Lead Mobility Engineering SME

AIGNew York City, Charlotte, Atlanta, New York, North Carolina, GeorgiaOn-siteFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

At AIG, we are reimagining the way we help customers to manage risk. Join us as a Lead Mobility Engineering SME  to play your part in that transformation. It’s an opportunity to grow your skills and experience as a valued member of the team.

Make your mark in Information Technology

At AIG, technology is at the heart of everything we do, from underwriting risks to processing claims. The Information Technology (IT) team equips our colleagues with the latest tools to complete their work efficiently, with the highest standards of excellence. The team is responsible for shielding the company’s systems from security risks, while designing technology strategies that enable AIG’s businesses to achieve their goals. Innovation in IT drives innovation across the organization.

How you will create an impact

The Lead Mobility Engineering SME is the senior hands-on engineer accountable for the architecture, engineering, security, automation, and operational health of the enterprise mobile and modern endpoint ecosystem — Microsoft 365 mobile services, Microsoft Intune, MDM and MAM, Apple iOS/iPadOS, Android Enterprise, and modern Windows provisioning including Autopilot. This is not a coordination or console-administration role, and it is deliberately not a single-discipline one: the estate depends on mobility platform engineering, modern authentication, endpoint security and network connectivity, and automation, and strength across all four is the bar. The role designs, builds, tests, automates, troubleshoots to root cause, documents, and leads controlled production change end to end.

Mobility platform engineering. Own the architecture and configuration standards for Intune, enrollment, MAM and app protection, compliance policies, configuration profiles, app deployment, certificates, and secure access. Own the Apple stack end to end — Apple Business Manager, Automated Device Enrollment, APNs certificate lifecycle, VPP, supervision, Declarative Device Management, managed software updates — and Android Enterprise in every mode: fully managed, dedicated/kiosk, COPE, and work profile, including managed Google Play, zero-touch enrollment, OEMConfig and Knox. Define compatibility, ring-based rollout, and lifecycle plans so major OS releases are planned events, not fire drills.

Multi-platform UEM breadth. Apply working knowledge of other enterprise mobility platforms — Omnissa Workspace ONE UEM (formerly VMware Workspace ONE / AirWatch), MobileIron/Ivanti Neurons, Jamf, SOTI or BlackBerry UEM — to migration, coexistence, and platform-selection decisions, and translate legacy profile, policy, and app configurations into their modern Intune equivalents without loss of control coverage.

Modern authentication and identity. Engineer device authentication across Entra ID registration, Entra join and hybrid join, Primary Refresh Token behavior, device-based Conditional Access, and token and session controls. Deliver passwordless and phishing-resistant authentication on mobile — platform credentials, FIDO2 and passkeys, certificate-based authentication, Authenticator broker behavior. Own certificate infrastructure: SCEP and PKCS, the Intune Certificate Connector, Cloud PKI, NDES, trusted roots, and renewal automation. Design Conditional Access and prove blast radius in report-only mode before production. Debug OAuth 2.0, OIDC, SAML, and MSAL failures at protocol level.

Modern endpoint management and Autopilot. Own Windows Autopilot end to end — user-driven and self-deploying modes, pre-provisioning, Autopilot device preparation, Enrollment Status Page tuning, hardware hash and attestation, and the OEM supply process. Operate settings catalog, security baselines, filters, scope tags and RBAC, Windows Update for Business and Autopatch rings. Retire legacy through co-management transition and GPO migration. Own Win32 and MSIX packaging, detection logic, and supersedence chains.

Security and governance. Engineer controls with Cybersecurity, IAM, Privacy and Legal: compliance, app protection, DLP, encryption, and certificate-based access. Integrate Defender for Endpoint and mobile threat defense signal into compliance and Conditional Access; apply ASR rules and jailbreak and root detection. Own key escrow, device wipe and departure lifecycle, Endpoint Privilege Management and LAPS. Maintain secure baselines, remediate drift and unsupported OS versions to defined targets, and supply audit evidence from reporting rather than screenshots.

Network engineering for mobility. Design and troubleshoot 802.1X and EAP-TLS Wi-Fi, RADIUS and NPS integration, roaming and captive portal behavior; per-app and always-on VPN, Global Secure Access and ZTNA patterns, and split-tunneling decisions. Diagnose DNS, proxy and TLS inspection effects on certificate pinning and push notifications, APNs and FCM egress, IPv6, and carrier and eSIM behavior — converting a capture or trace into a configuration change rather than a handoff.

Automation and engineering practice. Automate with PowerShell, Microsoft Graph, REST and JSON: bulk policy deployment, lifecycle operations, compliance and expiry reporting, and drift detection against baseline. Apply source-controlled policy-as-code with peer review and promotion across rings. Close operational loops with Power Automate, Azure Automation or Functions, proactive remediations, and ITSM integration. Build proactive monitoring and alerting for enrollment failure, noncompliance, deployment error and service degradation.

