Ascensus

Principal Architect, IT Corporate Services

Ascensus$150K — $180K *
US-Anywhere
+ 11 other locationsRemote
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field; Master's preferred.
  • 10+ years in IT with a focus on endpoint architecture and management.
  • Experience in supporting large enterprise environments of 7,500+ endpoints.
  • Deep knowledge of Microsoft Intune, Autopilot, and other management platforms.
  • Strong PowerShell skills for automation and scripting needed.

Responsibilities

  • Develop and implement enterprise endpoint architecture strategies and roadmaps.
  • Own standards for Windows and macOS operating systems, including upgrade planning.
  • Lead technology planning for acquisitions, migrations, and device refreshes.
  • Serve as technical owner for endpoint management solutions like Microsoft Intune.
  • Design endpoint enrollment and provisioning processes across various platforms.
  • Establish an enterprise mobility strategy and govern corporate mobile devices.
  • Coordinate with Cybersecurity to implement endpoint security controls.

Benefits

  • Opportunities for professional development and training.
  • Flexible working hours with remote work options available.
  • Collaborative work environment with cross-team interaction.
  • Participation in scheduled non-business-hour activities for major incidents.
Full Job Description

The Principal Architect serves as the enterprise technology owner and principal architect for all endpoint computing and enterprise mobility services across Ascensus. This role is the senior technical authority for End User Computing, Endpoint Engineering, Modern Endpoint Management, and Enterprise Mobility Services and is responsible for defining and executing the enterprise endpoint strategy while maintaining ongoing operational ownership of the platforms, processes, standards, and technologies that support approximately 7,500 Windows, macOS, and mobile endpoints. The Principal Architect provides architectural leadership and technical governance for Microsoft Intune, Windows Autopilot, Apple Business Manager, Entra ID device registration, NinjaOne, Addigy, operating system standards, Group Policy, endpoint configuration baselines, device provisioning, software distribution, patching, application packaging, hardware and peripheral standards, endpoint lifecycle management, and enterprise mobility. The role leads through technical influence and coordination with internal teams and service providers and serves as the final technical escalation point for complex endpoint engineering issues.

Section 2: Job Functions, Essential Duties and Responsibilities

Endpoint Architecture and Strategy

 Develop and execute the enterprise endpoint architecture strategy, standards, governance, and technology roadmaps for Windows, macOS, and mobile platforms.

 Own Windows and macOS operating system standards, upgrade planning, feature adoption, and endpoint configuration baselines.

 Lead endpoint technology planning and execution for acquisitions, divestitures, office openings and consolidations, migrations, and large-scale device refreshes.

Modern Endpoint Management

 Serve as technical owner for Microsoft Intune and the overall Modern Endpoint Management strategy, including architecture, design, implementation, governance, optimization, and operational ownership.

 Own Windows Autopilot, Apple Business Manager, Entra ID device registration, NinjaOne, Addigy, and related endpoint management technologies.

 Design and maintain endpoint enrollment, zero-touch provisioning, imaging, software distribution, patching, and device-management processes across supported platforms.

 Drive adoption of cloud-based endpoint management and automation while ensuring solutions remain secure, scalable, supportable, and aligned with enterprise requirements.

Endpoint Engineering and Configuration Management

 Design, test, implement, and govern end-user Group Policies in Active Directory and establish consistent enterprise endpoint configuration standards.

 Serve as the final technical escalation point for complex desktop engineering, application packaging, imaging, patching, Group Policy, software distribution, device enrollment, and endpoint-management issues.

 Own application packaging and compatibility standards; coordinate testing and implementation activities performed by Desktop Support and service provider teams.

 Provide technical direction to internal teams and service providers without direct supervisory responsibility.

Enterprise Mobility Services

 Establish and maintain the enterprise mobility strategy, standards, governance model, and technology roadmap for corporate mobile phones and tablets.

 Serve as the primary technology and vendor owner for T-Mobile, including service planning, escalations, technology evaluation, rate-plan and device-standard input, and roadmap alignment in partnership with Procurement.

 Define standards for mobile devices, operating systems, accessories, enrollment, eSIM, zero-touch provisioning, refresh, replacement, recovery, and retirement.

 Partner with Cybersecurity and operational teams to align mobility services with security, compliance, risk, and business continuity requirements.

Security and Risk Partnership

 Coordinate with Cybersecurity to design and implement endpoint security controls through Group Policy, Intune, and operating system configurations.

 Own BitLocker administration and governance while partnering with Cybersecurity on vulnerability remediation and Zero Trust initiatives.

 Participate in major incidents and security incidents involving endpoints, providing technical leadership for investigation, containment, remediation, and recovery activities.

