Endpoint Engineer Hybrid (2 Openings)
Palo Alto, CA - USA
Job Summary
Duration: 6 Months
Location: Onsite Palo Alto CA
- Apple (macOS & iOS): Jamf Pro
- Windows & Android: Microsoft Intune / Endpoint Manager
- Virtual Desktop: Amazon WorkSpaces (AWS)
- Scripting: PowerShell Bash Python
- Daily Operations: Perform daily upkeep system maintenance and regular patch management for all managed endpoints to ensure security and stability.
- Service Desk Escalation: Serve as the final point of contact and subject matter expert for service desk escalations related to complex endpoint issues.
- Apple Fleet: Architect and maintain the Jamf Pro environment for all macOS and iOS devices. Manage configuration profiles policies and patch management.
- Windows & Android: Lead the administration of Microsoft Intune ensuring robust policy application security baselines and application delivery.
- Provisioning: Manage Apple Business Manager (ABM) and Windows Autopilot to deliver a true zero-touch deployment experience.
- Administer and optimize Amazon WorkSpaces.
- Manage WorkSpaces directories custom bundles and image creation/maintenance.
- Troubleshoot connectivity and performance issues within the AWS ecosystem.
- Develop and maintain sophisticated scripts in PowerShell and Bash to automate manual tasks and integrate system APIs.
- Build and maintain a library of packaged software (dmg pkg msi) for silent deployment.
- Implement automated reporting for hardware inventory license compliance and security auditing.
- Enforce endpoint security standards including FileVault/BitLocker encryption and EDR agent health.
- Partner with Security teams to remediate vulnerabilities across the endpoint fleet.
- Experience: Minimum 3-5 years in an Endpoint Engineering or MDM-focused role.
- Jamf Mastery: Proven experience managing both macOS and iOS at scale via Jamf Pro.
- Intune Proficiency: Experience managing Windows environments through Microsoft Endpoint Manager.
- VDI Expertise: Hands-on experience with Amazon WorkSpaces administration.
- BYOD Deployment: Experience deploying and managing a Bring Your Own Device (BYOD) program for personal mobile phones (iOS/Android).
- Advanced Scripting: Ability to write and debug Bash and PowerShell scripts from scratch.
- Identity: Understanding of Okta or Azure AD (Entra ID) as it relates to device enrollment and SSO.
- Bachelors degree in Computer Science IT or equivalent professional experience.
- Relevant certifications (e.g. Jamf 200/300 Microsoft MD-102 or AWS Certified Cloud Practitioner) are a plus.
- Experience deploying Glean or similar AI-powered enterprise search platforms including connector configuration SSO integration (Okta/Azure AD) and end-user onboarding at scale.
- Familiarity with deploying Claude Code or GitHub Copilot to engineering teams including managing licensing IDE plugin distribution via MDM (Jamf/Intune) and API key or credential management through secure vaulting solutions.
- Experience rolling out AI desktop or productivity agents such as Claude Cowork including packaging and silent deployment managing update cadences and coordinating with IT Security to ensure compliance with data handling policies.
- Understanding of the endpoint and identity considerations unique to AI tools: network allowlisting for LLM API endpoints DLP policy tuning for AI-generated content user provisioning workflows and communicating rollout plans across IT Security and end-user teams.
About us: DivIHN the IT Asset Performance Services organization provides Professional Consulting Custom Projects and Professional Resource Augmentation services to clients in the Mid-West and beyond. The strategic characteristics of the organization are Standardization Specialization and Collaboration. DivIHN is an equal opportunity employer. DivIHN does not and shall not discriminate against any employee or qualified applicant on the basis of race color religion (creed) gender gender expression age national origin (ancestry) disability marital status sexual orientation or military status.