American International Group

Lead Mobility Engineering SME

American International Group$150K — $190K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in endpoint, mobility, or digital workplace engineering, with expertise in enterprise mobile services.
  • Hands-on experience with Microsoft Intune and its components: enrollment, compliance, and app deployment.
  • In-depth knowledge of MDM and MAM across BYOD and corporate-owned devices, specifically iOS/iPadOS and Android Enterprise.
  • Experience with at least one other UEM platform such as Workspace ONE, Ivanti/MobileIron, Jamf, or SOTI.
  • Familiarity with modern Windows provisioning, including Autopilot and update strategies.
  • Understanding of Entra ID, modern authentication, and conditional access mechanisms.
  • Practical knowledge in mobility network configurations including Wi-Fi, VPNs, and DNS analysis.
  • Demonstrated skills in automation using PowerShell, Microsoft Graph, and REST APIs.

Responsibilities

  • Own the architecture and configuration for Intune and mobile application management.
  • Manage the end-to-end Apple ecosystem, including device enrollment and app deployment.
  • Integrate and migrate legacy mobility profiles to modern Intune setups without losing coverage.
  • Engineer device authentication and security features across mobile platforms.
  • Oversee Windows Autopilot processes from preparation to roll-out.
  • Design and implement security policies and compliance checks in collaboration with cybersecurity teams.
  • Troubleshoot network engineering issues related to mobile device connectivity and access control.
  • Lead change management and technical leadership in mobility engineering projects.

Benefits

  • Comprehensive benefits package focusing on health and wellbeing.
  • Investments in professional development and career growth.
  • Supportive collaborative work environment emphasizing in-person teamwork.
Full Job Description

The Lead Mobility Engineering SME is the senior hands-on engineer accountable for the architecture, engineering, security, automation, and operational health of the enterprise mobile and modern endpoint ecosystem — Microsoft 365 mobile services, Microsoft Intune, MDM and MAM, Apple iOS/iPadOS, Android Enterprise, and modern Windows provisioning including Autopilot. This is not a coordination or console-administration role, and it is deliberately not a single-discipline one: the estate depends on mobility platform engineering, modern authentication, endpoint security and network connectivity, and automation, and strength across all four is the bar. The role designs, builds, tests, automates, troubleshoots to root cause, documents, and leads controlled production change end to end.


Mobility platform engineering. Own the architecture and configuration standards for Intune, enrollment, MAM and app protection, compliance policies, configuration profiles, app deployment, certificates, and secure access. Own the Apple stack end to end — Apple Business Manager, Automated Device Enrollment, APNs certificate lifecycle, VPP, supervision, Declarative Device Management, managed software updates — and Android Enterprise in every mode: fully managed, dedicated/kiosk, COPE, and work profile, including managed Google Play, zero-touch enrollment, OEMConfig and Knox. Define compatibility, ring-based rollout, and lifecycle plans so major OS releases are planned events, not fire drills.


Multi-platform UEM breadth. Apply working knowledge of other enterprise mobility platforms — Omnissa Workspace ONE UEM (formerly VMware Workspace ONE / AirWatch), MobileIron/Ivanti Neurons, Jamf, SOTI or BlackBerry UEM — to migration, coexistence, and platform-selection decisions, and translate legacy profile, policy, and app configurations into their modern Intune equivalents without loss of control coverage.


Modern authentication and identity. Engineer device authentication across Entra ID registration, Entra join and hybrid join, Primary Refresh Token behavior, device-based Conditional Access, and token and session controls. Deliver passwordless and phishing-resistant authentication on mobile — platform credentials, FIDO2 and passkeys, certificate-based authentication, Authenticator broker behavior. Own certificate infrastructure: SCEP and PKCS, the Intune Certificate Connector, Cloud PKI, NDES, trusted roots, and renewal automation. Design Conditional Access and prove blast radius in report-only mode before production. Debug OAuth 2.0, OIDC, SAML, and MSAL failures at protocol level.