 Contribute technical expertise to endpoint observability, compliance reporting, audit support, and operational metrics without serving as the primary owner of those functions.

Hardware, Vendor, Asset Lifecycle, and Licensing

 Lead evaluation, testing, selection, standardization, and lifecycle planning for enterprise laptops, desktops, mobile devices, peripherals, docking stations, and related end-user technologies.

 Serve as the primary technology owner for strategic endpoint hardware vendors, including Dell, Apple, and other providers; participate in vendor evaluations and contract negotiations in partnership with Procurement.

 Own the complete endpoint lifecycle, including deployment, refresh, recovery, secure disposition, and selection and oversight of asset recovery and eWaste vendors.

 Manage licensing and technology governance for endpoint software such as Adobe Acrobat, Snagit, and other end-user applications.

Automation and Continuous Improvement

 Develop and maintain PowerShell and other scripting solutions for endpoint provisioning, administration, software deployment, patching, remediation, and operational automation.

 Advance automation and standardization to reduce manual effort and improve the reliability, scalability, and consistency of endpoint operations.

 Evaluate emerging endpoint and mobility technologies, lead pilots, and recommend solutions that improve security, supportability, productivity, and associate experience.

Supervision

 No direct supervisory responsibilities are required in this position.

 Provides enterprise-wide technical leadership and architectural guidance for End User Computing, Endpoint Engineering, Modern Endpoint Management, and Enterprise Mobility Services.

 Leads through technical influence and coordination with Desktop Support, Service Desk, Infrastructure, Cybersecurity, Procurement, and third-party service providers.

 Serves as technology owner for endpoint management platforms, enterprise mobility services, hardware standards, endpoint lifecycle services, software licensing, and strategic vendor relationships.

Section 3: Experience, Skills, Knowledge Requirements

 Education: Bachelors degree in Computer Science, Information Systems, or a related field, or equivalent relevant experience. A masters degree is preferred.

 Extensive Experience: At least 10 years of progressive information technology experience, including substantial experience in endpoint architecture, desktop engineering, endpoint management, or End User Computing technical leadership.

 Large-Scale Endpoint Expertise: Demonstrated experience supporting large enterprise environments across Windows, macOS, and mobile platforms, including endpoint standards, operating system lifecycle management, configuration baselines, application packaging, software distribution, patching, imaging, and provisioning.

 Modern Endpoint Management: Deep hands-on knowledge of Microsoft Intune, Windows Autopilot, Apple Business Manager, Entra ID device registration, Group Policy, BitLocker, and endpoint management platforms such as NinjaOne and Addigy.

 Scripting and Automation: Strong PowerShell scripting skills are required. Experience using APIs and other automation frameworks to improve endpoint provisioning, deployment, management, remediation, and operational efficiency is preferred.

 Enterprise Mobility: Experience establishing mobile device standards, managing carrier and vendor relationships, and governing mobile enrollment, provisioning, lifecycle, and support technologies.

 Vendor and Lifecycle Management: Experience serving as a technology owner for strategic vendors and managing hardware standards, refresh programs, software licensing, asset recovery, secure disposition, and eWaste services in partnership with Procurement and operational teams.

 Security Partnership: Experience implementing endpoint security controls and partnering with Cybersecurity on vulnerability remediation, encryption, security incidents, audits, and Zero Trust initiatives.

 Leadership and Communication: Excellent organization, analytical, decision-making, communication, and interpersonal skills. Demonstrated ability to influence technical direction, coordinate across teams and service providers, and explain complex concepts to technical and business stakeholders.

 Certifications: Relevant endpoint administration and management certifications are preferred but not required, including Microsoft endpoint or Microsoft 365 certifications, Apple device management certifications, ITIL, NinjaOne, Addigy, or comparable credentials.

 Availability: Ability to participate in scheduled non-business-hour implementation and maintenance activities and in major incident or security incident response when required.

About Ascensus

Ascensus is a financial services company that provides retirement, health, and education savings plans to individuals and businesses. The company was founded in 1980 and is headquartered in Dresher, Pennsylvania. Ascensus has over 4,000 employees and serves more than 12 million customers nationwide. The company offers a wide range of retirement plan solutions, including 401(k), 403(b), and IRA plans. Ascensus is committed to helping its customers save for retirement and achieve their financial goals. The company has received several awards for its excellent customer service and innovative products.
Learn more about Ascensus
Size
4,000 employees
Industry
Founded
1980

Similar Jobs

More Jobs at Ascensus

More Information Technology Jobs

Find similar Principal Architect, IT Corporate Services jobs: