The administrator will design, deploy, and maintain zero-touch device enrollment and configuration policies across Windows, macOS, and iOS platforms. They are also responsible for application packaging, security compliance, and acting as a Tier 3 escalation point for endpoint technical issues.
We are looking for an experienced Microsoft Intune Systems Administrator to manage and modernize our multi-platform endpoint ecosystem for our HUD contract. IWe are looking for an experienced Microsoft Intune Systems Administrator to manage and modernize our multi-platform endpoint ecosystem. In this role, you will design, deploy, and maintain zero-touch device enrollment, configuration profiles, compliance policies, and app packaging across Windows, macOS, and iOS/iPadOS devices. The ideal candidate has hands-on technical expertise in unified endpoint management (UEM), Apple Business Manager (ABM), Windows Autopilot, and cloud-first security baselines
This position will be located within the United States and is fully remote.
Responsibilities
- Multi-Platform Device Lifecycle Management
- Configure and maintain zero-touch onboarding for all platforms: Windows Autopilot, Apple Automated Device Enrollment (ADE) via Apple Business Manager (ABM), and iOS/iPadOS enrollment
- Manage macOS configuration profiles, mobile device management (MDM) payloads, and shell scripts (Bash) for custom settings and elevated controls
- Define and manage Windows baseline policies, administrative templates, PowerShell scripts, and Remediation scripts
- Application Packaging & Deployment
- Package, test, and deploy applications across all platforms (Win32, LOB, Microsoft Store, macOS PKG/DMG files, and iOS App Store / VPP volume licensing)
- Maintain patching schedules and automated software update workflows for Windows, macOS, and mobile apps
- Implement Conditional Access policies, App Protection Policies (MAM), and Compliance Policies linked with Microsoft Defender for Endpoint
- Manage disk encryption standards across platforms (BitLocker for Windows, FileVault for macOS)
- Configure identity integrations, Single Sign-On (SSO), and Platform SSO for macOS endpoints
- Operational Support & Monitoring
- Act as Tier 3 escalation for endpoint-related technical issues across Windows, Mac, and mobile fleets
- Monitor tenant health, device compliance failures, sync errors, and security vulnerabilities; remediate non-compliant assets promptly
- Maintain accurate technical documentation, enrollment guides, and end-user self-service instructions
Qualifications- Bachelor's with 12+ years of system administration experience (or commensurate experience)
- 3–5+ years in Enterprise Endpoint Management, with at least 2+ years dedicated to Microsoft Intune / Endpoint Manager
- Hands-on experience integrating Apple Business Manager (ABM) with Intune, VPP app management, FileVault management, and running Bash scripts on macOS. JAMF knowledge preferred
- Experience with Windows Autopilot, BitLocker, PowerShell scripting, Win32 app packaging (IntuneWin App Prep Tool), and AD/Entra ID integration
- Strong knowledge of Microsoft Entra ID (Azure AD), Conditional Access, RBAC, and Endpoint Security baselines
- Experience configurating iOS/iPadOS devices, Supervision, App Protection Policies (MAM without enrollment), and Company Portal deployment
Clearance Required: Ability to maintain a HUD Public Trust clearance
Posted Salary RangeUSD $108,310.00 - USD $145,000.00 /Yr.