- Location
- East Brunswick, NJ
- Workplace
- Hybrid, Onsite
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Source
- Pinpoint
Description
Senior Endpoint Engineer
Department: IT
Employment Type: Full Time
Location: East Brunswick, NJ
Description
Trilon is building a supercharged, technology-enabled future for our people and partners. The Senior Endpoint Engineer is the senior technical owner for Trilon's workplace endpoint ecosystem, standards, and operating model across Windows, Apple devices, Microsoft Teams Rooms, and the enterprise copier and plotter fleet.
Reporting to the Vice President, Infrastructure & Operations, this role leads the design, modernization, and reliable operation of endpoint management through Microsoft Intune, Windows Autopilot, Windows Autopatch, Patch My PC, Microsoft Entra ID, Apple Business Manager, and related technologies. The goal is a secure, consistent, measurable, and increasingly zero-touch experience for employees across Trilon partner firms.
This is an individual-contributor technical-lead role, not a formal people-manager position. Working within a small, highly capable engineering function, the role sets technical direction and builds the platforms, automation, standards, and documentation that allow endpoint services to operate reliably at scale. Service Delivery and Field Support retain responsibility for routine incidents, requests, onsite assistance, consumables, and first-line troubleshooting. This role becomes directly engaged when platform design, configuration, vendor coordination, automation, or support processes break down, and serves as the senior technical escalation point for complex or systemic issues.
Key Responsibilities
• Provide hands-on technical leadership, architecture, design review, and practical guidance through expertise and influence, without formal direct-report or performance-management responsibility.
• Establish platform priorities, service ownership, technical standards, cross-training, escalation coverage, and an executable roadmap aligned with enterprise infrastructure and security strategy.
• Serve as the technical authority and senior escalation point for enterprise endpoint management; set technical direction, review engineering work, and maintain an executable roadmap.
• Own endpoint engineering documentation, change control, testing and rollback standards, support handoffs, knowledge transfer, and cross-training so services are repeatable and resilient.
• Establish service metrics and use operational reviews to drive accountability, reliability, security, and continuous improvement.
• Define and maintain enterprise standards for Windows endpoints, including configuration profiles, security baselines, compliance policies, assignment groups, role-based access, and policy exceptions.
• Own Microsoft Intune and Windows Autopilot architecture, including OEM registration, deployment profiles, pre-provisioning, Enrollment Status Page design, reset and redeployment workflows, and zero-touch readiness.
• Design enrollment and migration patterns for cloud-native Microsoft Entra join, hybrid Entra join, automatic MDM enrollment, and legacy-device transition while reducing long-term dependence on on-premises infrastructure.
• Maintain clear targeting and group-design standards and validate that enrollment, assignment, compliance, encryption, and application results are measured separately rather than inferred from group membership.
• Own enterprise management of Mac, iPhone, and iPad devices through Microsoft Intune and Apple Business Manager, including Automated Device Enrollment, supervision, enrollment, configuration and compliance, security, updates, remote actions, mobile application management, and lifecycle.
• Govern Apple platform integrations and controls, including Apple MDM Push certificates, device and MDM server assignments, Apps and Books licensing and location tokens, renewals, administrative access, procurement and reseller assignment, zero-touch setup, inventory, offboarding, secure wipe or recovery, and retirement.
• Own the application packaging lifecycle in Intune, including Win32 packages, PowerShell App Deployment Toolkit (PSADT), requirements, detection rules, dependencies, supersedence, pilot testing, production assignments, remediation, and retirement.
• Use Patch My PC's catalog and Custom Apps capabilities to publish and maintain third-party and specialized applications through Intune; require automated deployment as the standard path and document controlled fallback methods.
• Define the software-delivery model: Required assignments for security and business-critical applications, Company Portal for approved optional or role-specific software, and narrowly scoped blocking applications during Autopilot.
• Develop reliable delivery patterns for large and specialized AEC applications, including Autodesk AutoCAD and Bentley products, measuring end-to-end elapsed time separately from technician labor and improving same-day device readiness.
• Manage Windows Autopatch and update-ring strategy for quality, feature, driver, and firmware updates; monitor results and remediate failed installations and policy exceptions.
• Build and maintain PowerShell, Microsoft Graph, proactive-remediation, API-based, and responsibly governed AI-assisted automation that reduces manual effort, improves engineering throughput, and produces auditable results.
• Partner with Cybersecurity to implement and validate Microsoft Defender for Endpoint, BitLocker, Windows LAPS, Conditional Access device signals, endpoint security policies, and vulnerability remediation.
• Use pilot rings and defined acceptance criteria to test configurations, scripts, applications, and updates before broad production rollout.
• Develop dashboards and reports for enrollment, compliance, encryption, patch posture, deployment success, device health, exception age, and remediation performance.
• Apply least-privilege administration, privileged-role governance, auditability, and separation of duties to endpoint platforms and workflows.
• Maintain authoritative endpoint inventory and reconcile device identity and status across Microsoft Entra ID, Intune, Freshservice, remote-support platforms, procurement records, and vendor portals using durable identifiers.
• Set standards for endpoint models, warranties, leasing, refresh, recovery, reuse, retirement, and secure disposition; partner with Finance, Procurement, and hardware vendors on forecasts and lifecycle execution.
• Monitor asset, enrollment, compliance, encryption, and ownership exceptions and drive them to resolution with accountable owners.
• Own the enterprise architecture, standards, lifecycle, monitoring, documentation, and vendor coordination for Microsoft Teams Rooms, including device configuration, Intune management, account and licensing dependencies, update strategy, room readiness, health reporting, and escalation paths.
• Own governance of Trilon's copier and plotter fleet, including enterprise standards, vendor and contract coordination, secure configuration, print-management dependencies, firmware and lifecycle planning, inventory, usage and service metrics, and replacement strategy.
• Define clear operating boundaries and support handoffs: Service Delivery and Field Support handle routine incidents, requests, consumables, and onsite troubleshooting, while this role addresses systemic failures, recurring problems, complex escalations, platform changes, and breakdowns in vendor or support processes.
• Use monitoring, service data, root-cause analysis, automation, and documented runbooks to reduce recurring support demand and improve the reliability and user experience of workplace technology platforms.
• Lead endpoint discovery, assessment, planning, and migration for newly acquired firms, including inventories, identity and join state, security posture, applications, deployment dependencies, and local support requirements.
• Define phased integration plans that protect employee productivity while moving devices, policies, applications, and operational processes toward Trilon enterprise standards.
• Partner with Service Delivery and Field Support on onboarding, offboarding, office openings, relocations, refresh events, and complex escalations, with clear ownership and support handoffs.
• Communicate technical risks, decisions, progress, and exceptions clearly to IT leadership and business stakeholders.
Skills, Knowledge and Expertise
• 7 or more years of endpoint management, systems engineering, or modern workplace experience, including hands-on responsibility for managing thousands of endpoints through Microsoft Intune and Windows Autopilot in a distributed enterprise environment.
• Demonstrated technical leadership, sound judgment, and the ability to influence technical peers, establish standards, coordinate across teams, and communicate clearly without relying on formal reporting authority.
• Expert-level hands-on experience with Microsoft Intune, Windows Autopilot, Microsoft Entra ID device management, Windows 11, and endpoint policy architecture.
• Strong experience with enterprise software packaging and delivery, including Win32 applications, detection logic, dependencies, deployment rings, and troubleshooting failed installations; experience using PowerShell App Deployment Toolkit (PSADT) is strongly preferred.
• Experience with Windows Autopatch or equivalent update-ring governance and with third-party application and patch automation; Patch My PC experience is strongly preferred.
• Advanced PowerShell skills and practical experience using Microsoft Graph or other APIs for automation, reporting, and operational controls.
• Strong understanding of endpoint security controls, including Microsoft Defender for Endpoint, BitLocker, Windows LAPS, Conditional Access, compliance, least privilege, and vulnerability remediation.
• Experience supporting complex, distributed environments and integrating endpoint operations during mergers, acquisitions, or tenant/domain transitions.
• Ability to reconcile data across device-management, identity, asset, remote-support, and service-management systems, plus experience with hardware lifecycle, leasing, vendor coordination, asset governance, and secure retirement.
• Strong hands-on experience managing Mac, iPhone, and iPad through Microsoft Intune and Apple Business Manager, including automated enrollment, compliance, application delivery, and device lifecycle.
• Experience engineering or governing Microsoft Teams Rooms, including Intune-managed room systems, device health, updates, account and licensing dependencies, monitoring, and support escalation, is strongly preferred.
• Experience governing an enterprise copier, printer, or plotter fleet, including vendor coordination, secure configuration, lifecycle planning, inventory, service performance, and print-management dependencies, is preferred.
• Experience with endpoint equipment warehousing and depot operations, including receiving, secure storage, inventory control, device staging, shipping, returns, and lifecycle logistics, is preferred.
• Experience packaging and deploying complex AEC applications, particularly Autodesk AutoCAD and Bentley products, is preferred.
Benefits
Trilon was formed with the vision of building the next Top 20 infrastructure consulting firm in North America by bringing together some of the nation’s best infrastructure consulting firms, focused on delivering practical and sustainable infrastructure solutions. Trilon is backed by Alpine Investors, a PeopleFirst Private Equity Firm. Trilon currently comprises 5,500+ staff across the US. For more information, visit www.trilon.com.
Pay Transparency
Pay Transparency
The base salary range for this role is indicated in the posting. This range reflects the company’s good faith estimate of the compensation for this position at the time of posting. Final compensation will be determined based on factors such as experience, skills, qualifications, internal equity, and geographic location.
Skills
CybersecurityAutoCADComplianceProcurement