Endpoint & Identity Engineer (Onsite - San Francisco)
Location: 1800 Owens St, San Francisco, CA | Onsite 3-5 days/week
About the RoleWe're looking for a hands-on Endpoint & Identity Engineer to own and mature our device management and security tooling. This role is primarily onsite at our San Francisco HQ and sits at the intersection of endpoint engineering, IT security, and automation. You'll be the primary owner of our Microsoft Intune environment and will work closely with our security and IT teams to clean up legacy configurations, modernize device onboarding, and ensure our endpoint fleet is healthy, patched, and compliant.
What You'll DoIntune & Endpoint Management
Own the day-to-day administration and long-term strategy for Microsoft Intune, including device enrollment, compliance policies, configuration profiles, and conditional access.
Audit and remediate existing Intune policies - consolidating redundant configurations, resolving conflicts, and establishing clean, well-documented baselines.
Design, refine, and maintain Windows Autopilot workflows for zero-touch device provisioning.
Manage and improve application deployment pipelines, including Win32 app packaging, LOB apps, and Microsoft Store for Business integrations.
Drive ongoing cleanup and hygiene across the Intune tenant - stale devices, orphaned policies, misconfigured profiles.
Patching & Vulnerability Management
Administer Automox for cross-platform patching across Windows, macOS, and Linux endpoints.
Define and maintain patching policies, schedules, and SLAs to meet compliance requirements.
Work with security tools such as Rapid7 to correlate vulnerability findings with patching coverage and close gaps.
Produce regular reporting on patch compliance and endpoint health for stakeholders.
Identity & Access
Work within an Okta environment to support device trust integrations, SSO, and lifecycle management as it relates to endpoint posture.
Collaborate on Conditional Access policies that tie Intune compliance to Okta-managed application access.
Collaboration & Projects
Partner with IT, Security, and Engineering teams on projects requiring endpoint or identity expertise.
Document configurations, runbooks, and procedures to ensure knowledge continuity.
Identify opportunities to automate repetitive tasks using PowerShell, Graph API, or similar tooling.
What We're Looking For- 3+ years of hands-on experience administering Microsoft Intune in a mid-to-large enterprise environment.
- Proven track record cleaning up or restructuring an Intune environment - policy rationalization, conflict resolution, device hygiene.
- Solid experience with Windows Autopilot, including profile configuration, deployment troubleshooting, and hardware hash management.
- Experience with Automox or a comparable cross-platform patching solution.
- Familiarity with Okta, including understanding of how device trust and MDM integration work within an Okta-managed identity environment.
- Exposure to vulnerability management tools such as Rapid7 InsightVM or similar.
- Proficiency with PowerShell and/or Microsoft Graph API for automation and reporting.
- Strong documentation habits and a methodical approach to change management.
Nice to Have- Microsoft certifications (MD-102, MS-102, or similar).
- Experience with macOS management within Intune or alongside Jamf.
- Familiarity with CIS benchmarks or NIST frameworks as applied to endpoint hardening.
- Experience in a high-growth tech or hybrid-workforce environment.
Work ArrangementThis role requires onsite presence at 1800 Owens St, San Francisco, CA 3-5 days per week. Some flexibility on specific days may be available.
This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of the Employer.