About the job
The Endpoint Systems Engineer plays a vital role within our IT infrastructure team, overseeing the lifecycle management of all endpoint devices throughout the organization. This position integrates security, operations, and automation, ensuring that every managed device is compliant, up-to-date, and functioning optimally. The ideal candidate will be proficient in RMM tools, skilled in PowerShell scripting for automation, and excel in a dynamic managed services or enterprise IT setting.
Key Responsibilities
Endpoint Patching & Compliance
- Deploy, schedule, and validate operating system and software patches across Windows/macOS endpoints using Kaseya VSA and Datto RMM.
- Manage patch policies, rings, and compliance baselines through Microsoft Intune.
- Generate periodic patch compliance reports and propose remediation strategies for devices that do not meet compliance standards.
- Adhere to patch service level agreements (SLAs) and minimize exposure windows for critical Common Vulnerabilities and Exposures (CVEs).
Application Management
- Package, deploy, and maintain third-party applications across the endpoint fleet utilizing Intune and RMM tools.
- Oversee application version control, silent installations, and uninstallation processes.
- Monitor application health and ensure compliance with licensing agreements.
Ticketing & Incident Management
- Triage, manage, and resolve endpoint-related support tickets using ConnectWise Manage.
- Document resolution steps clearly for knowledge base contributions.
- Appropriately escalate complex issues while upholding SLA commitments.
Automation & Scripting
- Create and maintain PowerShell scripts to automate repetitive tasks such as software installations, system health assessments, user provisioning, and reporting.
- Develop and deploy scripts via RMM platforms for large-scale application across managed endpoints.
Asset & Documentation Management
- Keep accurate records of endpoint inventory and configuration through Liongard.
- Ensure audit trails, change logs, and runbooks are consistently updated.
- Contribute to internal IT documentation and standard operating procedures (SOPs).
Security & Compliance
- Enforce endpoint security standards, including antivirus, EDR, encryption, and multi-factor authentication (MFA) policies.
- Proactively monitor for policy deviations and resolve non-compliant devices.
- Collaborate with security teams on vulnerability management and endpoint hardening initiatives.
