Job Summary: The System Engineer- Infrastructure Services will lead the design, implementation, and lifecycle management of endpoint infrastructure systems, directory services and user computing platforms across the enterprise. This role ensures reliable, secure, and efficient access to IT resources by managing Windows-based devices, Microsoft Intune, Azure, Group Policy, Active Directory, and related services. The engineer will lead initiatives to improve user experience, endpoint security, device lifecycle management, and software deployment, while supporting collaboration and mobility. The ideal candidate will have strong expertise in desktop engineering, automation, identity and access management, and a passion for optimizing end-user productivity. Essential Functions:
- Design, recommend, and implement global workplace technologies that align with business needs and IT best practices
- Develop and maintain enterprise-wide standards for desktop engineering, device management, and user experience
- Administer and support Microsoft Intune, Autopilot, Endpoint Manager, and Configuration Profiles for modern device management
- Manage the full lifecycle of end-user devices (desktops, laptops, mobile), including imaging, deployment, patching, and retirement
- Maintain and support Active Directory, Group Policy Objects (GPOs), Azure Entra ID, and identity and access configurations
- Implement and enforce endpoint security policies including antivirus, encryption, and conditional access
- Participate in audits, IT risk assessments, and compliance activities (e.g., NIST, ISO 27001, 21 CFR Part 11)
- Develop and manage automation scripts (e.g., PowerShell) to streamline endpoint deployment, support, and reporting
- Provide Tier 3 support for end-user and endpoint issues; serve as a subject matter expert for escalations
- Collaborate with helpdesk, infrastructure, and application teams to ensure seamless support and service delivery
- Implement and monitor usage of self-service tools and knowledge bases to improve end-user experience
- Coordinate with hardware and software vendors to ensure timely support, SLAs, and lifecycle standards
- Contribute to the development and maintenance of workplace services documentation, standards, and training materials
- Participate in projects such as hardware refresh, OS upgrades, Zero Trust, and mobile device integration initiatives
Additional Responsibilities:
- Support security policies and participate in audits (NIST, ISO, GDPR, 21 CFR Part 11).
- Participate in incident response and security assessments.
- Provide training to IT team members on infrastructure best practices.
- Support hosting and networking technologies as needed.
- Administer software distribution and automation tools.
- Contribute to infrastructure budgeting and planning.
- Participate in infrastructure modernization and cloud migration initiatives.
- Perform other duties as assigned.
Job Specifications:
- Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience)
- 5-7 years of experience in systems engineering with a focus on Workplace Services, End-User Computing, or Device Management
- Strong hands-on experience with Microsoft Intune, Autopilot, and Endpoint Manager
- Proven experience with Active Directory, Azure AD, and Group Policy administration
- Expertise in managing Windows endpoints in hybrid (on-prem + cloud) environments
- Solid understanding of endpoint security practices including antivirus, patching, encryption, and conditional access
- Experience with scripting and automation using PowerShell
- Familiarity with compliance frameworks such as ISO 27001, NIST, and 21 CFR Part 11
- Strong troubleshooting skills for desktops, mobile devices, and productivity tools (O365, VPN, MFA, etc.)
Desirable:
- Certifications such as Modern Desktop Administrator Associate, Azure Administrator, CompTIA A+, MD-102, or equivalent.
- Experience with:
- Endpoint analytics and performance monitoring tools
- Software deployment and patch management solutions (e.g., SCCM, Intune)
- ITSM tools and structured Change management processes
- Identity and access solutions (MFA, SSO, Conditional Access Policies)
- Ability to work cross-functionally with application, infrastructure, and support teams.
Physical Requirements
- Must be able to lift 50 lbs, bend, and climb stairs as needed.
- Ability to travel to company sites as required.