Endpoint Engineering Specialist

Canada Life

$58K — $108K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in endpoint engineering or related roles.
  • Strong experience in enterprise Windows environments; knowledge of macOS management is a plus.
  • Deep familiarity with Microsoft endpoint technologies like Intune and MECM.
  • Hands-on experience with Azure Virtual Desktop and FSLogix.
  • Understanding of endpoint lifecycle management and compliance processes.
  • Proficient in PowerShell and related automation technologies.
  • Experience collaborating across multiple teams in a large enterprise setting.

Responsibilities

  • Design, implement, and maintain endpoint management for various environments.
  • Administer platforms like Intune, MECM, and related management services.
  • Develop automation for provisioning and operational efficiency using PowerShell and Azure.
  • Support and optimize Azure Virtual Desktop environments.
  • Manage security, compliance, and risk related to endpoint systems.
  • Troubleshoot connectivity issues and collaborate to ensure secure access.
  • Provide Tier 3 support for complex endpoint incidents and foster service improvement.

Benefits

  • Health, dental, and vision insurance.
  • Retirement savings plan with employer match.
  • Professional development opportunities and training.
  • Flexible work schedule and remote work options.
Full Job Description
Permanent Full Time

The Engineering Specialist is a senior technical role responsible for designing, implementing, securing, and continuously improving the organization's end-user computing and digital workplace platforms. This role combines endpoint engineering, desktop engineering, virtual desktop infrastructure, automation, security, compliance, and service improvement responsibilities to deliver secure, scalable, and user-focused workplace technology services.

The successful candidate will work across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), Microsoft Entra ID, Microsoft Defender, Windows Autopatch, Azure Virtual Desktop (AVD/AVDI), FSLogix, Microsoft 365 Apps, Jamf for macOS, automation frameworks, and enterprise analytics/DEX capabilities. The role requires strong technical depth, practical operational awareness, and the ability to collaborate across Architecture, Infrastructure, Security, Cloud, Network, Service Desk, Field Services, HCL/partner teams, and business stakeholders.

What you will do

Endpoint Platform Engineering & Automation
  • Design, develop, and maintain modern endpoint management capabilities across Windows, macOS, physical desktop, and virtual desktop environments.
  • Administer and enhance platforms including Microsoft Intune, MECM, Entra ID, Microsoft Defender, Windows Autopatch, Microsoft 365 Apps, Jamf, and related management services.
  • Develop automation using PowerShell, Microsoft Graph, REST APIs, Azure tooling, and other approved technologies to improve provisioning, software deployment, compliance, reporting, and operational efficiency.
  • Evaluate emerging endpoint, AI-enabled, and digital workplace technologies to improve service delivery, employee experience, resiliency, and supportability.


Azure Virtual Desktop & Cloud Desktop Services
  • Design, deploy, and manage Azure Virtual Desktop environments including host pools, session hosts, application groups, images, scaling plans, and user access models.
  • Implement and troubleshoot FSLogix profile containerization, user profile issues, session host performance, and service reliability concerns.
  • Integrate AVD/AVDI with Microsoft Entra ID, Conditional Access, MFA, network controls, and enterprise security requirements.
  • Optimize virtual desktop performance and health through Azure Monitor, Log Analytics, endpoint analytics, DEX insights, and operational reporting.
  • Support infrastructure-as-code and repeatable deployment practices using Terraform or other approved automation frameworks.


Patching, Security, Compliance & Risk
  • Develop, maintain, and continuously improve endpoint patching, vulnerability management, configuration baseline, compliance, and endpoint hardening processes.
  • Design and implement endpoint security controls, compliance policies, application control capabilities, software governance practices, and audit-supporting controls.
  • Monitor, assess, and remediate security, compliance, vulnerability, and audit findings through automation, reporting, risk assessment, and collaboration with Security and Infrastructure teams.
  • Support governance, change management, technical review, operational readiness, and positive risk-culture expectations across engineering deliverables.


Network, Access & Platform Reliability
  • Troubleshoot endpoint and AVD-related connectivity issues, including routing, firewall, segmentation, policy, and access control challenges.
  • Collaborate with Network, Cloud, Security, IAM, and Infrastructure teams to analyze traffic flows, resolve firewall rule conflicts, and ensure secure access to workplace services.
  • Identify root causes of recurring environmental issues and recommend proactive engineering improvements that reduce downtime, support incidents, and operational risk.


