Endpoint Engineer
- Employment type
- Full-time
- Location
- Switzerland
- First posted
The Endpoint Engineer is a key member of the Endpoint Administration & Protection team, responsible for the management, compliance, protection and lifecycle of corporate endpoints across the organisation. The role brings specialist expertise in macOS and mobile platforms including iOS, iPadOS and Android, complementing the team's existing Windows capabilities. Working primarily with Microsoft Intune and Microsoft Defender for Endpoint, the Endpoint Engineer ensures that endpoints remain secure, compliant, operational and aligned with business and security requirements. The successful candidate is curious, adaptable and proactive, continuously seeking opportunities to improve the endpoint experience, increase automation and strengthen endpoint security posture.
macOS and Mobile Device Management
- Act as the primary technical specialist for macOS, iOS, iPadOS and Android endpoint management.
- Design, implement and maintain device management capabilities using Microsoft Intune and platform-native technologies.
- Manage Apple Business Manager integration, Automated Device Enrollment (ADE) and Apple device lifecycle processes.
- Manage Android Enterprise enrollment models and operational administration.
- Ensure devices are enrolled, compliant, properly configured and supported throughout their lifecycle.
- Troubleshoot complex device management, enrollment and configuration issues across supported platforms.
- Provide technical guidance and documentation for endpoint administrators, Service Desk teams and stakeholders.
Intune Compliance and Configuration Management
- Design, implement and maintain Microsoft Intune configuration profiles, device restrictions and endpoint management policies.
- Develop and maintain device compliance policies and compliance reporting across all supported platforms.
- Support integration between compliance policies and Conditional Access controls in collaboration with Identity and Information Security teams.
- Maintain enrollment methods and provisioning workflows, including awareness of Windows Autopilot processes and integration points.
- Monitor platform health, configuration drift and policy effectiveness.
- Continuously evaluate new Microsoft Intune capabilities and recommend adoption where business value exists.
Endpoint Protection and Microsoft Defender for Endpoint
- Own the operational health and enforcement of Microsoft Defender for Endpoint across Windows, macOS and mobile platforms.
- Ensure Defender onboarding, deployment, policy assignment, reporting and agent health remain at target service levels.
- Implement and maintain endpoint security controls defined by Information Security.
- Monitor protection coverage, health status and deployment gaps across the endpoint estate.
- Produce operational reporting and remediation plans for non-compliant or unprotected devices.
- Collaborate with Security Operations during investigations requiring endpoint visibility or remediation actions.
- Maintain endpoint protection platforms to supported and secure versions.
Information Security defines security standards, baselines and control requirements. This role is responsible for implementing, enforcing, operating and maintaining those controls on endpoint platforms and reporting on compliance, coverage and operational gaps.
Application Packaging and Deployment
- Package, test, deploy and maintain applications through Microsoft Intune for both Windows and macOS devices.
- Manage Win32 applications, MSI deployments, executable wrappers, Microsoft Store applications, Line-of-Business applications and macOS application packages.
- Develop deployment strategies that minimise user disruption and maximise reliability.
- Manage application lifecycle processes including onboarding, updating, supersedence, retirement and removal.
- Support update rings and deployment strategies for operating systems and applications.
- Maintain documentation, testing procedures and deployment standards.
Operations and Continuous Improvement
- Monitor service health, platform performance and compliance metrics across endpoint technologies.
- Investigate root causes of recurring issues and implement permanent corrective actions.
- Identify opportunities for automation, simplification and service improvement.
- Maintain accurate technical documentation, standards and operational procedures.
- Participate in incident resolution, problem management and change processes.
- Stay current with Microsoft roadmap developments, endpoint security trends and modern management practices.
- Take ownership of problems and initiatives through to completion, ensuring solutions are documented and operationally sustainable.
- 4+ years of experience in endpoint engineering, endpoint administration or modern workplace management roles.
- Strong hands-on experience with Microsoft Intune administration and endpoint management.
- Experience managing macOS devices in enterprise environments.
- Experience managing iOS, iPadOS and Android devices using enterprise MDM solutions.
- Strong understanding of device compliance policies, configuration profiles and enrollment methods.
- Experience implementing and operating Microsoft Defender for Endpoint.
- Experience with application packaging and deployment for Windows and macOS platforms.
- Knowledge of Microsoft Entra ID and Conditional Access integration.
- Experience troubleshooting endpoint, operating system and device management issues.
- Strong documentation and operational process discipline.
- Excellent communication and stakeholder management skills.
Desirable Skills
- Scripting experience using PowerShell, Bash, Mac Shell Scripts or Python.
- Experience with Apple Business Manager and Automated Device Enrollment.
- Experience with Windows Autopilot.
- Experience with Jamf Pro or comparable Apple management platforms.
- Experience with endpoint automation and reporting using Microsoft Graph.
- Familiarity with security operations processes and endpoint incident response.
- Microsoft MD-102 certification.
- Microsoft security, endpoint management or modern
Posted today