Change, operations, and technical leadership. Own changes from scope and impact through test evidence, pilot, implementation, validation, communications and tested backout. Lead Tier 3/4 troubleshooting and root-cause analysis; drive vendor escalations with complete diagnostic evidence. Maintain architecture diagrams, designs, runbooks and decision records complete enough for another qualified engineer to operate and recover the service. Mentor engineers, set engineering quality standards, and maintain a prioritized roadmap and technical debt backlog.

What you'll need to succeed

- 7+ years in endpoint, mobility, or digital workplace engineering, with significant ownership of enterprise mobile services in a large or complex environment.
- Deep hands-on Intune engineering: enrollment, compliance, configuration profiles, app deployment, app protection, reporting, troubleshooting.
- Strong MDM and MAM architecture knowledge across corporate-owned and BYOD scenarios, plus iOS/iPadOS and Android Enterprise management models and OS lifecycle.
- Hands-on exposure to at least one additional UEM platform such as Workspace ONE UEM (AirWatch), Ivanti/MobileIron, Jamf or SOTI, including migration or coexistence work.
- Modern Windows provisioning experience including Autopilot, ESP troubleshooting, and update ring strategy.
- Entra ID, modern authentication, Conditional Access dependencies, and certificate-based secure access.
- Practical mobility network competence: 802.1X and certificate-based Wi-Fi, VPN and per-app VPN, DNS, proxy and TLS inspection effects.
- Demonstrated automation with PowerShell, Graph, REST APIs and JSON, and root-cause troubleshooting using logs, telemetry and structured testing.
- Enterprise change, incident and problem discipline, high-quality technical documentation, and clear communication to technical and nontechnical stakeholders.

Preferred Qualifications

- Advanced End-to-end ownership of the  Microsoft Intune platform  — design, engineering, and Tier 3/4 support across tenant and RBAC architecture, enrollment, policy, app deployment, and certificate services — with equivalent hands-on design, engineering and support experience on  Omnissa Workspace ONE UEM (AirWatch) .
- Deep mobile platform specialization — Apple Business Manager and Declarative Device Management at scale, Android Enterprise dedicated and kiosk fleets, mobile threat defense, and zero-touch provisioning.
- Large-scale UEM migration into Intune — from Omnissa Workspace ONE UEM (AirWatch) or Ivanti/MobileIron — including policy mapping, app re-packaging, and phased device cutover.
- Telecom and carrier or eSIM integration, passwordless authentication on mobile, or legacy VPN retirement.
- Experience in a global, highly regulated, or large-enterprise environment; frontline and shared-device populations alongside corporate users.
- Certifications such as MD-102, SC-300, SC-200 or SC-100, Apple Certified IT Professional, Android Enterprise Professional, or CCNA.

Ready to make a bigger impact? We look forward to reviewing your application.

•        #LI-CN1

•        #Cybersecurity #InfoSec

For positions based in New York, NY, the base salary range for this position is $150,000 – $190,000 and the position is eligible for a bonus in accordance with the terms of the applicable incentive plan.

Your actual compensation will be dependent on your skills, experience, and qualifications.  If your compensation expectations are above the posted range, we still encourage you to apply—your unique background matters to us.  In addition, we’re proud to offer a range of competitive benefits, a summary of which can be viewed here: US Benefits Overview .

At AIG, we value in-person collaboration as a vital part of our culture, which is why we ask our team members to be primarily in the office. This approach helps us work together effectively and create a supportive, connected environment for our team and clients alike.

Enjoy benefits that take care of what matters

At AIG, our people are our greatest asset. We know how important it is to protect and invest in what’s most important to you. That is why we created our Total Rewards Program, a comprehensive benefits package that extends beyond time spent at work to offer benefits focused on your health, wellbeing and financial security—as well as your professional development—to bring peace of mind to you and your family.

Reimagining insurance to make a bigger difference to the world

American International Group, Inc. (AIG) is a global leader in commercial and personal insurance solutions; we are one of the world’s most far-reaching property casualty networks. It is an exciting time to join us — across our operations, we are thinking in new and innovative ways to deliver ever-better solutions to our customers. At AIG, you can go further to support individuals, businesses, and communities, helping them to manage risk, respond to times of uncertainty and discover new potential. We invest in our largest asset, our people, through continuous learning and development, in a culture that celebrates everyone for who they are and what they want to become.

Welcome to a culture of inclusion

We’re committed to creating a culture that truly respects and celebrates each other’s talents, backgrounds, cultures, opinions and goals. We foster a culture of inclusion and belonging through learning, cultural awareness activities and Employee Resource Groups (ERGs). With global chapters, ERGs are a cornerstone for our culture of inclusion. The talent of our people is one of AIG’s greatest assets, and we are honored that our drive for positive change has been recognized by numerous recent awards and accreditations.

AIG provides equal opportunity to all qualified individuals regardless of race, color, religion, age, gender, gender expression, national origin, veteran status, disability or any other legally protected categories.

AIG is committed to working with and providing reasonable accommodations to job applicants and employees with disabilities.  If you believe you need a reasonable accommodation, please send an email to [email protected] .

Functional Area:
IT - Information Technology