Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
US05Mercer Investments LLC logo

Windows Endpoint Engineer

US05Mercer Investments LLC
  • 🇲🇾 Malaysia
  • Hybrid
  • 23 hours ago
  • Windows
  • Microsoft Intune
  • Entra
  • Defender
  • PowerShell
  • Microsoft Graph
  • ServiceNow
  • JSON
  • XML
  • Azure
  • Microsoft Defender
  • Conditional Access
  • Active Directory
  • Group Policy
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Company:

Marsh

Description:

We are seeking a talented individual to join our Colleague Tech team at Marsh. This role will be based in Pavilion Damansara, Kuala Lumpur. This is a hybrid role that has a requirement of working at least three days a week in the office.


Windows Endpoint Engineer

As a Specialist in Windows Endpoint Engineering, you will help design, engineer and continuously improve the global Windows endpoint platform supporting approximately 95,000 colleagues across a complex enterprise environment.


You will work across modern device management, Windows deployment and servicing, application delivery, endpoint security and compliance, hardware lifecycle, automation and digital employee experience. You will collaborate with security, identity, network, application, service management and regional support teams to deliver reliable, secure and user-focused solutions.


You will also provide technical leadership for complex incidents and engineering changes, produce clear documentation and standards, and use telemetry and colleague feedback to improve endpoint performance, reliability and experience.


What can you expect:

  • A global engineering role supporting approximately 95,000 colleagues and a diverse Windows device estate.
  • The opportunity to shape modern Windows management using Microsoft Intune, Entra ID, Windows Autopilot, Windows Update for Business and related cloud services.
  • Work spanning endpoint build, configuration, application experience, hardware standards, security, compliance, automation and digital experience.
  • An open, collaborative engineering culture focused on standardisation, measurable service improvement and colleague outcomes.

We will rely on you to:

  • Engineer and maintain the enterprise Windows endpoint platform, including laptops, desktops, virtual endpoints and specialist device configurations.
  • Design and support modern provisioning and lifecycle workflows using Microsoft Intune, Entra ID and Windows Autopilot, including Entra-only device scenarios.
  • Manage Windows configuration, feature updates, quality updates, servicing rings, drivers, BIOS, firmware, UEFI and supporting hardware standards.
  • Engineer and improve application packaging, deployment, update and remediation processes, working with application owners to reduce compatibility and colleague-experience issues.
  • Implement and maintain endpoint security and compliance capabilities, including BitLocker, Secure Boot, Defender controls, Windows Hello for Business and security baselines.
  • Use PowerShell, Microsoft Graph and workflow automation to remove manual effort, improve control and integrate endpoint services with platforms such as ServiceNow.
  • Use endpoint telemetry and digital employee experience data to identify trends, assess change impact and proactively improve device health, performance and reliability.
  • Lead technical investigation and root-cause analysis for complex tier III incidents, engaging Microsoft and other technology vendors where required.
  • Translate business, colleague, security and operational requirements into technical designs, implementation plans, testing approaches and production acceptance criteria.
  • Create and maintain roadmaps, standards, engineering guides, release documentation, support knowledge and operational handover materials.
  • Contribute to peer reviews, technical governance, proof-of-concept activity and continual improvement across the global endpoint engineering service.

What you need to have:

  • Strong experience engineering and supporting Windows 11 endpoints in a large, distributed enterprise environment.
  • Hands-on experience with Microsoft Intune, Entra ID, Windows Autopilot and cloud-based Windows configuration and compliance.
  • Experience with Windows deployment, servicing, recovery and troubleshooting, including feature updates, quality updates, drivers and firmware.
  • Strong knowledge of application deployment, update management and compatibility troubleshooting for Microsoft 365 Apps and enterprise Windows applications.
  • Practical PowerShell automation skills and experience working with APIs, Microsoft Graph or structured data formats such as JSON, XML and CSV.
  • Good understanding of endpoint security, identity, compliance and access controls, including BitLocker, Secure Boot and Windows Hello for Business.
  • Ability to analyse complex technical problems, communicate clearly with technical and non-technical stakeholders, and produce high-quality engineering documentation.

What makes you stand out:

  • Deep experience with Microsoft Intune, Entra ID, Windows Autopilot, Windows Update for Business and modern management migration.
  • Experience engineering Windows 11 at scale, including deployment, in-place upgrades, update rings, application compatibility and rollback or recovery strategies.
  • Advanced PowerShell skills, with experience using Microsoft Graph, proactive remediations, Azure Automation or comparable workflow tooling.
  • Knowledge of endpoint analytics or digital employee experience platforms and the ability to turn telemetry into prioritised engineering improvements.
  • Experience integrating endpoint management data and workflows with IT service management or hardware asset management platforms such as ServiceNow.
  • Strong knowledge of device security controls, Microsoft Defender capabilities, security baselines, certificates, authentication and conditional access dependencies.
  • Experience evaluating enterprise laptop hardware, drivers, BIOS and firmware, including Intel and Windows on Arm device considerations.
  • Understanding of legacy management technologies such as Active Directory, Group Policy and Microsoft Configuration Manager, together with experience transitioning services towards modern management.
  • A record of producing clear technical standards, design documents, operational guidance and root-cause analysis for global services.
  • Excellent collaboration and communication skills, with the confidence to work across engineering, security, operations, vendors and business stakeholders.
  • A proactive, pragmatic and improvement-focused approach, with the ability to work independently and manage competing priorities.

Why join our team:

  • We help you be your best through professional development opportunities, interesting work and supportive leaders.
    • We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.
    • Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being

Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit marsh.com, or follow us on LinkedIn and X.

Marsh is committed to creating a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.

Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.

Windows Endpoint Engineer · US05Mercer Investments LLC

Auto apply with Likeremote