waypointjobs

Tier One Technologies

Microsoft Windows Engineer

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Overview

The Microsoft Windows Engineer serves as the lead technical specialist for the Microsoft endpoint and identity ecosystem supporting this effort, including Windows workstation engineering, Intune, Windows Autopilot, Group Policy, Entra ID/Active Directory integration, passwordless authentication, hardware-backed credentials, and Windows endpoint telemetry.

This role is responsible for engineering secure Windows endpoint baselines, device provisioning and compliance workflows, authentication and access controls, and the operational integration of Windows devices into the company's security monitoring and incident response framework.

Responsibilities

Design, maintain, and secure Windows workstation images supporting both on-site and remote/VDI users.

Engineer Windows endpoint baselines, policy settings, compliance configurations, and patch orchestration mechanisms using approved Microsoft technologies.

Administer and optimize Microsoft Intune, Windows Autopilot, Group Policy, and associated endpoint compliance and configuration controls.

Support implementation of passwordless authentication, hardware-backed credentials (e.g., YubiKeys, CAC, software keys), and other protections for privileged and sensitive accounts.

Integrate endpoint enrollment and conditional access controls with Entra ID / Active Directory to ensure devices are securely configured before receiving access.

Support device lifecycle operations including provisioning, compliance enforcement, reassignment, and decommissioning for Windows endpoints.

Engineer and validate Windows endpoint logging, monitoring, and telemetry, including Windows Event Logs, endpoint agents, and SIEM/EDR forwarding.

Coordinate Intune/GPO-based patch orchestration, policy enforcement, and remediation of Windows configuration drift.

Produce documentation, standards, runbooks, validation artifacts, and technical guidance related to the Microsoft endpoint environment.

Support escalated incident response, troubleshooting, and audit activities involving Windows devices and Microsoft-managed endpoint services.

Qualifications

Core Qualifications:

Bachelor’s degree in IT, Cybersecurity, or related field preferred; equivalent experience acceptable

Must possess an active or interim Top Secret security clearance

8 years of experience in IT, Endpoint Engineering, or Cybersecurity

6 years of experience performing engineering functions in enterprise environments

Experience working under formal change control, audit, and security governance processes

Additional Qualifications:

Experience with Microsoft Intune for provisioning, compliance, configuration profiles, and security policy enforcement

Experience with Windows Autopilot for automated provisioning and device lifecycle management

Experience with Group Policy Objects (GPO) for Windows configuration and policy delivery

Experience with Entra ID / Active Directory integration, conditional access, and device/user association workflows

Experience building and maintaining Windows workstation images

Experience integrating Windows images with VDI, EDR, authentication tools, and logging agents

Experience managing Windows patch orchestration, baseline enforcement, and configuration drift remediation

Experience validating patch deployments and supporting rollback procedures

Experience implementing passwordless authentication and hardware-backed credentials

Experience configuring and maintaining Windows Event Logs and forwarding telemetry to SIEM/EDR platforms such as Microsoft Sentinel

Experience monitoring enrollment, patch status, compliance posture, and operational failures across Windows endpoints

Experience supporting audit readiness, forensic support, and technical validation reporting

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job