InTune Endpoint Engineer

3 days ago

Torrance, CA, United States Milestone Technologies, Inc. Full-time
InTune Endpoint Engineer
ONSITE TORRANCE, CA - MUST BE CURRENTLY LOCAL TO TORRANCE.

Focus:  Microsoft Intune, Microsoft Entra ID, Windows Autopilot, certificate-based authentication, device hardening, and cross-platform endpoint governance, while also supporting integrations for Apple, Android, and third-party PKI/RADIUS solutions.

This is a 6+ month W2 ONLY contract 
Fully onsite in Torrance. 
Rate range is 80-100/hr


MUST BE A U.S. Person status as defined by ITAR (22 CFR 120.15), due to access to export-controlled technical data. (US Citizen or Green Card - no EAD)

We are seeking an experienced InTune Endpoint Engineer to lead the design, implementation, and validation of modern device management and security capabilities across Windows and other major endpoint platforms.

This role will focus on Microsoft Intune, Microsoft Entra ID, Windows Autopilot, certificate-based authentication, device hardening, and cross-platform endpoint governance, while also supporting integrations for Apple, Android, and third-party PKI/RADIUS solutions.

The ideal candidate is a hands-on technical specialist who can translate business and security requirements into scalable endpoint architectures, implement solutions in production, and support pilot-to-rollout execution with strong documentation and stakeholder coordination.

Key Responsibilities
Intune Quickstart
  • Lead discovery and design workshops to confirm tenant configuration, device platforms, enrollment models, and target-state policy architecture.
  • Produce a configuration design document for review and approval prior to build.
  • Configure Microsoft Intune tenant settings
  • Design and implement Entra ID dynamic device and user group architecture to support policy, application, and Conditional Access targeting.
  • Configure Windows Autopilot for cloud provisioning
  • Configure Windows enrollment for Microsoft Entra ID joined devices, including Company Portal deployment and user-driven enrollment.
  • Package and deploy a representative set of applications using reusable deployment patterns.
  • Manage pilot deployment to agreed pilot device groups, including validation, remediation, and sign-off before production rollout.

EZ PKI and EZ RADIUS Integration
  • Lead integration design for certificate authority topology, certificate templates, and SCEP-based certificate issuance for Intune-managed devices.
  • Configure Intune certificate integration with EZ PKI, including connector or API integration as required.
  • Create and deploy trusted root and intermediate certificate profiles for all managed platforms.
  • Design and configure device and user certificate profiles
  • Integrate EZ RADIUS with Intune-managed devices to enable certificate-based EAP-TLS authentication for Wi-Fi and VPN.
  • Define authorization policies based on Entra ID group membership and Intune device compliance state.
  • Create and deploy Wi-Fi and VPN profiles per platform, referencing deployed certificate profiles.
  • Validate RADIUS policies, certificate-to-identity mapping, and end-to-end authentication across device platforms.
  • Validate certificate lifecycle behavior, including issuance, renewal, and revocation upon device retirement or wipe.

Addigy and Apple Device Management Integration
  • Manage Apple Business Manager configuration and hygiene
  • Integrate Addigy with Microsoft Intune using the current Device Compliance integration model so Addigy-managed Mac compliance state is available to Entra ID Conditional Access.
  • Design and configure enrollment methods
  • Manage application deployment across macOS, iPadOS, and iOS, including managed app distribution and Apps and Books licensing.
  • Configure device restrictions for iPhone, iPad, and Mac
  • Define Apple platform compliance policies and integrate them with Condi