Director, Infrastructure & End-User Services
Penn MutualAbout the role
Job Description:
The Director, Infrastructure & End-User Services leads enterprise teams that deliver secure, reliable, and high-quality workplace and infrastructure services. Accountable for identity and account management, end-user computing (Windows and macOS), Microsoft 365 platforms, Windows Servers and Desktop Support operations, this leader ensures employees have the access, devices, and tools needed to work productively while meeting security, compliance, and reliability expectations. The Director serves as the single point of accountability for end-user services, ensuring a seamless, secure, and audit-ready technology experience from employee onboarding through exit.
Key Responsibilities
- Identity, Account & Access Management (IAM): Own enterprise Identity and Access Management operations, including employee onboarding, role changes, offboarding, user identity lifecycle, provisioning/de-provisioning, and access certifications aligned to least-privilege, segregation of duties, and timely access removal principles.
- End-User Systems & Device Management: Lead teams responsible for Windows and macOS endpoint management, including configuration, patching, OS lifecycle management, endpoint security, compliance, vulnerability remediation, device standards, imaging, and hardening. Own full device lifecycle from procurement through retirement.
- Desktop Support Operations: Lead Desktop Support teams providing day-to-day user support, hardware troubleshooting, software installation, and break-fix support. Define and enforce SLAs, service standards, escalation paths, and drive automation to reduce ticket volume and improve resolution times.
- Microsoft 365 & Collaboration Services: Lead M365 engineering and operations teams (Exchange Online, SharePoint Online, OneDrive, Microsoft Teams). Establish governance for collaboration lifecycle, external/guest access, information protection, retention, and compliance. Partner with Security and Architecture to ensure secure, scalable adoption.
- Windows Server Administration: Oversee the development, operational support and security of 150+ windows servers in AWS, including patching (Ivanti Neurons), AMI lifecycle management, and instance right-sizing. Lead system administrators to administer, maintain, and optimize a single domain Active Directory forest including Domain Controllers, DNS, DHCP, Group Policy, and Sites & Services.
- Service Delivery & Operational Excellence: Ensure end-user and infrastructure services meet SLAs, reliability, and experience goals. Implement automation and standard operating procedures; define and report service performance metrics; coordinate business continuity and disaster recovery readiness.
- Leadership & Stakeholder Management: Lead, mentor, and develop multi-disciplinary teams across IAM, end-user computing, Desktop Support, System Administrators and M365 engineering. Manage vendor relationships, partner with Security and Business leaders, communicate risks and performance to executive leadership, and own budget forecasting and cost optimization.
- Strategic Planning: Develop and maintain workplace technology strategy and multi-year roadmap aligned to business priorities and security requirements.
Minimum Qualifications
- 10+ years of experience in infrastructure, end-user services, or workplace technology
- 5+ years of people leadership managing multiple technology teams
- Strong experience in Identity & Access Management, Windows and macOS endpoint management, desktop support operations, Windows server administration and Microsoft 365 platforms
- Experience operating in large, regulated enterprise environments
Required Technical Skills & Knowledge
- Identity: Microsoft Entra ID (Azure AD), MFA/SSPR, conditional access, privileged access concepts (PIM/PAM), and access review processes
- Endpoint Management: Microsoft Intune/Endpoint Manager, Ivanti, and/or JAMF (or equivalent), patching, compliance policies, software deployment, and endpoint hardening
- Microsoft 365 Administration: Exchange Online, Teams, SharePoint/OneDrive, collaboration governance, external sharing controls, and information protection fundamentals
- ITSM Operations: Incident/problem/change management, service catalog, knowledge management, and major incident communications (ITIL-aligned)
- Security and Compliance: Endpoint security controls, vulnerability management coordination, audit support, and regulated-environment operational discipline
- Endpoint Security Tooling: Microsoft Defender for Endpoint (or equivalent), device risk scoring, and attack surface reduction concepts
- Microsoft 365 Compliance & Data Protection: Purview (sensitivity labels, DLP basi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s