Sr. Endpoint Engineer
Hksinc · Dallas–Fort Worth, TX
📍 Dallasvia workdayFirst listed here 2026-09-21
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Hksinc.
Overview:
Responsible for the enterprise patch and update management platform and the endpoint services supporting approximately 2,500 devices across 28 locations, spanning Azure and on-premises workloads. Leads the monthly patch cycle for Windows, macOS, Windows Server, and firmware, including deployment ring design, test coordination, and critical CVE remediation. Manages the device, application, policy, and security configurations to remain compliant. Partners across IT, leveraging Intune and other endpoint management tools to deliver endpoint solutions to the firm.
Responsibilities:
Owns the monthly patch cycle for Windows and macOS endpoints and Windows Server
Designs and maintains deployment rings (pilot, early adopter, broad), coordinating with test groups to validate patch levels for monthly publication
Patches third-party applications (browsers, runtimes, 7zip, etc.) through Intune or a dedicated patch management tool
Manages firmware, driver, and BIOS updates for laptops and server hardware
Meets remediation SLAs for critical and high-severity CVEs, executes out-of-band emergency patching for actively exploited vulnerabilities, and reports on compliance, exceptions, and drift
Partners with the security team on scan findings, false positives, risk acceptance, and remediation planning
Packages, deploys, updates, and retires applications (Win32, MSIX, Store, macOS pkg/dmg) and drivers, including detection rules, dependencies, and supersedence
Maintains a documented QA methodology for packages, patches, and configuration changes — test plans, acceptance criteria, and documented results before broad release
Administers Intune across Windows, macOS, iOS/iPadOS, and Android, including enrollment (Autopilot, Apple Business Manager/ADE, Android Enterprise), configuration profiles, compliance policies, and Conditional Access inputs
Onboards and manages servers in Azure Arc to extend update and configuration management on-premises and cloud servers
Maintains SCCM/Intune co-management and drives cloud native adoption
Maintains device and security baselines and hardening configurations
Helps design, build, and document the patch and device management system end to end, including architecture, runbooks, and standard operating procedures
Writes and maintains policies and standards for patching, update rings, device configuration, and application lifecycle
Evaluates, pilots, and recommends tooling to close gaps in the current platform
Automates operational work using PowerShell, Microsoft Graph, and bash/zsh
Builds patch compliance and device health dashboards for IT leadership
Submits and drives change requests for all production work, represents those changes at change advisory board review, and communicates maintenance windows, impact, and rollback plans
Assists application owners and other IT teams with packaging, deployment, and patching
Supports the service desk on escalated endpoint issues, patch-related breakage, and rollbacks
Participates in scheduled after-hours maintenance and supports high-severity incidents after-hours
Ensures all technology and departmental activities comply with company, security, regulatory and regional requirements
Stays current with industry trends, technological advancements, and leverages these capabilities to improve and streamline the operation
Qualifications:
B.A./B.S. degree in Computer Science or related field, or equivalent work experience
Typically, with 6+ years of experience, with 4+ years of experience administering Microsoft Intune in a production enterprise environment
Advanced competency of Microsoft Endpoint Management (MEM) technologies, including Intune, Autopilot, Azure ARC, AZURE AD
Advanced competency of CVE/CVSS scoring, vulnerability scanner output, and remediation SLA reporting
Working knowledge of SCCM/MECM, including co-management with Intune
Experience with managing macOS in an enterprise environment, plus iOS and Android mobile device management
Experience with third-party application patching using Intune integrations or a dedicated patch management tool
Experience with application packaging and deployment (Win32, MSIX, macOS pkg/dmg) and with a documented QA and testing methodology
Experience with scripting for automation: PowerShell required; Microsoft Graph and bash/zsh for macOS strongly preferred
Experience with disciplined change management practice (ITIL-aligned) and a genuine willingness to write and maintain documentation and policy
Experience in MS Office Suite
Strong communication and interpersonal skills, with the ability to interact with all levels of staff
Strong work ethic and eagerness to produce high quality, accurate results
Ability to hold sensitive information with a high level of confidentiality and integrity
Ability to present ideas in a clear, concise and professional manner both verbally and in writing
Ability to proactively solve problems and apply innovative solutions
Ability to collaborate in a team environment and ability to work independently
Ability to prioritize competing demands
Ability to effectively meet deadlines at expected quality
Travel may be required
If you currently work for HKS, please submit your application via the Internal Careers Portal .
HKS is an EEO/AA Employer: M/F/Disabled/Veteran
More Dallas–Fort Worth, TX jobs
Dallas–Fort Worth, TX jobs · Browse all locations