Overview
Support operations and manage delivery for production systems and services as a hands-on Windows endpoint build engineering role. Own the Windows client end to end across Microsoft Configuration Manager, Microsoft Intune, cloud-native management, configuration, automation, security, patching and end-user experience.
What you'll do
- Engineer Windows operating system deployment, imaging, drivers, WinPE, task sequences, upgrades, state migration, BitLocker and firmware integration.
- Troubleshoot deployment failures from logs and make fixes repeatable.
- Engineer and maintain Configuration Manager site health, roles, boundaries, distribution points, PXE, boot images, client settings, collections, software updates and reporting.
- Manage co-management and workload transition to Intune.
- Build and manage Intune capabilities for Autopilot, enrollment, Windows policy, compliance, security baselines, scripts and proactive remediations.
- Migrate Group Policy and Configuration Manager workloads to cloud management with clear validation.
- Own Windows servicing through Windows Update for Business, Autopatch where adopted, update rings, deferrals, expedited updates, feature updates, driver policy and compliance reporting.
- Optimize update delivery for remote and bandwidth-constrained sites.
- Package and deploy Intune Win32, Microsoft Store, Enterprise App Catalog and Microsoft 365 Apps with reliable detection, requirements, dependencies, supersedence and assignment strategy.
- Convert Configuration Manager applications to cloud-ready equivalents.
- Own the Group Policy estate, including OU structure, filtering, precedence, ADMX, preferences and documented baselines.
- Rationalize legacy policy, resolve conflicts and map policies to Intune where appropriate.
- Build production-grade PowerShell for provisioning, configuration, detection, remediation, reporting and drift control.
- Ensure scripts are logged, error-handled, idempotent, signed and source-controlled.
- Own application packaging across MSI, MSIX, App-V where required and Intune Win32 apps.
- Standardize silent installs, transforms, uninstall logic, rollback testing, catalog quality and self-service delivery.
- Engineer endpoint dependencies including Active Directory, Entra ID, domain join, DNS, DHCP, PKI, WSUS, activation, Windows Hello for Business and LAPS.
- Understand network and content-delivery behavior supporting branch and remote builds.
- Implement Windows security baselines, BitLocker, ASR, WDAC or AppLocker, Credential Guard, exploit protection and local admin controls.
- Maintain patch compliance, feature update readiness and remediation of non-compliant devices.
- Measure and improve provisioning, OOBE, boot, sign-in, policy processing, application reliability and profile performance.
- Use telemetry, targets and proactive remediation to reduce tickets and technician touch.
- Lead change, pilot planning, validation, backout, Tier 3/4 escalation and root-cause analysis.
- Maintain documentation, runbooks, design records, roadmaps and technical debt priorities.
What you'll need
- Minimum 3 year(s) of experience is required.
- 7+ years in Windows endpoint or desktop engineering, with significant ownership of the build and configuration estate in a large or complex environment.
- Minimum 7.5 years of experience in Microsoft Endpoint Configuration Manager.
- 15 years full time education.
- Microsoft Endpoint Configuration Manager skills.
- Deep hands-on Microsoft Configuration Manager engineering, including site administration, OS deployment, task sequence authoring and debugging, application and update deployment, collections, boundaries and content distribution.
- Demonstrable mastery of Windows OS deployment, including imaging and image servicing, WinPE and boot image customization, driver management, USMT and in-place upgrade at scale.
- Hands-on Microsoft Intune engineering for Windows, including Autopilot provisioning, settings catalog and ADMX-backed policy, compliance policies, platform scripts and proactive remediations, filters and scope tags.
- Cloud patch and update management with Windows Update for Business, including ring and deferral design, feature update control, expedited updates and compliance reporting.
- Cloud application delivery through Intune Win32 apps, including packaging, detection and requirement rules, supersedence and assignment strategy.
- Advanced Group Policy engineering, including policy architecture, filtering, precedence and conflict resolution, ADMX central store, preferences and systematic rationalization of legacy policy.
- Production-grade PowerShell scripting for configuration, automation, detection and remediation, including error handling, logging, code signing and source control.
- Strong Windows client internals and troubleshooting, including registry, services, WMI, event and setup logs, performance analysis, profile and logon behavior.
- Application packaging across MSI, Win32 and MSIX, including detection logic, transforms and supersedence.
- Working knowledge of Active Directory, Entra ID, DNS, DHCP, PKI and certificate autoenrollment, WSUS and update infrastructure, and activation services.
- Windows security baseline and hardening experience, including BitLocker, application control, ASR and patch compliance management.
- Enterprise change, incident and problem discipline, high-quality technical documentation, and clear communication to technical and nontechnical audiences.
- End-to-end ownership of a Microsoft Configuration Manager environment, including design, engineering and Tier 3/4 support across site architecture, OS deployment, content distribution and update management, with demonstrable modernization or co-management work alongside Microsoft Intune.
- Delivered migration of a workload from Configuration Manager to cloud management, provisioning, policy, application delivery or patching, including parity validation and on-premises retirement.
- Zero-touch or low-touch provisioning delivery, Autopilot, pre-provisioning, or a hardened Configuration Manager sequence replacing technician-built devices.
- Large-scale Windows feature update or OS migration programs, including application and driver compatibility remediation.
Nice to have
- Familiarity with Windows Autopatch.
- Advanced automation beyond scripting, policy-as-code, CI/CD for packaging, Graph or WMI-driven reporting, or infrastructure automation.
- Global, highly regulated or large-enterprise environments, including frontline, shared-device or VDI populations.
- Certifications such as MD-102, MCSE or equivalent Windows Server and client credentials, SC-200 or SC-100, or a scripting or automation certification.
Details
- This position is based at the Bengaluru office.
Read the full description and apply on the company’s own careers page.