Modern endpoint management and Autopilot. Own Windows Autopilot end to end — user-driven and self-deploying modes, pre-provisioning, Autopilot device preparation, Enrollment Status Page tuning, hardware hash and attestation, and the OEM supply process. Operate settings catalog, security baselines, filters, scope tags and RBAC, Windows Update for Business and Autopatch rings. Retire legacy through co-management transition and GPO migration. Own Win32 and MSIX packaging, detection logic, and supersedence chains.


Security and governance. Engineer controls with Cybersecurity, IAM, Privacy and Legal: compliance, app protection, DLP, encryption, and certificate-based access. Integrate Defender for Endpoint and mobile threat defense signal into compliance and Conditional Access; apply ASR rules and jailbreak and root detection. Own key escrow, device wipe and departure lifecycle, Endpoint Privilege Management and LAPS. Maintain secure baselines, remediate drift and unsupported OS versions to defined targets, and supply audit evidence from reporting rather than screenshots.


Network engineering for mobility. Design and troubleshoot 802.1X and EAP-TLS Wi-Fi, RADIUS and NPS integration, roaming and captive portal behavior; per-app and always-on VPN, Global Secure Access and ZTNA patterns, and split-tunneling decisions. Diagnose DNS, proxy and TLS inspection effects on certificate pinning and push notifications, APNs and FCM egress, IPv6, and carrier and eSIM behavior — converting a capture or trace into a configuration change rather than a handoff.


Automation and engineering practice. Automate with PowerShell, Microsoft Graph, REST and JSON: bulk policy deployment, lifecycle operations, compliance and expiry reporting, and drift detection against baseline. Apply source-controlled policy-as-code with peer review and promotion across rings. Close operational loops with Power Automate, Azure Automation or Functions, proactive remediations, and ITSM integration. Build proactive monitoring and alerting for enrollment failure, noncompliance, deployment error and service degradation.


Change, operations, and technical leadership. Own changes from scope and impact through test evidence, pilot, implementation, validation, communications and tested backout. Lead Tier 3/4 troubleshooting and root-cause analysis; drive vendor escalations with complete diagnostic evidence. Maintain architecture diagrams, designs, runbooks and decision records complete enough for another qualified engineer to operate and recover the service. Mentor engineers, set engineering quality standards, and maintain a prioritized roadmap and technical debt backlog.


What you'll need to succeed

  • 7+ years in endpoint, mobility, or digital workplace engineering, with significant ownership of enterprise mobile services in a large or complex environment.
  • Deep hands-on Intune engineering: enrollment, compliance, configuration profiles, app deployment, app protection, reporting, troubleshooting.
  • Strong MDM and MAM architecture knowledge across corporate-owned and BYOD scenarios, plus iOS/iPadOS and Android Enterprise management models and OS lifecycle.
  • Hands-on exposure to at least one additional UEM platform such as Workspace ONE UEM (AirWatch), Ivanti/MobileIron, Jamf or SOTI, including migration or coexistence work.
  • Modern Windows provisioning experience including Autopilot, ESP troubleshooting, and update ring strategy.
  • Entra ID, modern authentication, Conditional Access dependencies, and certificate-based secure access.
  • Practical mobility network competence: 802.1X and certificate-based Wi-Fi, VPN and per-app VPN, DNS, proxy and TLS inspection effects.
  • Demonstrated automation with PowerShell, Graph, REST APIs and JSON, and root-cause troubleshooting using logs, telemetry and structured testing.
  • Enterprise change, incident and problem discipline, high-quality technical documentation, and clear communication to technical and nontechnical stakeholders.

Preferred Qualifications

  • Advanced End-to-end ownership of the Microsoft Intune platform — design, engineering, and Tier 3/4 support across tenant and RBAC architecture, enrollment, policy, app deployment, and certificate services — with equivalent hands-on design, engineering and support experience on Omnissa Workspace ONE UEM (AirWatch).
  • Deep mobile platform specialization — Apple Business Manager and Declarative Device Management at scale, Android Enterprise dedicated and kiosk fleets, mobile threat defense, and zero-touch provisioning.
  • Large-scale UEM migration into Intune — from Omnissa Workspace ONE UEM (AirWatch) or Ivanti/MobileIron — including policy mapping, app re-packaging, and phased device cutover.
  • Telecom and carrier or eSIM integration, passwordless authentication on mobile, or legacy VPN retirement.
  • Experience in a global, highly regulated, or large-enterprise environment; frontline and shared-device populations alongside corporate users.
  • Certifications such as MD-102, SC-300, SC-200 or SC-100, Apple Certified IT Professional, Android Enterprise Professional, or CCNA.

