunmatched
  • Software Patchesunmatched
  • Source Code/Configuration Management (SCM)unmatched
  • System Center Configuration Manager (SCCM)unmatched
  • System Integration (SI)unmatched
  • Systems Administration/Managementunmatched
  • Technical Leadershipunmatched
  • Technical Writingunmatched
  • Telemetryunmatched
  • User Interface/Experience (UI/UX)unmatched
  • Validation Planunmatched
  • WMI API (Windows Management Instrumentation)unmatched
  • Win32 API (Application Programming Interface)unmatched
  • Windows PowerShellunmatched
  • Windows Server Update Services (WSUS)unmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder