Role: Endpoint Automation Engineer (Intune, Entra ID, PowerShell)
Location: Onsite – Santa Clara, CA (5 days/week)
Duration: 3–6 Months Contract
Pay Rate: Commensurate with experience
Job Summary: We are seeking a highly skilled Endpoint Automation Engineer to lead enterprise-wide modernization and automation of endpoint management. This role demands deep hands-on expertise in Microsoft Intune, PowerShell automation, Microsoft Entra ID, and endpoint lifecycle automation. The ideal candidate will drive zero-touch provisioning, security compliance, and operational efficiencies.
Key Responsibilities:
- Endpoint Management & Automation
- Lead enterprise deployment/configuration of Microsoft Intune
- Automate device provisioning, compliance, and lifecycle workflows
- Package/deploy apps (Win32, MSIX, LoB); manage Autopilot, PSADT, PPKG
- Create/maintain configuration profiles, compliance policies, and baselines
- Microsoft Entra ID Administration
- Manage Entra ID (Azure AD), implement SCIM, Conditional Access, RBAC
- Strengthen identity governance and compliance
- PowerShell Scripting & Automation
- Build secure, reusable PowerShell scripts for device/app onboarding, compliance remediation, and reporting
- Maintain version-controlled script repository and CI/CD pipelines
- Cloud & M365 Integration
- Leverage Microsoft 365 tools (Defender, Exchange, Teams, etc.)
- Support Azure-based device registration and configuration
- (Preferred) Apply IaC practices using ARM, Bicep, Terraform
- Endpoint Security & Compliance
- Align with CIS benchmarks for Windows 11
- Ensure BitLocker, AV, firewall, and security compliance via policy and automation
- Collaboration & Support
- Act as Tier-3 escalation point for IT End User Services
- Document and enhance EUS workflows through automation
Required Qualifications:
- 5+ years in endpoint automation and modern device management
- Expert-level experience with Microsoft Intune, PowerShell, and Entra ID
- Experience with Windows 10/11, Autopilot, PSADT, and PPKG provisioning
- Familiarity with Microsoft 365 and Azure services for endpoint security
Preferred:
- Certifications: MD-102, AZ-104, SC-300, AZ-400
- Infrastructure as Code (IaC) experience with ARM/Bicep/Terraform
- Exposure to Defender for Endpoint, Log Analytics, and Sentinel