12 Aug
|
Blue Yonder
|
Hyderabad
12 Aug
Blue Yonder
Hyderabad
About Blue Yonder, Inc. Blue Yonder is the proven leader in artificial intelligence and machine learning (AI/ML)-driven supply chain and retail solutions for 4,000 of the world’s leading, manufacturing and logistics companies. Blue Yonder’s world-class client brands include 75 of the top 100 retailers, 77 of the top 100 consumer goods companies, and 8 of the top 10 global 3PLs.
Running Blue
Yonder, you can plan to deliver.
Title: Staff System Engineer 1
Blue Yonder is seeking a highly experienced Senior Endpoint Engineering SME to lead the design, engineering, modernization, and security of the enterprise endpoint ecosystem. This role owns the endpoint strategy and is responsible for delivering transformational initiatives across Windows MacBook, and mobile devices. Experienced candidates will assess endpoint security opportunities, assist with device lifecycle management, and identify modern workplace technologies to enhance end user experience.
The ideal candidate brings deep expertise with the following technologies: Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Endpoint Security, Microsoft Defender, Zero Trust architecture, MDM, Desktop as a Service (DaaS), and enterprise endpoint engineering. Candidate will serve as the primary technical lead, collaborating closely with Infrastructure, Security, Identity, Networking, Cloud, and End User Computing teams.
Key Responsibilities
Enterprise Device Management
Lead enterprise endpoint management modernization initiatives, including ManageEngine Endpoint Central cloud migration, Microsoft Intune adoption, and the transition away from legacy endpoint management platforms.
Design and implement automated endpoint patching, software deployment, and application lifecycle management processes to improve security, compliance, and operational efficiency.
Establish and maintain endpoint governance through device inventory management, compliance reporting, asset visibility, and endpoint health monitoring across the global setting
Endpoint Modernization
Lead enterprise endpoint modernization programs, including Windows Autopilot deployment, Entra ID Join adoption, and the migration from traditional Group Policy management to cloud-native Intune/MDM policies.
Design and implement modern endpoint access and identity solutions, including certificate lifecycle management and the replacement of legacy Hybrid Join VPN architectures with secure, cloud-first access technologies.
Establish and maintain Windows endpoint standards,
including Windows 11 lifecycle management, security baselines, configuration governance, and endpoint compliance across the enterprise.
Secure workforce Experience
Architect and deliver modern identity and access management solutions, including DUO MFA migration to Microsoft Authenticator.
Intune Conditional
Access integration to enhance security and user experience. Password-less authentication via biometrics such as Windows Hello for Business.
Enhance secure endpoint access by modernizing guest network services, optimizing Global Protect endpoint protection and connectivity, and implementing device posture-based access controls aligned with Zero Trust principles
Endpoint Trust and Governance Architect and implement endpoint trust and governance frameworks, including privileged access management, admin rights automation, and endpoint hardening initiatives aligned with Zero Trust principles.
Drive endpoint compliance and mobile security strategies through software lifecycle governance, mobile device segmentation, and enhanced security controls for corporate-owned and Blue Yonder devices.
Endpoint Strategy and Architecture
Establish endpoint security, compliance, and governance standards through Microsoft Defender strategy, device posture controls, Zero Trust principles, and ongoing review of endpoint usage and security policies.
Develop and execute the endpoint technology roadmap by driving hardware lifecycle automation, VDI architecture modernization, and future workplace technology strategies that enhance user experience, operational efficiency, and scalability.
Own DaaS Architecture & Design including solution design and capacity planning
Security and Compliance Lead endpoint security engineering initiatives, including Microsoft Defender/XDR deployment, endpoint hardening, vulnerability management, Zero Trust controls, and Conditional Access integration to strengthen the organization's security posture.
Establish and maintain enterprise endpoint security and compliance standards through device encryption,
CIS benchmark alignment and continuous security monitoring across all managed endpoints.
Automation and Engineering
Develop automation for provisioning, patching, certificates, and compliance utilizing both Manage Engine and Microsoft Intune.
Build Microsoft Graph API integrations for endpoint management workflows
Automate certificate renewal, device lifecycle events, and compliance remediation
Create self-healing endpoint configurations and monitoring scripts
Qualifications
Bachelor's degree in computer science, MIS or engineering related field or equivalent work experience 10+ years in Enterprise Endpoint Engineering or End User Computing
5+ years hands-on experience with Microsoft Intune or Endpoint Manager
Proven experience managing 10,000+ enterprise endpoints globally
Experience delivering large-scale endpoint modernization programs
Ability to interact with various levels of professionals Ability to work under pressure in a fast-paced environment and meet tight deadlines Ability to act independently to drive IT goals and changes Advanced troubleshooting methodology Ability to judge priorities and adjust their work accordingly Preferred skills
Strong experience in Windows OS deployment, configuration, and lifecycle management along with windows security baselines and CIS benchmarks.
Experience in Microsoft Entra ID / Azure AD - Conditional Access, MFA, SSPR and Microsoft Authenticator deployment and migration
Strong knowledge on Windows Autopilot – Zero-touch provisioning
Proficiency in MS Defender and BitLocker for encryption and key management
Hands-on experience on Vulnerability management and device compliance enforcement
Hands-on experience in ManageEngine patch management
Strong knowledge on PowerShell — advanced scripting, modules, and CI/CD integration.
Working knowledge on DNS, DHCP, and endpoint network diagnostics
VPN solutions — Global Protect, Always On VPN, or Microsoft VPN solutions
Solid foundational understanding of Group Policy (GPO) design and migration to Intune MDM policies.
Our Values If you want to know the heart of a company, take a look at their values. Ours unite us. They are what drive our success – and the success of our customers. Does your heart beat like ours?
Find out here: Core Values
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
📌 Sr. Endpoint Engineer - MS Intune,Endpoint Engineering (Hyderabad)
🏢 Blue Yonder
📍 Hyderabad