About the job
Join our dynamic IT infrastructure team at prime-system as an Endpoint Systems Engineer, where you will play a pivotal role in managing the lifecycle of endpoint devices across our organization. This position combines elements of security, operations, and automation, guaranteeing that all managed devices are compliant, up-to-date, and functioning optimally. The ideal candidate is adept with RMM tools, skilled in PowerShell automation, and excels in a high-energy managed services or enterprise IT environment.
Key Responsibilities
Endpoint Patching & Compliance
- Deploy, schedule, and validate OS and software patches across Windows/macOS endpoints utilizing Kaseya VSA and Datto RMM.
- Oversee patch policies, rings, and compliance baselines via Microsoft Intune.
- Produce regular patch compliance reports and propose remediation strategies for non-compliant devices.
- Uphold patch SLAs and reduce exposure windows for critical CVEs.
Application Management
- Package, deploy, and sustain third-party applications throughout the endpoint fleet using Intune and RMM tools.
- Manage application versioning, silent installations, and uninstall processes.
- Monitor application health and ensure licensing compliance.
Ticketing & Incident Management
- Triage, manage, and resolve endpoint-related tickets within ConnectWise Manage.
- Document resolution steps clearly for knowledge base contributions.
- Appropriately escalate complex issues while adhering to SLA commitments.
Automation & Scripting
- Develop and maintain PowerShell scripts to automate repetitive tasks like software installations, system health checks, user provisioning, and reporting.
- Deploy scripts via RMM platforms efficiently across managed endpoints.
Asset & Documentation Management
- Ensure accurate endpoint inventory and configuration records through Liongard.
- Keep audit trails, change logs, and runbooks updated.
- Contribute to internal IT documentation and SOPs.
Security & Compliance
- Implement endpoint security standards (antivirus, EDR, encryption, MFA policies).
- Monitor for policy drift and proactively remediate non-compliant devices.
- Collaborate with security teams on vulnerability management and endpoint hardening.
