Ensure a stable, secure, and scalable Intune environment;
Identify risks, technical debt, management complexity, and improvement opportunities;
Translate strategic IT and security objectives into concrete Intune configurations;
Ensure consistency across device types, user groups, countries, divisions, and business units;
Define and govern endpoint management frameworks;
Establish organization-wide standards for configurations, policies, compliance, application deployment, and exceptions;
Define processes and agreements for IT teams;
Document roles, responsibilities, and authorities;
Set up change, review, and approval processes;
Assess deviations and exception requests based on risk, manageability, and security impact;
Ensure changes are reproducible, controlled, documented, and aligned with standards;
Act as content owner of Intune-related management processes;
Translate security policies into endpoint configurations and standards;
Implement and optimize security baselines, compliance policies, and endpoint security settings;
Ensure devices meet security and compliance requirements;
Reduce local administrator privileges using Endpoint Privilege Management or similar solutions;
Identify and mitigate security risks;
Collaborate with Security on risk analysis, audits, vulnerability management, and compliance;
Advise on security within Intune Suite, Microsoft Defender for Endpoint, and Microsoft Entra ID;
Balance security, user experience, and manageability;
Design and maintain a scalable Intune architecture;
Develop blueprints, standards, and reference configurations;
Define naming conventions, policy structures, group models, scope tags, and roles;
Standardize configurations, compliance policies, security policies, and application deployment;
Prevent uncontrolled growth and duplication;
Advise on lifecycle management of policies and configurations;
Separate standard configurations, exceptions, and experimental setups;
Design, implement, and manage Intune Suite functionality;
Develop Endpoint Privilege Management;
Define governance for elevated access, approvals, and logging;
Align functionality with security, management, and user goals;
Advise on further use of Intune Suite capabilities;
Define standards for application packaging and lifecycle management;
Develop and maintain packaging blueprints;
Define detection rules, remediation, install/uninstall standards, and logging;
Determine which applications are available via Company Portal and under which conditions;
Structure categories and target groups;
Collaborate on deployment and risk mitigation;
Ensure controlled and reproducible application deployment;
Reduce servicedesk workload through better self-service;
Act as the central contact for Intune and endpoint management;
Define and enforce organization-wide working agreements;
Advise IT teams on Intune standards;
Drive uniform ways of working;
Support complex incidents, changes, and projects;
Ensure cross-team consistency;
Escalate structural issues to IT management;
Translate operational signals into structural improvements;
Create and maintain documentation, standards, and work instructions;
Translate complex setups into practical processes;
Ensure documentation is actively used;
Transfer knowledge to IT teams;
Coach colleagues;
Prevent key knowledge from being person-dependent;
Support team maturity growth;
Design and manage patching processes via Intune;
Configure Windows Update for Business policies and update rings;
Define patch strategies including pilot, phased rollout, and emergency patches;
Monitor patch compliance;
Coordinate with Security and Infrastructure;
Reduce security risks through controlled patching;
Ensure processes are predictable and documented;
Handle advanced 2nd/3rd line troubleshooting;
Analyze incidents related to enrollment, policies, applications, and compliance;
Perform root cause analysis;
Support escalations;
Identify recurring issues and drive improvements;
Ensure stable day-to-day operations without dependency on individuals.
требования
Bachelor-level working and thinking capability (HBO) in IT or a related field;
Proven experience with Microsoft Intune in enterprise environments;
Experience in complex, multi-team, and international environments;
Experience with governance, security, and standardization;
Experience advising management and stakeholders;
Experience with modern workplace and endpoint management;
Experience with Windows endpoint management;
Experience with device enrollment and lifecycle management;
Experience with compliance policies and security baselines;
Experience with application packaging and distribution;
Experience with Company Portal and self-service;
Experience with Endpoint Privilege Management;
Experience with security and compliance;
Deep knowledge of Microsoft Intune;
Strong Windows endpoint management experience;
Knowledge of Microsoft Entra ID;
Experience with Autopilot, enrollment, compliance, and security baselines;
Experience with application deployment via Intune;
Knowledge of endpoint security and privileged access;
PowerShell for automation;
Governance and process experience;
Strong communication skills;
Nice to have: Intune Suite, Microsoft Defender for Endpoint, Conditional Access, RBAC and scope tags, ServiceNow or similar ITSM tools, multi-entity environments, zero-touch deployment.