Design and lead the end-to-end Microsoft Intune architecture for a large federal enterprise while establishing secure modern management patterns. Collaborate with security, identity, and engineering teams to deliver a Zero Trust aligned endpoint platform.
Benefits:
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Parental leave
- Vision insurance
Intune Architect
Role Description:
Design and lead the end to end Microsoft Intune architecture for a large federal enterprise, establishing secure modern management patterns across Windows, iOS/iPadOS, and Android. Define security baselines and conditional access guardrails, engineer a Blackberry UEM → Intune migration and co management strategy (SCCM/Configuration Manager), and stand up technical governance (standards, patterns, and guardrails) to keep the environment compliant, resilient, and cost effective. The architect partners with Security, Identity, Networking, Client Engineering, and PMO to deliver a Zero Trust aligned endpoint platform.
Key Responsibilities:
- Minimum 8 years experience in relevant field.
- Intune & Modern Management (Expert): Autopilot provisioning, device compliance, configuration profiles, application lifecycle (Win32/MSIX/MAM), update rings, and RBAC/scopes.
- Security & Compliance: Conditional Access design, BitLocker governance, Microsoft Security Baselines, Defender for Endpoint integration, threat & vulnerability workflows.
- Entra ID & Identity: Azure AD/Entra ID tenant administration, user/group design, SSO (SAML/OIDC), device identities, certificate/PKI integration.
- Automation: PowerShell scripting; configuration as code mindset; build reusable modules and reporting.
- Mobile Management (MDM/MAM): MAM/app protection policies, conditional launch controls.
- Co Management & Migration: Hands on experience transitioning SCCM/Configuration Manager to cloud based Intune; defining co management workloads and phased cutovers.
- Experience: 7–10+ years in endpoint management; 3–5+ architecting Intune at enterprise scale (10k+ devices or federal programs).
- Delivery: Demonstrated ability to lead pilots, wave plans, and executive level briefings; strong documentation and stakeholder management.
Preferred Skills
- Zero Trust architecture and NIST 800 53 control mapping for endpoints; familiarity with FedRAMP/ATO processes.
- Win32 packaging at scale (IntuneWin, detection rules, dependencies), app remediation, and Autopatch/Update rings optimization.
- Advanced CA design (session controls, sign in risk, compliant network locations), Entra ID P2 features (Identity Protection, Access Reviews).
- Defender for Endpoint advanced hunting (KQL), attack surface reduction (ASR), tamper protection, and automated response playbooks.
- Enterprise certificate management (device certs, SCEP/PKCS), Wi Fi/VPN profiles, and network pre requisites.
- Terraform/Bicep or pipeline driven deployments for repeatable config; Git based governance for profiles/policies.
- Incident response and DR runbooks for endpoint outages; executive communications and change management expertise.
- Public Trust (or higher) clearance eligibility; prior federal client experience.
This is a remote position.