JOB DESCRIPTION
POSITION SUMMARY
The Systems Engineer, Senior is responsible for the design, implementation, administration, and optimization of
enterprise endpoint management solutions across Windows, mobile, and thin client platforms. This role supports
Microsoft Intune, Configuration Manager (SCCM), Apple Business Manager, Android Enterprise, and virtual endpoint
technologies to ensure secure, scalable, and efficient device management while enhancing the end-user experience.
WORK ENVIRONMENT AND TRAVEL REQUIREMENTS
Work Environment: Onsite/Hybrid 2-4 days a/wk - Brentwood, TN
Travel Requirements: Up to 25% travel
ESSENTIAL FUNCTIONS
- Manage, support, and optimize Microsoft Intune, Microsoft Configuration Manager (SCCM), Apple Business
Manager (ABM), and Android Enterprise environments to deliver secure and reliable endpoint management
services. - Design, implement, and maintain endpoint provisioning and deployment solutions, including Windows
Autopilot, Operating System Deployment (OSD), Apple Automated Device Enrollment (ADE), Android ZeroTouch Enrollment, and thin client provisioning processes. - Develop, test, and troubleshoot application deployments, software distribution packages, configuration
profiles, compliance policies, task sequences, and operating system upgrades across Windows, mobile, and
thin client platforms. - Manage endpoint lifecycle activities including device enrollment, imaging, provisioning, driver management,
application packaging, patching, compliance remediation, inventory management, and retirement processes. - Administer and support Mobile Device Management (MDM) and Mobile Application Management (MAM)
solutions for corporate-owned and BYOD devices. - Support and maintain Network Device Enrollment Service (NDES) infrastructure, SCEP certificate
deployments, PKI integrations, and certificate-based authentication services supporting managed endpoints. - Administer and support Apple Business Manager, including Managed Apple IDs, application licensing,
enrollment profiles, and automated device assignment workflows. - Administer and support Android Enterprise deployments, including Fully Managed, Corporate-Owned
Personally Enabled (COPE), Dedicated Device, and Work Profile configurations. - Design, implement, test, and maintain Intune App Protection Policies (MAM) for managed and
unmanaged/BYOD devices, including application access, corporate data protection, data transfer controls, and
application-level security requirements. - Manage and support enterprise thin client infrastructures, including IGEL OS, Dell Wyse, and other virtual
desktop endpoint platforms. - Support virtual workplace technologies and endpoint integrations for Citrix, Azure Virtual Desktop (AVD), and
other remote access solutions. - Lead and support enterprise endpoint modernization initiatives, migration projects, and cloud-based
management transformations. - Monitor device health, deployment success, compliance posture, certificate services, and endpoint
performance through reporting, analytics, and monitoring tools. - Collaborate with cybersecurity teams to implement and maintain security controls, Conditional Access policies,
endpoint protection, and Zero Trust initiatives. - Troubleshoot complex endpoint management, operating system, application deployment, enrollment,
authentication, and certificate-related issues. - Create and maintain technical documentation, standards, architecture diagrams, and operational procedures
for endpoint management services. - Evaluate emerging technologies and management platforms that improve endpoint security, automation,
operational efficiency, and user experience. - Participate in an on-call support rotation and provide advanced technical support for endpoint and mobility
management services. - Mentor junior engineers and administrators while promoting adherence to operational, security, and compliance
standards. - Partner with infrastructure, networking, security, and application teams to support organizational objectives and
technology roadmap initiatives
QUALIFICATION, EDUCATION, KNOWLEDGE, SKILLS
Education
- Bachelor’s degree and/or equivalent experience required.
- Experience
- 5+ years of experience supporting Apple Business Manager (ABM) in a large enterprise environment.
- Hands-on experience administering Microsoft Intune and modern endpoint management solutions.
- Strong experience with:
- Apple Business Manager
- Microsoft Intune
- Windows Autopilot
- Apple Automated Device Enrollment
- Android Enterprise
- Mobile Device Management (MDM)
- Mobile Application Management (MAM)
- NDES/SCP
- PKI and Certificate Stores
- Conditional Access
- Distribution Point (DP) and Management Point (MP) administration
- Experience configuring, deploying, and troubleshooting enterprise endpoint infrastructure.
- Strong troubleshooting and root-cause analysis skills.
- Ability to manage multiple projects and operational priorities with limited supervision.
- Demonstrates a team-first mindset, consistently contributing to a positive culture, sharing knowledge, and
supporting colleagues to achieve common goals. - Demonstrates a service-oriented mindset and willingness to troubleshoot and resolve issues across the broader
technology environment, regardless of functional ownership.
Preferred Qualifications - Windows 11 Endpoint Management
- Android Zero-Touch Enrollment
- IGEL OS Management
- Dell Wyse Management Suite (WMS)
- Thin Client Administration
- Citrix Virtual Apps and Desktops
- Azure Virtual Desktop (AVD)
- Microsoft Entra ID (Azure AD)
- Microsoft Defender for Endpoint
- PowerShell Automation
- Microsoft Graph API
- Endpoint Security and Zero Trust Architecture
ORGANIZATIONAL EXPECTATIONS
- Maintains compliance with applicable regulatory requirements and supports hospital and department policies,
procedures, and standards. - Consistently supports the mission, vision, values, and goals of the hospital and Lifepoint Health.
- Acts in a positive, proactive, and professional manner when interacting with employees, leaders, physicians, patients,
visitors, and community partners. - Maintains confidentiality, complies with HIPAA requirements, and handles sensitive business and patient information
appropriately. - Demonstrates accountability for workplace safety and completes assigned education, training, and mandatory
requirements in a timely manner. - Maintains required licensure, certification, and professional credentials, if applicable, in good standing.