End User Experience, Tier 3 Support & Service Improvement
  • Provide Tier 3 support for complex endpoint, software, security, desktop, and virtual desktop incidents and escalations.
  • Partner with Service Desk, Field Services, End User Operations, Security, Cloud, and partner teams to drive timely resolution and knowledge transfer.
  • Use endpoint health, performance, DEX, and incident trends to identify opportunities for proactive remediation and measurable service improvement.
  • Develop support guidance, technical training, change enablement material, and adoption support for new technologies and workplace services.


Project Delivery, Lifecycle & Roadmap Contribution
  • Lead and participate in endpoint, desktop, AVDI, modernization, lifecycle, migration, and compliance-related projects.
  • Contribute to technology roadmaps, lifecycle planning, platform modernization, Windows servicing, device lifecycle, and continuous improvement initiatives.
  • Work within Agile delivery practices including sprint planning, backlog refinement, daily standups, retrospectives, release planning, and prioritization using Jira, ServiceNow, Azure DevOps, or other approved tools.
  • Provide technical leadership to ensure solutions are secure, supportable, operationally ready, and aligned with business, architectural, compliance, and service-management standards.


Governance, Documentation & Knowledge Management
  • Develop and maintain engineering standards, technical documentation, architecture diagrams, operational procedures, configuration baselines, compliance controls, and support documentation.
  • Promote process standardization, knowledge sharing, handoff readiness, and continuous improvement across End User Technology and partner support teams.
  • Ensure documentation supports effective transition of operational activities where appropriate while preserving engineering accountability for design and lifecycle ownership.

What you will bringRequired Qualifications
  • 5-7 years of experience in endpoint engineering, desktop engineering, workplace technology, virtual desktop, infrastructure engineering, or related technical roles.
  • Strong experience supporting and engineering enterprise Windows environments, with working knowledge of macOS management in enterprise settings.
  • Deep knowledge of Microsoft endpoint and workplace technologies including Intune, MECM, Entra ID, Microsoft Defender, Windows Autopatch, Microsoft 365 Apps, endpoint analytics, and related management capabilities.
  • Hands-on experience with Azure Virtual Desktop, FSLogix, virtual desktop operations, image management, session host troubleshooting, and performance optimization.
  • Strong understanding of endpoint lifecycle management, configuration baselines, software deployment, vulnerability management, patching, compliance, and audit-supporting processes.
  • Proficiency with PowerShell and experience leveraging Microsoft Graph, REST APIs, automation technologies, reporting, and operational scripting.
  • Practical understanding of Azure networking and security concepts relevant to endpoint and virtual desktop services, including VNets, NSGs, access controls, firewall rules, routing, and segmentation.
  • Experience collaborating with Security, Cloud, Network, Architecture, IAM, Service Desk, Field Services, Operations, and business stakeholders in a large enterprise environment.
  • Familiarity with Agile delivery methodologies and enterprise work-management platforms such as Jira, ServiceNow, Azure DevOps, or equivalent tools.
  • Strong analytical, troubleshooting, communication, documentation, stakeholder management, and technical leadership skills.

Preferred Assets
  • Microsoft certifications related to Intune, Endpoint Management, Azure, Security, Entra ID, Modern Workplace, or Azure Virtual Desktop.
  • Microsoft Certified: Azure Virtual Desktop Specialty, Microsoft Certified: Endpoint Administrator Associate, or equivalent experience.
  • HashiCorp Certified: Terraform Associate or demonstrable infrastructure-as-code experience in Azure environments.
  • ITIL, Security+, CISSP, or equivalent security, governance, or service-management certifications.
  • Experience with Digital Employee Experience (DEX) platforms, endpoint analytics, and AI-enabled productivity technologies such as Microsoft Copilot and Copilot Studio.
  • Experience with Windows 365, cloud PC, AVDI modernization, enterprise automation frameworks, and large-scale hybrid or cloud-first deployments.
  • Experience operating in a large, regulated enterprise environment with strong governance, change management, compliance, and audit expectations.


The base salary for this position is between $58,700.00 - $108,700 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

Requisition ID: 6854

Category: Digital Technology

Location:

Similar Jobs

More Jobs at Canada Life

More Information Technology Jobs

Find similar Endpoint Engineering Specialist jobs: