26 Aug
|
Unisys
|
Bengaluru
About the Role
This position is for a L3 Engineer will act as a subject-matter expert for a multi-tenant Workspace ONE MSP environment supporting approximately 30 clients, spanning shared managed-service tenants, dedicated customer SaaS consoles, and legacy on-premises deployments. The L3 Engineer is accountable for integrations, escalated incident resolution, upgrade planning, automation strategy, and technical governance across all supported customer environments.
Key Responsibilities
- Platform Architecture & Workplace Management: Own the end-to-end Workspace ONE architecture across SaaS, Hybrid, and On-Premises models, covering UEM, Workspace ONE Access, Unified Access Gateway (UAG), Assist, Intelligence, ACC/AWCM connectors, and gateways.
- Define Organization Group hierarchies (tenant, sub-OGs, staging, platform-based, and business-unit OGs), global UEM settings, and environment segregation across dev/test/pre-prod/production, controlling configuration promotion between environments.
- Plan, document, and execute upgrades for UEM, Access, UAG, Assist, and related components, including rollback readiness and post-upgrade validation.
- Enrollment & Device Lifecycle: Design enrollment strategies for Android, iOS, macOS, Windows, and rugged devices across Corporate-Owned, Corporate-Shared, and BYOD models, including Autodiscovery, zero-touch, DEP/Automated Device Enrollment, Windows OOBE and PPKG provisioning, and staging scenarios.
- Policies, Profiles & Baselines: Define profile and baseline architecture per platform; design and debug custom ADMX/OMA-URI payloads; resolve conflicts between ADMX profiles, CIS/security baselines, custom settings, and legacy GPOs.
- Application Lifecycle: Own the application lifecycle strategy: Win32/MSI/EXE, PKG, APK/AAB and Managed Google Play, ABM/VPP delivery, Omnissa SDK integration, deployment ring design (pilot to broad), dependency and rollback planning.
- Android Enterprise & Rugged: Architect Android Enterprise deployments (Work Profile, Fully Managed, COPE, Dedicated) including rugged fleets, Secure Launcher kiosk designs, corporate-shared device workflows, and OS/app update strategy.
- Apple Ecosystem: Maintain the Apple ecosystem integrations: ABM/DEP profiles with supervision and user affinity, APNs certificate lifecycle, VPP token management, and resolution of ABMVPPUEM synchronization issues.
- Identity, SSO & Access: Design identity and access integrations: AD via ACC/LDAP, Microsoft Entra ID, Workspace ONE Access IdPs and access policies, SAML federations with third-party IdPs and SaaS applications, Android CertProxy SSO, iOS Kerberos SSO, conditional access design, and custom role/delegated administration models.
- UAG & Secure Access: Architect and operate UAG: OVA/OVF deployment in vSphere, Photon OS administration, one/two/three-NIC DMZ designs, HA behind enterprise load balancers (F5 or equivalent), session persistence design, and SSL passthrough/bridging/offloading topologies with correct certificate, cipher, and SNI handling.
- Design and troubleshoot Per-App VPN / Workspace ONE Tunnel with Device Traffic Rules, SEG (with/without Kerberos), Content Gateway, and ENS, including end-to-end network path analysis (routing, firewall, NAT, DNS, ports).
- PKI & Certificates: Define PKI strategy for certificate-based authentication; manage CAs, SCEP and issuance workflows, public SSL certificate lifecycles, Java keystores for AWCM,
and deep trust-chain troubleshooting using OpenSSL (chains, CSR validation, TLS handshakes, CRL/OCSP, SAN/hostname mismatches).
- Automation & Intelligence: Design Freestyle Orchestrator workflows for onboarding, remediation, and change automation; integrate Workspace ONE Intelligence for dashboards, automations, webhooks/SIEM/ticketing integration, and management-level reporting.
- Privacy & Governance: Define privacy governance for BYOD/Corporate-Owned/Corporate-Shared scenarios aligned with customer contractual and data-protection expectations (Work Profile, iOS User Enrollment, data-collection minimization).
- L3 Troubleshooting & Incident Ownership: Serve as final internal escalation for complex incidents across UEM, Access, UAG, ACC/AWCM, Assist, SEG, Content Gateway, and ENS; perform root-cause analysis; troubleshoot Windows communication stack (AWCM/WNS) issues; lead service restoration across heterogeneous customer architectures.
- Vendor Escalation, Documentation & Mentoring: Manage vendor escalations to Omnissa Support (case creation, evidence and log collection, reproduction, fix validation); maintain runbooks, architecture diagrams, and best-practice standards; mentor L1/L2/L2.5 associates and act as technical decision-maker for projects and transitions.
Required Skills & Experience
- 7-8 years in enterprise End User Computing / mobility, with 5+ years of expert, hands-on Workspace ONE UEM administration and architecture in multi-tenant or MSP environments.
- Proven l expertise across Workspace ONE UEM, Access, UAG, Assist, Intelligence, ACC, AWCM, SEG, Content Gateway, ENS, and Tunnel.
Preferred Qualifications
- Omnissa/VMware certification (e.g., VCP/VCAP Digital Workspace or equivalent).
- French language proficiency
#LI-UG1
BA/BS degree and 7-8 years relevant experience OR equivalent combination of education and experience
📌 Associate Principal Engineer - Workspace ONE (Bengaluru)
🏢 Unisys
📍 Bengaluru