Ready to make a bigger impact? We look forward to reviewing your application.

•        #LI-CN1

•        #Cybersecurity #InfoSec

For positions based in New York, NY, the base salary range for this position is $150,000 – $190,000 and the position is eligible for a bonus in accordance with the terms of the applicable incentive plan.

Your actual compensation will be dependent on your skills, experience, and qualifications.  If your compensation expectations are above the posted range, we still encourage you to apply—your unique background matters to us.  In addition, we’re proud to offer a range of competitive benefits, a summary of which can be viewed here: US Benefits Overview.

At AIG, we value in-person collaboration as a vital part of our culture, which is why we ask our team members to be primarily in the office. This approach helps us work together effectively and create a supportive, connected environment for our team and clients alike.

Enjoy benefits that take care of what matters

At AIG, our people are our greatest asset. We know how important it is to protect and invest in what’s most important to you. That is why we created our Total Rewards Program, a comprehensive benefits package that extends beyond time spent at work to offer benefits focused on your health, wellbeing and financial security—as well as your professional development—to bring peace of mind to you and your family.

Functional Area:

IT - Information Technology

About American International Group

American International Group provides property insurance, life insurance, and financial services.

American International Group Careers

Join the dynamic team at American International Group (AIG), a leading global insurance organization, and propel your career into a future of opportunities and professional growth. At AIG, we are committed to fostering a culture of innovation, leadership, and diversity that is unmatched in the industry.

Work You’ll Do

At American International Group, you will collaborate with some of the brightest minds in the industry, dedicated to solving complex challenges and driving transformative solutions in the world of insurance. Our team is at the forefront of developing innovative insurance products that not only meet the needs of our clients worldwide but also anticipate future trends.

Explore Job Opportunities and Internships

Whether you're a seasoned professional looking for your next challenge or a recent graduate eager to start your career, AIG offers a range of job opportunities and internships across various functions. From underwriting and claims to finance and technology, your next position awaits you at AIG. Our internships provide invaluable hands-on experience, helping you to enhance your skills and make meaningful contributions from day one.

Grow and Develop Your Career

AIG believes in the power of continuous learning and offers extensive training and development programs to help you hone your skills and advance your career. Leadership development, diversity training, and innovation workshops are just a few examples of how we invest in our employees' growth and leadership capabilities.

Benefits and Culture

Joining AIG means more than just having a job; it means being part of a team that values diversity and is committed to creating an inclusive environment where everyone can thrive. We offer competitive benefits that support the health, well-being, and financial security of our employees and their families. At AIG, you will find a supportive network and a culture that applauds innovation and rewards performance.

Networking and Professional Development

We encourage our employees to build professional relationships both within and outside the company through networking events, professional groups, and career fairs. These opportunities not only enhance your career but also expand your professional network, which is vital in today’s dynamic job market.

Join Our Team

Search open positions that match your skills and interests on our Careers page. We are looking for passionate, curious, and solution-driven team players who are ready to take their career to the next level. Explore the exciting and rewarding career opportunities available at American International Group today.

Stay Connected

Keep up to date with the latest industry trends, career tips, and company news by subscribing to our careers blog. Personalize your experience by signing up for job alert emails tailored to your preferences and be the first to know about new openings and exclusive insights from professionals within AIG. At American International Group, your career is just the beginning – it’s a pathway to developing your skills, meeting new challenges, and making a difference in a global company known for its commitment to innovation and excellence. Join us and shape your future with AIG.
Learn more about American International Group
Size
36,600 employees
Market Cap
$46.4 billion
Industry
Net Income
-$5.9 billion
Founded
1919
5 Year Trend
-0.3%
Revenue
$43.7 billion
NASDAQ

Similar Jobs

More Jobs at American International Group

More Enterprise Technology Jobs

Find similar Lead Mobility Engineering SME jobs: