Senior Systems Engineer – Workplace Engineering
Marriott InternationalAbout the role
The Sr. Systems Engineer will be responsible for the design, implementation, and comprehensive management of all Intune features specifically related to Windows 365 (W365) Cloud PC environments. This role requires an expert understanding of Microsoft Intune and its integration with W365, emphasizing compliance, security, device configuration, and seamless user experiences. The ideal candidate will bring in-depth experience in endpoint management and possess the ability to lead, optimize, and support complex Intune configurations. This role involves closely managing policies, application deployment, access control, and all facets of device lifecycle management within the Intune environment to maximize the effectiveness of W365 Cloud PCs across the organization.
CANDIDATE PROFILE
Education and Experience
Required:
• Undergraduate degree in an engineering or computer science discipline, or equivalent experience/certification.
• 7+ years in information technology, including:
o 5+ years implementing cloud-based SaaS/Daas solutions and virtualization platforms and technologies.
o 3+ years specializing in virtual desktop infrastructure (VDI), with a focus on Windows 365 (W365) and Intune.
o 5+ years of automation experience in infrastructure provisioning using scripting and automation technologies.
o 3+ years in Intune management, including policy creation, compliance settings, app deployment, and endpoint security configurations.
o 3+ year experience in creating, deploying, and managing IntuneWin and custom MSI packages for streamlined app deployment in W365 environments.
o 3+ years of Microsoft Endpoint Manager, with expertise in managing Windows Autopilot, Conditional Access Policies, and compliance policies according to industry best practices.
o 5+ years working with scripting languages, such as PowerShell, for automation and endpoint management.
o 2+ years experience with Agile methodologies, including sprints, JIRA, and creating user stories to align with business requirements and technical needs.
Other Required Capabilities
W365 & Intune Policy Management:
• Design and enforce provisioning policies tailored for W365 Cloud PCs, enabling seamless enrollment, configuration, and compliance.
• Manage Intune compliance policies specific to W365, ensuring Cloud PCs meet regulatory and internal standards.
• Establish device configuration policies for security settings, user permissions, network profiles, and connectivity, ensuring consistent, secure configurations across all W365 devices.
• Implement security baselines specifically crafted for W365 in Intune, aligning with industry best practices for enhanced device security.
Application Deployment & Management:
• Oversee application deployment strategies through Intune to ensure applications are securely and efficiently delivered to W365 devices.
• Develop and manage Intune app configuration policies for smooth app installation, updating, and removal across the W365 fleet.
• Configure app protection policies for Microsoft and third-party applications within W365 to enhance data security and user productivity.
• Custom Package Development: Design and build custom MSI and Intunewin packages for application deployment in Intune, ensuring compatibility and optimized installation processes for W365 Cloud PC environments.
Conditional Access & Security Policies:
• Understanding of conditional access policies within Intune and Azure AD for W365, managing access based on compliance, user location, and risk-based criteria.
• Manage and implement endpoint security settings within Intune, including antivirus, encryption, intrusion detection, and real-time monitoring.
User Experience & Profile Management:
• Optimize user profile management through Intune, ensuring personalized, consistent user experiences across W365 devices.
• Leverage Intune’s user and device-based settings to streamline experiences, including device restrictions, personalization, and default settings.
• Profile management and configure persistent user settings, reducing login times and improving overall user satisfaction.
Device Configuration & Compliance:
• Design configuration profiles for W365 devices to manage essential settings such as Wi-Fi, VPN, certificates, and device restrictions.
• Monitor compliance through Intune reporting, ensuring W365 devices align with corporate security policies and regulatory requirements.
• Perform regular reviews and adjustments to security and compliance configurations to align with emer
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s