Sr Staff Endpoint Architect

Western DigitalIrvine, CaliforniaOn-siteFull-timeSenior, 5–8 yearsListed 4 hours ago

Apply now

About this role

Company Description

WD is building the infrastructure behind the AI-driven data economy.

As AI scales, so does data. Every interaction, every model, every system generates data that must be stored, managed, and made accessible over time. That’s where we come in.

We combine deep engineering expertise with global-scale manufacturing to deliver the storage systems that make AI possible, powering hyperscale data centers, cloud platforms, and enterprise infrastructure worldwide.

This isn’t theoretical work. It’s real systems, at real scale, people solving some of the hardest challenges in technology today.

We’re looking for people who want to build, solve, and operate at that level.

Join us and let’s shape the future of data.

Job Description

Position Overview

We are seeking an experienced Sr. Staff Endpoint Architect to lead the strategy, architecture, modernization, and engineering of our global Apple and Windows endpoint platforms.
This role will serve as a senior technical authority for macOS, Windows, iOS, and iPadOS. A key focus will be enabling the responsible expansion of Mac adoption by evaluating employee personas, business workflows, application compatibility, security requirements, support readiness, cost, and employee experience—not simply providing Macs to more users.
The successful candidate will define the future-state endpoint architecture and build secure, scalable, automated, and employee-centered capabilities across the device lifecycle. This individual will partner with Security, Identity, Infrastructure, Networking, Application teams, Service Management, Procurement, and business functions to modernize the endpoint environment and deliver a consistent global employee experience.

Key Responsibilities

Endpoint Strategy and Architecture
•    Define the enterprise endpoint strategy, reference architecture, and modernization roadmap across Apple and Windows platforms.
•    Develop a persona-based device strategy that aligns endpoint selection with job responsibilities, business workflows, application requirements, security, mobility, and employee experience.
•    Lead assessments of applications, workflows, peripherals, and technical dependencies to identify appropriate Mac and Windows use cases.
•    Develop a data-driven roadmap for expanding Mac adoption across qualified employee personas and business functions.
•    Establish standards for endpoint hardware, operating systems, identity, applications, security, compliance, connectivity, and lifecycle management.
•    Evaluate emerging Apple, Microsoft, digital employee experience, automation, and AI capabilities for enterprise use.
•    Present technical recommendations, investment priorities, risks, and progress to technology and business leadership.
Apple and Windows Platform Engineering
•    Architect and modernize Apple device management using Jamf Pro, Microsoft Intune, Apple Business Manager, Automated Device Enrollment, and modern Apple management frameworks.
•    Architect Windows management using Microsoft Intune, Windows Autopilot, Microsoft Configuration Manager, Entra ID, and related cloud-management technologies.
•    Design secure zero-touch provisioning, application delivery, configuration, compliance, recovery, replacement, and decommissioning experiences for both platforms.
•    Define the appropriate use of Jamf, Intune, Configuration Manager, co-management, and cloud-native management within the endpoint ecosystem.
•    Establish operating-system testing, patching, upgrade, enforcement, exception, and vulnerability-response strategies.
•    Architect identity capabilities using Entra ID, Platform SSO, Windows Hello for Business, Conditional Access, passwordless authentication, and certificates.
•    Define endpoint security standards covering FileVault, BitLocker, privileged access, endpoint protection, data protection, recovery keys, local accounts, and device compliance.
•    Engineer scalable application packaging, deployment, updating, and retirement for macOS and Windows applications.
•    Provide senior technical leadership for complex endpoint, identity, security, application, and management-platform issues.
Application Readiness and Device Adoption
•    Establish a device eligibility framework that identifies the appropriate endpoint platform for each employee persona and business use case.
•    Maintain cross-platform application catalogs identifying supported, conditional, incompatible, and remediation-required applications.
•    Partner with application owners and vendors to address compatibility, licensing, authentication, performance, and supportability requirements.
•    Develop solutions for platform-specific dependencies using SaaS alternatives, browser-based applications, modernization, virtualization, Windows 365, Azure Virtual Desktop, or remote application delivery.
•    Lead pilots and phased deployments to validate application readiness, security, supportability, and employee experience.
•    Develop repeatable migration approaches for user data, applications, identity, settings, collaboration tools, and peripherals.
•    Partner with Change Management, Communications, Learning, and Support teams to develop adoption campaigns, training, and migration guidance.
Automation and Modern Endpoint Operations
•    Build an automation-first engineering practice using PowerShell, Bash, Zsh, Python, Microsoft Graph, Jamf APIs, REST APIs, and orchestration platforms.
•    Automate provisioning, application deployment, configuration, compliance, remediation, patching, inventory, reporting, and lifecycle management.
•    Establish source control, peer review, testing, release management, rollback, and documentation standards for endpoint engineering.
•    Use endpoint telemetry and digital employee experience data to proactively identify reliability, performance, compliance, and user-experience issues.
•    Develop self-service and self-healing capabilities that improve employee productivity and reduce support demand.
•    Explore the responsible use of AI and intelligent automation for troubleshooting, compliance analysis, proactive remediation, and endpoint operations.
Operational Readiness and Technical Leadership
•    Ensure Global Service Desk and deskside teams are prepared to support Apple and Windows platforms at enterprise scale.
•    Define support models, escalation paths, diagnostic workflows, knowledge requirements, and engineering-to-operations handoffs.
•    Identify recurring incidents and engineer permanent, scalable solutions.
•    Maintain architecture diagrams, engineering standards, technical decisions, operational procedures, and support documentation.
•    Mentor endpoint engineers, lead technical design reviews, and establish consistent engineering practices.
•    Influence cross-functional architecture, security, application, and investment decisions without relying on direct authority.

