Senior Desktop Engineer - Hybrid - Blue Bell, Pennsylvania

Slipstream IT

$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience managing Microsoft Intune environments and applications
  • Strong understanding of endpoint security, compliance, and data protection policies
  • Experience with PowerShell scripting for device management and reporting
  • Proficiency in Azure Active Directory and Group Policies
  • Familiarity with Microsoft Defender for Endpoint integration

Responsibilities

  • Design and refine the Microsoft Intune environment for security and compliance needs.
  • Own tenant settings and enforce access policies for diverse endpoints.
  • Continuously audit configurations to identify and address issues.
  • Deploy applications across various platforms through Intune.
  • Monitor deployment success rates and resolve policy conflicts proactively.
  • Collaborate with security teams to implement role-based access controls.
  • Mentor junior engineers on best practices and configuration management.

Benefits

  • 401k match
  • Comprehensive group health, dental, vision benefits
  • Life insurance and long-term disability coverage
  • Discretionary paid time off
Full Job Description
Responsibilities
  • Design, configure, and continuously refine the Microsoft Intune environment to meet organizational security, compliance, and productivity requirements.
  • Own Intune tenant settings, conditional access policies, and compliance baselines across Windows, macOS, iOS, and Android endpoints.
  • Review and optimize existing configurations on an ongoing basis, identifying gaps, redundancies, and drift from defined standards.
  • Maintain and document configuration profiles, endpoint security policies, and compliance posture in alignment with CIS benchmarks or internal security frameworks.
  • Deploy and manage applications across the estate via Intune, including Win32, MSIX, Line-of-Business, and Microsoft Store app types.
  • Define and enforce app protection policies (APP/MAM) for both managed and unmanaged devices, ensuring data loss prevention controls are consistently applied.
  • Configure and manage app configuration policies for managed apps, including Microsoft 365 and third-party applications.
  • Own the end-to-end application patching process - packaging, testing, staged rollout, and validation - ensuring timely remediation of vulnerabilities.
  • Monitor deployment success rates and proactively resolve failed assignments or conflicting policies.
  • Design and maintain Azure AD dynamic groups to support accurate, automated policy and application targeting across users and devices.
  • Develop and refine dynamic membership rules using device and user attributes (OS version, department, location, compliance state) to reduce manual overhead.
  • Audit group membership and assignment logic regularly, eliminating over-broad targeting or conflicting inclusions and exclusions.
  • Collaborate with IAM and security teams to align group structures with role-based access control (RBAC) and zero-trust principles.
  • Write, test, and deploy PowerShell scripts via Intune for device configuration, remediation, and reporting tasks that fall outside native policy capabilities.
  • Build and maintain Proactive Remediations to detect and self-heal common endpoint issues at scale.
  • Leverage Microsoft Graph API and PowerShell modules (Microsoft.Graph, Az) to automate administrative tasks, reporting, and bulk operations within the Intune and Entra ID environment.
  • Maintain a version-controlled script library (Git), ensuring scripts are documented, peer-reviewed, and tested in a non-production environment before deployment.
  • Evaluate and implement automation opportunities to reduce manual toil across endpoint lifecycle processes - provisioning, patching, decommission.
  • Maintain endpoint compliance policies and act as the subject-matter expert for Intune-based security controls within the wider security team.
  • Integrate Intune with Microsoft Defender for Endpoint, ensuring MDE onboarding, sensor health, and policy enforcement are maintained across all managed devices.
  • Support audit and compliance activities by producing accurate device compliance reports and responding to findings in a timely manner.
  • Act as the escalation point for complex Intune, endpoint, and application delivery issues, driving root-cause analysis and resolution.
  • Mentor junior engineers, conducting script and configuration reviews and sharing knowledge of modern management best practices.
  • Contribute to and maintain internal runbooks, SOPs, and technical documentation for all areas of the Intune environment.
  • Stay current with Microsoft Intune, Entra ID, and Windows feature releases, proactively assessing impact and communicating changes to the team.
  • Lead or contribute to endpoint modernization projects, including Autopilot deployments, co-management transitions, and Windows feature update rings.

Work Location & Schedule
  • Employees are expected to maintain a consistent hybrid schedule of three (3) onsite workdays per week at our Blue Bell, PA office and two (2) remote workdays each week.

Benefits
  • 401k match
  • Comprehensive group health, dental, vision benefits
  • Life insurance/LTD
  • Discretionary PTO

This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of the Employer.

Similar Jobs

More Jobs at Slipstream IT

More Information Technology Jobs

Find similar Senior Desktop Engineer - Hybrid - Blue Bell, Pennsylvania jobs: