We’re hiring an M365Endpoint Architect (Windows SOE, Intune, SCCM) to lead the design and delivery of a modern, secure Windows operating environment. You will run design workshops, produce authoritative designs, build and validate the SOE, define and execute the migration approach (Windows 10 to Windows 11), modernize endpoint management with Intune, and orchestrate app packaging and deployment using SCCM/Intune across lab, pre‑prod, and production. This is a hands-on architecture role working closely with client SMEs, a client TDA, security, and support teams without PM duties.
Key Responsibilities
Discovery and design
Run workshops: Lead core and use‑case design workshops; capture requirements, decisions, constraints, and personas.
SOE blueprint: Specify and version Windows 11 SOE (image/lightweight reference), secure baselines, hardening, default apps, policies, and configuration layers.
Policy design: Author device configuration, compliance, and Endpoint Security policies (BitLocker, Defender, Firewall, Account protection including LAPS and WHfB).
Update strategy: Design Windows Update for Business rings, deadlines, and safeguards; driver/firmware approach.
Co‑management sliders: Plan SCCM to Intune workload migration (client apps, compliance, device config, Endpoint Protection, WUfB), with rollback paths.
Application packaging: Define packaging standards and deployment patterns (Win32 + MSIX, detection rules, requirements, PSADT), content delivery, and pilot strategy.
Documentation: Produce Core Endpoint Management Design, Use‑Case Addenda, Test Plans, Migration Playbook, and As‑Built documentation.
Build and validation (lab to production)
Lab build: Stand up lab/DEV; configure Intune tenant components, Autopilot profiles, enrolment restrictions, test identities/devices, and integration touchpoints.
SOE build: Build and validate SOE artifacts (reference configs, provisioning packages where applicable, Autopilot profiles) and app baselines.
Automation: Create PowerShell/Graph automations for packaging, reporting, posture, and remediation.
Testing: Define and execute functional, performance, and user validation; UAT coordination with SMEs; defect triage and remediation.
Identity and access: Entra ID join models (AADJ/HAADJ), Conditional Access impacts on device posture, PKI/certificates for device and Wi‑Fi/VPN auth.
Security controls: BitLocker (MBAM/Key escrow), Microsoft Defender for Endpoint policies, LAPS, WHfB, firewall, device control.
Automation: PowerShell and Microsoft Graph for packaging, reporting, compliance, and remediation.
Enterprise delivery: Lab→pre‑prod→prod promotion, change control, and wave‑based migrations across thousands of endpoints.
Documentation: Authoritative design docs, test plans, runbooks, and as‑built records.
You will be successful in this role if you have:
NV1 Security Clerance is required.
Certifications: MD‑102 (Endpoint Administrator), AZ‑104/AZ‑140 or MS‑102, and/or SC‑200/SC‑100 desirable.
Experience: 7+ years in endpoint engineering/architecture with recent Windows 11 and Intune modern management at enterprise scale.
Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age, caste, citizenship, color, disability, family medical history, family status, ethnicity, gender, gender expression, gender identity, genetic information, marital status, national origin, parental status, pregnancy, race, religion, sex, sexual orientation, transgender status, veteran status or any other category protected by law.
Local employment practices and rights may vary by jurisdiction and are subject to applicable local laws. This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers.
If you are a US job seeker unable to review the job opportunities herein, or cannot otherwise complete your expression of interest, without additional assistance and would like to discuss a request for reasonable accommodation, please contact our Global Recruiting organization at [email protected]. US job seekers can find more information about Unisys’ EEO commitment here.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Australia.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Australia, connecting you to thousands of jobs fast!
Find the best jobs in Australia, apply in 1 click and get a job today!