What are the responsibilities and job description for the Senior Microsoft Intune Engineer (macOS, Apple, & Windows Engineering Specialist) position at Ender-IT?
Senior Microsoft Intune Architect (macOS, Apple, & Windows Engineering Specialist)
Duration: 12 Months
Bridgewater, NJ ( 3 days onsite)
12 Months | 40,000 Devices
We are seeking a hands-on Engineer to lead the design, implementation, and engineering of an enterprise-grade Apple and Windows management environment within Microsoft Intune. You will own the technical strategy for a massive, dual-platform fleet (macOS and Windows), ensuring seamless integration with Apple Business Manager, Windows Autopilot, and modern deployment workflows across a large global tenant.
π Key Responsibilities
- Design and lead the technical architecture for both macOS/iOS (leveraging Apple Business Manager and Automated Device Enrollment) and Windows 10/11 endpoints within a unified Microsoft Intune environment.
- Drive the engineering strategy for the Windows fleet, including advanced Group Policy (GPO) migration to Intune, Co-Management strategies, Configuration baselines, and custom Administrative Templates (ADMX).
- Implement Declarative Device Management (DDM) and Platform SSO for macOS, while simultaneously scaling Windows Autopilot for a true "Zero Touch" deployment across all hardware types.
- Design configuration profiles (system extensions, kernel extensions, TCC) and custom scripts (Shell, Bash, and PowerShell) to manage complex macOS and Windows settings not natively available in the Intune UI.
- Drive the end-to-end strategy for application packaging and deployment across both platforms using PKG, DMG, and VPP for Mac, alongside MSI, MSIX, Win32 apps (IntuneWin), and third-party patching tools for Windows.
- Integrate Intune with Azure AD (Entra ID) and Conditional Access to enforce strict compliance-based access control for both Apple and Windows endpoints.
- : Establish rigorous endpoint security controls including FileVault for Mac, BitLocker encryption for Windows, Microsoft Defender for Endpoint across all platforms, and Gatekeeper/AppLocker management.
Qualifications
- 5 years of experience architecting Microsoft Intune specifically for both macOS and Windows at a massive enterprise scale (10,000 nodes per platform).
- Expert-level understanding of Windows 10/11 architecture, Windows Autopilot, Windows Update for Business (WUfB), Delivery Optimization, and registry/GPO management.
- Deep Knowledge: Expert-level understanding of Apple-specific frameworks (APNs, ADE, VPP, and Configuration Profiles).
- Highly proficient in PowerShell for Intune/Graph API automation and Windows customization, as well as Bash/Zsh for macOS customization.
- Security: Strong background in Microsoft Defender for Endpoint and Conditional Access.
- Environment: Experience in Manufacturing/Lab environments is a plus.