Endpoint Engineer - Tier 2
Remote Worker
Description

The Tier 2 Endpoint Engineer performs day-to-day operation and support of client endpoint management platforms, spanning Microsoft Configuration Manager (MECM/SCCM) and Microsoft Intune. This role is accountable to the Director of Operations for patch compliance, client health, and policy integrity across managed client environments, and serves as the escalation point for endpoint issues that exceed Tier 1 scope. The Endpoint Engineer operates within established architectures rather than designing new ones, and is responsible for recognizing when a client request falls outside managed services scope and routing it accordingly.

Duties and Responsibilities

  • Maintain Configuration Manager collections, applications, packages, and task sequences, including OS deployment and driver management
  • Maintain Intune device compliance policies, configuration profiles, and security baselines across Windows, iOS, Android, and macOS
  • Administer application deployment and lifecycle activities, including app protection policies and Company Portal availability
  • Maintain certificate profiles (SCEP/PKCS) and VPN configurations, and monitor certificate health, expiration, and renewal
  • Monitor Conditional Access and multifactor authentication compliance, and investigate policy enforcement and configuration drift issues
  • Support Microsoft Defender for Endpoint integration and perform security response activities including selective device wipe
  • Resolve assigned tickets within SLA, escalate appropriately, and follow change management procedures when working in client environments
  • Produce and maintain as-built documentation and standard operating procedures for supported environments
  • Contribute technical findings to quarterly client reviews covering compliance posture, policy effectiveness, and operational trends
  • Identify configuration gaps, operational risks, and supportability concerns, and surface recommendations for optimization or remediation
Requirements
  • 3–5 years of hands-on experience administering Microsoft Configuration Manager (SCCM/MECM) in a production environment, including software update management and client health troubleshooting
  • Working knowledge of Configuration Manager site infrastructure, including management points, distribution points, software update points, and boundary groups
  • Demonstrated experience administering Microsoft Intune, including enrollment, compliance policies, configuration profiles, and application management across multiple device platforms
  • Practical understanding of Conditional Access, multifactor authentication, and their interaction with device compliance
  • Experience with certificate-based authentication (SCEP/PKCS) and VPN profile configuration
  • Ability to diagnose endpoint issues through log analysis and structured troubleshooting rather than escalation by default
  • Experience delivering support in a managed services or multi-client environment, including ticket queue discipline, SLA adherence, and change management
  • Clear written communication sufficient to produce client-facing documentation and remediation recommendations
  • Sound judgment in distinguishing routine operational work from requests requiring separately scoped professional services
  • Microsoft certifications such as MD-102 (Endpoint Administrator) or equivalent demonstrated experience preferred

All Sparkhound employees are expected to handle client and company data with care, follow our information security policies, complete required security training, and report any suspected incidents or policy violations promptly. Employees are also responsible for maintaining accurate documentation and following change management procedures when working in client environments.