Intune Architect
PCI Professional Services is seeking an Intune Architect for an upcoming opportunity. This position is remote and reports to the Program Manager. Responsibilities:
PCI Professional Services is seeking an Intune Architect for an upcoming opportunity. This position is remote and reports to the Program Manager. Responsibilities:
- Design and lead the end to end Microsoft Intune architecture for a large federal enterprise, establishing secure modern management patterns across Windows, iOS/iPadOS, and Android.
- Define security baselines and conditional access guardrails
- Engineer a Blackberry UEM → Intune migration and co management strategy (SCCM/Configuration Manager)
- Stand up technical governance (standards, patterns, and guardrails) to keep the environment compliant, resilient, and cost effective.
- Partners with Security, Identity, Networking, Client Engineering, and PMO to deliver a Zero Trust aligned endpoint platform.
- Bachelor's degree in a related discipline
- Minimum 8 years experience in relevant field.
- Experience: 7–10+ years in endpoint management; 3–5+ architecting Intune at enterprise scale (10k+ devices or federal programs).
- Intune & Modern Management (Expert): Autopilot provisioning, device compliance, configuration profiles, application lifecycle (Win32/MSIX/MAM), update rings, and RBAC/scopes.
- Security & Compliance: Conditional Access design, BitLocker governance, Microsoft Security Baselines, Defender for Endpoint integration, threat & vulnerability workflows.
- Entra ID & Identity: Azure AD/Entra ID tenant administration, user/group design, SSO (SAML/OIDC), device identities, certificate/PKI integration.
- Automation: PowerShell scripting; configuration as code mindset; build reusable modules and reporting.
- Mobile Management (MDM/MAM): MAM/app protection policies, conditional launch controls.
- Co Management & Migration: Hands on experience transitioning SCCM/Configuration Manager to cloud based Intune; defining co management workloads and phased cutovers.
- Delivery: Demonstrated ability to lead pilots, wave plans, and executive level briefings; strong documentation and stakeholder management.
- Public Trust (or higher) clearance eligibility
- Zero Trust architecture and NIST 800 53 control mapping for endpoints; familiarity with FedRAMP/ATO processes.
- Win32 packaging at scale (IntuneWin, detection rules, dependencies), app remediation, and Autopatch/Update rings optimization.
- Advanced CA design (session controls, sign in risk, compliant network locations), Entra ID P2 features (Identity Protection, Access Reviews).
- Defender for Endpoint advanced hunting (KQL), attack surface reduction (ASR), tamper protection, and automated response playbooks.
- Enterprise certificate management (device certs, SCEP/PKCS), Wi Fi/VPN profiles, and network pre requisites.
- Terraform/Bicep or pipeline driven deployments for repeatable config; Git based governance for profiles/policies.
- Incident response and DR runbooks for endpoint outages; executive communications and change management expertise.
- Prior federal client experience.
PI286486714