Description
Overview
Position Summary
The Endpoint Systems Engineer owns endpoint device management and security across JDA TSG's Windows and MacOS environment. This role is central to the company's SOC 2 compliance program and plays a key part in strengthening how JDA manages its Microsoft 365 environment.
This is a hands-on role covering device enrollment, configuration, patching, and vulnerability remediation, along with working knowledge of Microsoft 365 and Entra ID that adds depth to JDA's broader cloud environment.
Because this is a newly created role, you will help define how JDA manages and secures its endpoint fleet as the company scales, working directly with IT leadership and the SOC 2 compliance program.
What You Will Do
Why You'll Love This Role
- Own a security-critical function from day one, with influence over how JDA manages and protects its device fleet.
- Play a direct role in JDA's SOC 2 compliance program, not just support it from the sidelines.
- Build working knowledge of Microsoft 365 and Entra ID that extends your impact across JDA's broader cloud environment.
- Work closely with IT leadership on policy, standards, and strategic direction, not only day-to-day tickets.
You'll Own Endpoint Security & Compliance
- Own the SOC 2 controls tied to device enrollment, configuration, patching, and vulnerability remediation across Windows and macOS.
- Maintain compliance evidence in the GRC platform for endpoint related controls, supporting audits.
- Design and enforce device configuration standards and security baselines.
- Identify and remediate device vulnerabilities through scripting and application deployment in Intune.
- Maintain working knowledge of Microsoft 365 and Entra ID as they intersect with device and identity management.
Device Lifecycle & Vulnerability Management
- Manage the Windows and macOS device lifecycle: enrollment, provisioning, and configuration through Intune and Autopilot.
- Roll out configuration changes and adapt device policy as SOC 2 requirements and business needs evolve.
- Test and validate configuration changes before wider rollout.
Success Measures
- Endpoint related SOC 2 controls pass audit with minimal findings.
- Reduced device vulnerabilities and faster time to remediation across the fleet.
- Device configuration standards are documented, enforced, and consistently maintained across the environment.
Who You Are
What You'll Bring
- 5+ years of experience in endpoint or device management in an enterprise environment, supporting both Windows and macOS.
- Hands-on experience with Microsoft Intune and Autopilot.
- Working knowledge of Microsoft 365 and Entra ID.
- Experience supporting a SOC 2 or similar compliance framework, ideally with a GRC platform like Vanta.
- Scripting experience, PowerShell preferred, for vulnerability remediation and application deployment.
Preferred Experience
- Background in vulnerability management.
- Experience with Microsoft Defender for Endpoint and/or Defender for Cloud Apps.
- Familiarity with structured change management processes.
What We Offer
- Healthcare – Comprehensive coverage for you and your family
- Employee Assistance Program – Get support when you or your family need it with counseling and coaching
- 401K with company match
- Paid time off
- Paid parental leave
- Volunteer Day Off
- Life insurance – Protect your loved ones and their future
- Business travel accident insurance
USD $125,000.00 - USD $135,000.00 /Yr.
We are an equal opportunity employer committed to building an inclusive workplace. To view our Equal Employment Opportunity (EEO) policy, please click here.
Qualifications
What You'll Bring
- 5+ years of experience in endpoint or device management in an enterprise environment, supporting both Windows and macOS.
- Hands-on experience with Microsoft Intune and Autopilot.
- Working knowledge of Microsoft 365 and Entra ID.
- Experience supporting a SOC 2 or similar compliance framework, ideally with a GRC platform like Vanta.
- Scripting experience, PowerShell preferred, for vulnerability remediation and application deployment.
Preferred Experience
- Background in vulnerability management.
- Experience with Microsoft Defender for Endpoint and/or Defender for Cloud Apps.
- Familiarity with structured change management processes.
Responsibilities
Why You'll Love This Role
- Own a security-critical function from day one, with influence over how JDA manages and protects its device fleet.
- Play a direct role in JDA's SOC 2 compliance program, not just support it from the sidelines.
- Build working knowledge of Microsoft 365 and Entra ID that extends your impact across JDA's broader cloud environment.
- Work closely with IT leadership on policy, standards, and strategic direction, not only day-to-day tickets.
You'll Own Endpoint Security & Compliance
- Own the SOC 2 controls tied to device enrollment, configuration, patching, and vulnerability remediation across Windows and macOS.
- Maintain compliance evidence in the GRC platform for endpoint related controls, supporting audits.
- Design and enforce device configuration standards and security baselines.
- Identify and remediate device vulnerabilities through scripting and application deployment in Intune.
- Maintain working knowledge of Microsoft 365 and Entra ID as they intersect with device and identity management.
Device Lifecycle & Vulnerability Management
- Manage the Windows and macOS device lifecycle: enrollment, provisioning, and configuration through Intune and Autopilot.
- Roll out configuration changes and adapt device policy as SOC 2 requirements and business needs evolve.
- Test and validate configuration changes before wider rollout.
Success Measures
- Endpoint related SOC 2 controls pass audit with minimal findings.
- Reduced device vulnerabilities and faster time to remediation across the fleet.
- Device configuration standards are documented, enforced, and consistently maintained across the environment.
Apply on company website