This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an experienced Senior Engineer to design, implement, and manage secure, scalable endpoint solutions across Windows and mobile (iOS and Android). The role focuses on modern device management using Microsoft technologies, including Autopilot, Intune, and Entra ID, while ensuring strong security controls through Conditional Access and application control policies. You will act as a technical lead and escalation point for complex endpoint issues, contributing to continuous improvement initiatives and supporting the wider IT team through knowledge sharing and collaboration. This role will play a crucial part in ensuring the stability, security, and scalability of PGI's IT infrastructure. The position combines technical expertise with hands-on implementation, proactive systems management, and a strong commitment to continuous improvement, working closely with IT colleagues and business stakeholders to deliver robust infrastructure solutions that align with organisational goals.
Job Responsibility
Design, implement and maintain Windows Autopilot deployments for corporate laptops, transitioning and optimising from SCCM
Manage and secure endpoints using Microsoft Intune, Entra ID, and Conditional Access policies including update and driver management
Administer and enhance MDM & MAM (iOS & Android), ensuring secure access to corporate data
Maintain and improve endpoint security controls, including AppLocker and/or App Control for Business, BitLocker, Defender XDR
Act as an escalation point for complex support issues, troubleshooting root causes and driving resolution, including IP networking, poor performance, stop codes
Collaborate with the IT team to design, implement, and document solutions, ensuring consistency and maintainability
Support and mentor team members, explaining technical concepts clearly and improving overall team capability
Identify opportunities to automate, standardise, and improve endpoint management and security posture
Ensure endpoint solutions align with ISO 27001, Cyber Essentials+, DCC, and organisational security policies
Requirements
A minimum of 7 years' experience in Microsoft-based on-prem and SaaS infrastructure engineering, including Windows 11 endpoint management and modern workplace technologies such as Microsoft Intune, Entra ID, Conditional Access, Microsoft Defender XDR, and Microsoft 365
Experience with SCCM-based operating system deployment (OSD) and the transition to modern endpoint management using Windows Autopilot
Hands-on experience implementing and managing Windows Autopilot, Conditional Access policies, Mobile Device Management (MDM), Mobile Application Management (MAM) for iOS and Android, and Universal Print or equivalent solutions
Experience with application control technologies such as AppLocker or Microsoft Defender Application Control (App Control for Business preferred)
Strong troubleshooting and root cause analysis skills, with the ability to resolve complex infrastructure and endpoint issues
Experience working within secure, compliance-driven environments
Excellent communication and stakeholder management skills, with the ability to explain technical concepts to non-technical audiences, collaborate effectively across teams, and provide technical leadership and guidance
Nice to have
Building and managing environments with Windows 365 and/or Azure Virtual Desktop
PowerShell and/or other automation experience
Familiarity with endpoint security baselining and monitoring