Qualifications

Required Qualifications

•    10+ years of experience in endpoint engineering, workplace technology, enterprise infrastructure, or related discipline.
•    Extensive experience architecting and supporting Apple and Windows endpoints in a large, complex, or global enterprise.
•    Demonstrated experience leading an endpoint modernization, Mac adoption, cloud-management, or device-transformation initiative.
•    Deep expertise with Jamf Pro and strong experience with Microsoft Intune, Windows Autopilot, and Microsoft Configuration Manager.
•    Hands-on experience with Apple Business Manager, Automated Device Enrollment, and Apple application management.
•    Advanced knowledge of macOS and Windows architecture, security, configuration, deployment, and troubleshooting.
•    Strong experience with Entra ID, Platform SSO, Windows Hello for Business, Conditional Access, certificates, and passwordless authentication.
•    Advanced automation skills using PowerShell and at least one of the following: Bash, Zsh, Python, Microsoft Graph, Jamf APIs, or REST APIs.
•    Experience implementing enterprise security baselines, encryption, endpoint protection, privileged-access controls, and compliance policies.
•    Experience assessing employee personas, business workflows, application compatibility, and device requirements.
•    Strong knowledge of enterprise networking, including Wi-Fi, VPN, DNS, proxies, certificates, and Zero Trust.
•    Ability to translate business requirements into architecture, roadmaps, execution plans, and measurable outcomes.
•    Strong communication, documentation, stakeholder management, and technical leadership skills.
•    Experience developing device standards, total-cost-of-ownership models, technical pilots, migration programs, and employee enablement.
•    Familiarity with AI-assisted endpoint operations and self-healing capabilities.

Additional Information

Preferred Qualifications

•    Jamf 300 or Jamf 400 certification.
•    Relevant Microsoft, Apple, security, automation, or enterprise architecture certifications.
•    Experience with Jamf Connect, Jamf Protect, Microsoft Defender for Endpoint, or comparable technologies.
•    Experience with declarative device management, Platform SSO, Windows Autopatch, Windows 365, or Azure Virtual Desktop.
•    Familiarity with AutoPkg, Installomator, PSAppDeployToolkit, or similar tools.
•    Experience with digital employee experience platforms, endpoint telemetry, and proactive remediation.
•    Knowledge of CIS, NIST, ISO 27001, SOC 2, or comparable compliance frameworks.

#LI-TD1

Compensation & Benefits Details

- An employee’s pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills, ability, knowledge of the job; (3) performance, contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
- The salary range is what we believe to be the range of possible compensation for this role at the time of this posting.  We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York.  This range may be modified in the future.
- If your position is non-exempt, you are eligible for overtime pay pursuant to company policy and applicable laws.  You may also be eligible for shift differential pay, depending on the shift to which you are assigned.
- You will be eligible to be considered for bonuses under  either WD’s Short Term Incentive Plan (“STI Plan”) or the Sales Incentive Plan (“SIP”) which provides incentive awards based on Company and individual performance, depending on your role and your performance. You may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires, subject to WD's Standard Terms and Conditions for Restricted Stock Unit Awards.
- We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life, accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D, legal plan, pet insurance, critical illness, accident and hospital indemnity; tuition reimbursement; transit; the Applause Program; employee stock purchase plan; and the WD Savings 401(k) Plan.
- Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

Notice To Candidates: Please be aware that WD and its subsidiaries will never request payment as a condition for applying for a position or receiving an offer of employment. Should you encounter any such requests, please report it immediately to  WD Ethics Helpline or email [email protected] .