- Salary
- $130k – $155k
- Location
- Chicago - IL - 200 N. La Salle St - Suite 1700, United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Bachelor
- Source
- Workday
Description
ABOUT US
At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.
HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions
Responsibilities
Platform Administration and Fleet Operations
- Own the day-to-day operation of NinjaOne across approximately 25,000 Windows endpoints on Lenovo standard hardware, covering HUB's 600-plus locations across the United States and Canada
- Maintain NinjaOne agent health, version currency, policy assignments, and organization structure across the full fleet
- Manage the application catalog, application lifecycle, and deployment assignments, ensuring each application has exactly one primary owner across NinjaOne and Intune with no overlap
- Configure and maintain Autopilot orchestration and provisioning workflows within NinjaOne
- Perform quarterly coexistence reviews with EUC, SecOps, and the Tanium platform team to validate agent versions, policy exclusions, Zscaler bypass entries, and catalog ownership
- Resolve coexistence issues across the stack including Zscaler SSL bypass, SentinelOne exclusion configuration, Tanium Threat Response exclusions, and Intune Management Extension conflicts
Capability Expansion and Approval Program
- Own the technical documentation and capability justification for each of the six pending NinjaOne capability approvals, working with Engineering leadership and Security
- Drive capability activation, policy build, and rollout for each approved module once cleared
- Build and maintain the application-layer patching program using NinjaOne's 200-plus application patch engine once the Automated Patch Management capability is approved
- Maintain a clean, properly structured NinjaOne environment as the hard pre-requisite for production fleet rollout
Scripting, Automation, and Runbooks
- Build and maintain a library of NinjaOne automation scripts in PowerShell, covering routine maintenance, provisioning, remediation, and compliance enforcement
- Author and maintain monitoring policies and alert configurations that surface actionable signal without false-positive noise, in coordination with the Nexthink team
- Collaborate with the DEX team on Amplify remote actions that leverage NinjaOne scripting and remote action capabilities as part of the L1 ticket deflection program
- Document all scripts, policies, and runbooks to SOC 2 standard, ensuring every automated action has an associated KB article before scale deployment
Data Lake Integration
- Design, build, and maintain the NinjaOne extraction pipeline to HUB's Microsoft Fabric data lake using the NinjaOne REST API v2 with OAuth 2.0 client-credentials (monitoring scope only), cursor-based pagination, and updatedAfter incremental filters
- Coordinate on entity resolution, joining NinjaOne records to Nexthink records via hardware serial number, hostname, and logged-on user UPN to build the unified golden device record
- Monitor pipeline health, handle API version changes, implement backoff on rate limits, and maintain extraction schema documentation
- Maintain monitoring-scope-only credential posture with secrets managed in Azure Key Vault and following SOC 2 credential rotation standards
CMDB and ServiceNow Integration
- Own the NinjaOne to ServiceNow CMDB bidirectional sync, ensuring device state, software inventory, and operational changes flow automatically between platforms
- Resolve CMDB drift and data quality issues in coordination with the ServiceNow platform team
- Maintain IAM compliance on device deletion rights and role-based access controls within the NinjaOne console
Governance, Compliance, and Documentation
- Maintain NinjaOne documentation to SOC 2 audit standard including access controls, change records, policy history, and exception tracking
- Support quarterly and annual coexistence audits including end-to-end installation walkthroughs, exclusion accuracy verification, and tabletop troubleshooting exercises
- Participate in the patching governance RACI contributing EUC endpoint perspective on patch ring design, advancement criteria, and compliance reporting
Requirements
- Four or more years of hands-on experience administering NinjaOne or a comparable enterprise RMM platform such as Datto RMM, N-able, or Kaseya at scale
- Deep experience with NinjaOne specifically — policy configuration, monitoring and alerting, scripting and automation, application catalog management, and console administration
- Strong PowerShell scripting including production automation, error handling, logging, and integration with external APIs
- Working knowledge of the Windows endpoint security and management stack with hands-on experience across at least two of the following: Microsoft Intune, SentinelOne, Zscaler, Tanium, or equivalent platform
- Experience with REST API integration including OAuth 2.0 client-credentials flows, cursor-based pagination, incremental filters, and webhook handling
- Understanding of enterprise patch management principles including ring-based deployment, compliance reporting, and controlled rollback
- Ability to operate in an enterprise governance environment including change management, RACI-aligned accountability, and audit-facing documentation
Nice to Have
- Direct experience configuring NinjaOne coexistence with Zscaler ZIA and ZCC including SSL inspection bypass policy and domain allowlisting
- Experience with the NinjaOne to ServiceNow CMDB integration or bidirectional sync from any RMM to a CMDB platform
- Familiarity with Microsoft Fabric, Azure Data Lake Storage Gen2, or Fabric Data Factory for building REST-based data pipelines
- Experience operating within a SOC 2 Type II audit framework including evidence collection, access control documentation, and control testing
- Familiarity with Nexthink Infinity or a comparable DEX platform
- Experience with Lenovo enterprise hardware and Windows Autopilot provisioning workflows
- NinjaOne certification or documented advanced platform training
- Familiarity with Microsoft Defender for Endpoint and dual-agent management alongside a contracted EDR platform
Teamwork and Collaboration
- Communicate technical concepts clearly to both technical and non-technical stakeholders including Engineering leadership and Security reviewers
- Work cross-functionally with the EUC, DEX, SecOps, Tanium, and ServiceNow teams to maintain platform boundaries and deliver shared goals
- Participate actively in team rituals — sprint readouts, retrospectives, and planning sessions — and contribute to a culture of continuous improvement
- Share knowledge through documentation, internal KB articles, and peer mentoring, holding the standard that every automation ships with a runbook
- Give and receive constructive feedback in technical design discussions and coexistence reviews
- Adapt to shifting priorities and support teammates during high-pressure incidents or capability rollouts
- Unified asset and experience view used for proactive remediation and executive reporting
JOIN OUR TEAM
Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International, you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.
The expected salary range for this position is $ 130,000 to $155,000 and will be impacted by factors such as the successful candidate’s skills, experience and working location, as well as the specific position’s business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.
Department Information TechnologyRequired Experience: 5-7 years of relevant experienceRequired Travel: NegligibleRequired Education: Bachelor's degree (4-year degree)HUB International Limited is an equal opportunity employer that does not discriminate on the basis of race/ethnicity, national origin, religion, age, color, sex, sexual orientation, gender identity, disability or veteran's status, or any other characteristic protected by local, state or federal laws, rules or regulations.
We endeavor to make this website accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the recruiting team [email protected]. This contact information is for accommodation requests only; do not use this contact information to inquire about the status of applications.