Senior End Point Engineer
HUB InternationalAbout the role
ABOUT US
At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.
HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions
Responsibilities
Platform Administration and Fleet Operations
- Own the day-to-day operation of NinjaOne across approximately 25,000 Windows endpoints on Lenovo standard hardware, covering HUB's 600-plus locations across the United States and Canada
- Maintain NinjaOne agent health, version currency, policy assignments, and organization structure across the full fleet
- Manage the application catalog, application lifecycle, and deployment assignments, ensuring each application has exactly one primary owner across NinjaOne and Intune with no overlap
- Configure and maintain Autopilot orchestration and provisioning workflows within NinjaOne
- Perform quarterly coexistence reviews with EUC, SecOps, and the Tanium platform team to validate agent versions, policy exclusions, Zscaler bypass entries, and catalog ownership
- Resolve coexistence issues across the stack including Zscaler SSL bypass, SentinelOne exclusion configuration, Tanium Threat Response exclusions, and Intune Management Extension conflicts
Capability Expansion and Approval Program
- Own the technical documentation and capability justification for each of the six pending NinjaOne capability approvals, working with Engineering leadership and Security
- Drive capability activation, policy build, and rollout for each approved module once cleared
- Build and maintain the application-layer patching program using NinjaOne's 200-plus application patch engine once the Automated Patch Management capability is approved
- Maintain a clean, properly structured NinjaOne environment as the hard pre-requisite for production fleet rollout
Scripting, Automation, and Runbooks
- Build and maintain a library of NinjaOne automation scripts in PowerShell, covering routine maintenance, provisioning, remediation, and compliance enforcement
- Author and maintain monitoring policies and alert configurations that surface actionable signal without false-positive noise, in coordination with the Nexthink team
- Collaborate with the DEX team on Amplify remote actions that leverage NinjaOne scripting and remote action capabilities as part of the L1 ticket deflection program
- Document all scripts, policies, and runbooks to SOC 2 standard, ensuring every automated action has an associated KB article before scale deployment
Data Lake Integration
- Design, build, and maintain the NinjaOne extraction pipeline to HUB's Microsoft Fabric data lake using the NinjaOne REST API v2 with OAuth 2.0 client-credentials (monitoring scope only), cursor-based pagination, and updatedAfter incremental filters
- Coordinate on entity resolution, joining NinjaOne records to Nexthink records via hardware serial number, hostname, and logged-on user UPN to build the unified golden device record
- Monitor pipeline health, handle API version changes, implement backoff on rate limits, and maintain extraction schema documentation
- Maintain monitoring-scope-only credential posture with secrets managed in Azure Key Vault and following SOC 2 credential rotation standards
CMDB and ServiceNow Integration
- Own the NinjaOne to ServiceNow CMDB bidirectional sync, ensuring device state, software inventory, and operational changes flow automatically between platforms
- Resolve CMDB drift and data quality issues in coordination with the ServiceNow platform team
- Maintain IAM compliance on device deletion rights and role-based access controls within the NinjaOne console
Governance, Compliance, and Documentation
- Maintain NinjaOne documentation to SOC 2 audit standard including access controls, change records, policy history, and exception tracking
- Support quarterly and annual coexisten
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s