About this role
Role Summary
The Client Operations Support Engineer supports the Device Management & Endpoint Security team in managing and improving the foundation's endpoint fleet, with customer experience, productivity, and security in mind. The role applies sound endpoint and configuration management practices across Windows, macOS, iOS, and Android devices, typically through platforms such as Intune, Windows Autopilot, Tanium, Apple Business Manager, and Samsung Knox, with PowerShell or similar scripting for automation. This person works closely with the Service Delivery team to understand, communicate, and manage priorities in support of modern device delivery.
Day to day, the role covers the device provisioning experience, endpoint administration, application packaging and deployment, patching, and configuration management, while maintaining a safe and secure computing environment. The role also works the DM&ES ticket queue, resolves remote-resolvable escalations from Tier 1, and hands off hands-on work to onsite teams with full diagnostic context.
Strong foundational knowledge of endpoint and configuration management matters more than experience with any single tool. The platforms named in this description are representative of our environment, and candidates who bring solid fundamentals and the ability to learn new tools quickly are encouraged to apply.
Responsibilities
Endpoint Management and Engineering
- Manage endpoints across their full lifecycle (enrollment, configuration, compliance, application deployment, and retirement) on Windows 11, macOS, iOS, and Android, using a modern management platform such as Intune.
- Apply consistent configuration management practices, including baselines, policy design, change testing, and drift detection and remediation.
- Manage macOS and mobile devices, including enrollment programs such as Apple Business Manager and Samsung Knox.
- Work with OEMs to develop, validate, and maintain the zero-touch provisioning experience (for example, Windows Autopilot).
- Package, test, and deploy applications; manage patching, OS servicing, and configuration baselines.
- Use endpoint monitoring and management tools (for example, Tanium) to track patch state, software inventory, and endpoint health.
Security and Compliance
- Monitor and administer endpoint security controls (malware protection, MDM, device compliance policies, and encryption) to improve the health of all mobile and client platforms and meet requirements established in service delivery standards.
- Implement and enforce best practices for endpoint security, endpoint policy, and data protection.
- Build positive working relationships with Information Security partners and Service Delivery teams.
Automation and Quality
- Use PowerShell or similar scripting to automate remediation and reduce manual, repetitive engineering work before Tier 1 and Tier 2 initiate manual remediation.
- Define test and validation plans for policy, application, and OS changes, and use pilot and phased deployment rings to verify results before broad rollout.
- Define and trace requirements for the changes owned, and confirm they are met through documented verification steps.
Operations, Support, and Escalation
- Support the DM&ES ticket queue, including receiving escalations from Tier 1 and leading problem management for unresolved remote-resolvable tickets.
- Escalate issues that need hands-on or deskside intervention to onsite engineers or Tier 1, providing full diagnostic context at handoff.
- Maintain CMDB and asset lifecycle accuracy for managed devices, including accurate ownership, state, and lifecycle records.
- Maintain and improve documentation and knowledge base articles for owned processes and recurring issues.
- Support identity and productivity platform configuration (such as Entra ID and Microsoft 365) as it relates to device management, including group-based assignment, licensing, and conditional access dependencies.
Communication and Coordination
- Report data, communicate, and educate teams on the overall security and health of the endpoint environment.
- Coordinate with the Service Manager and engineering leads to determine priorities, processes, and requirements.
- Coordinate and communicate with customers to ensure the best user experience.
- Anticipate potential issues or bottlenecks and identify possible solutions.
- Liaise with vendors as needed and keep stakeholders up to date on developments.
Required Qualifications and Skills
Foundational Knowledge
- Solid foundation in endpoint management: device lifecycle, operating system administration, provisioning and imaging concepts, and application packaging and deployment.
- Solid foundation in configuration management: baselines, policy-based management, change control, and drift remediation.
- Working knowledge of patch and vulnerability management, endpoint security fundamentals (encryption, malware protection, compliance), and identity and access concepts (directory services, group-based assignment, conditional access).
- Working knowledge of the networking and systems fundamentals that affect endpoints, such as DNS, DHCP, certificates, and VPN.
- Structured, root-cause-oriented troubleshooting, and familiarity with ITSM practices and ticket-based workflows.
- Experience defining requirements and planning verification and test activities for configuration or deployment changes.
Experience
- Bachelor's degree and 2 to 5 years of related experience, or an equivalent combination of education and experience.
- Hands-on experience with Windows 11, macOS, iOS, and Android on a range of hardware form factors.
- Experience with at least one modern endpoint management platform (Intune or an equivalent MDM/UEM). Ability to learn new tools quickly is valued over experience with any specific one.
- Experience with scripting for automation and remediation (PowerShell preferred).
Professional Skills
- Exercises sound judgment within defined procedures and practices to determine appropriate action.
- Builds productive internal and external working relationships.
- Strong written and verbal communication, presentation, and organizational skills.
- Ability to work under project deadlines and schedule constraints.
Preferred Qualifications
- Direct experience with Intune, Windows Autopilot, Tanium, ServiceNow, Apple Business Manager, or Samsung Knox.
- Microsoft certifications such as MD-102 (Endpoint Administrator), SC-300 (Identity and Access Administrator), or AZ-104 (Azure Administrator).
- CompTIA (or similar) certifications such as A+, Security+, and Network+.
- ITIL 4 Foundation.
Success Metrics
Mobile and client service satisfaction is met based on the measures and goals set by the Service Manager and/or Owner:
- Windows OS feature updates: develop and manage servicing plans; 90% or higher deployment and installation success rate.
- Monthly OS quality and security updates: deploy and manage monthly updates; 90% or higher deployment and installation success rate.
- Application updates and deployments: deploy and manage application updates; 90% or higher deployment and installation success rate.
- Hardware security standards (encryption, drivers, firmware, and BIOS): deploy and manage standards; maintain at minimum the latest two major versions as the environment standard.
- Mobile OS security standards (iOS and Android): deploy and manage standards; maintain at minimum the latest two major versions as the environment standard.
Salary Range
$85,120.00 - $134,400.00 USD (Salary)
- Please note that the salary information provided herein is base pay only (gross); it does not include other forms of compensation which may or may not apply to this specific position, namely, performance-based bonuses, benefits-related payments, or other general incentives - none of which are guaranteed, may be subject to specific eligibility requirements, and are wholly within the discretion of Astreya to remit.
- Further, the salary information noted above is a range that consists of a minimum and maximum rate of pay for this specific position. Where an applicant or employee is placed on this range will depend and be contingent on objective, documented work-related considerations like education, experience, certifications, licenses, preferred qualifications, among other factors.
Astreya offers comprehensive b enefits to all Regular, Full-Time Employees, including:
- Medical provided through UHC (PPO, HSA, Surest options) / Medical provided through Kaiser (HMO option only) for California employees only
- Dental provided through UHC
- Nationwide Vision provided by UHC
- Flexible Spending Account for Health & Dependent Care
- Pre-Tax Account for Commuter Benefit/Parking & Transit (location-specific)
- Continuing Education and Professional Development via various integrated platforms, e.g. Udemy and Coursera
- Corporate Wellness Program provided by Goomi Group
- Employee Assistance Program
- Wellness Days
401k Plan
- Basic and Supplemental Life Insurance
- Short Term & Long Term Disability
- Critical Illness, Critical Hospital, and Voluntary Accident Insurance
- Tuition Reimbursement (available 6 months after start date, capped)
- Paid Time Off (accrued and prorated, maximum of 120 hours annually)
- Paid Holidays
- Any other statutory leaves, paid time, or other ancillary benefits required under state and federal law
