A Day in the Life of our MDM/Endpoint Engineer
As an MDM/Endpoint Engineer at KDI, you will be responsible for supporting and securing the full device lifecycle across our client’s organization. This includes but is not limited to mobile device management, endpoint provisioning, patch and update management, endpoint security hardening, and support for devices operating in a regulated, validated-systems environment.
Who Should Apply:
An ideal candidate is self-motivated and passionate about technology, and naturally curious. We are looking for someone who enjoys taking an outside-the-box approach to unique problems and who understands the added rigor that comes with managing endpoints in an environment where data integrity, privacy, and compliance are non-negotiable.
Responsibilities
Endpoint Fleet Management
- Multi-OS device administration: Manage and support the endpoint fleet across macOS (Jamf Pro), Windows (FleetDM/PDQ), Linux, and Chrome devices, including enrollment, configuration profiles, and lifecycle management.
- Apple Business Manager: Maintain ABM hygiene, including enrollment tokens, prestage/zero-touch enrollment, and removal of retired or e-wasted devices to prevent unauthorized re-enrollment.
- Shared and lab devices: Support shared-use and lab instrument endpoints alongside standard user devices, coordinating maintenance windows with lab and facilities teams to minimize disruption.
Patching & Vulnerability Remediation
- OS upgrade cycles: Drive macOS upgrade adoption (e.g., Tahoe) through Jamf nudges and forced-update strategies for non-compliant devices.
- Windows patching: Coordinate Windows 10/11 patching and ESU licensing, tracking machines by support status and closing gaps identified through fleet reporting.
- Quarterly maintenance windows: Plan and execute rolling patch cycles for hard-to-schedule lab instruments and shared devices.
Security Tooling & Identity
- EDR and identity coordination: Monitor CrowdStrike agent health and Okta device trust/SSO status across the fleet; escalate gaps to InfoSec and remediate agent or enrollment failures.
- Access hygiene: Administer and configure Okta/Active Directory for security and access management. Troubleshooting endpoint authentication using biometrics, hardware tokens, and certificates.
Asset Inventory & Service Management
- CMDB accuracy: Maintain accurate device and user records in Fresh Service, including primary device assignment, location, and lifecycle status, per documented SOPs.
- Physical and remote audits: Execute recurring inventory audits (FTE, contractor, and lab device phases) combining in-person checks with automated compliance validation.
- Ticket-based tracking: Log and track compliance exceptions (backup failures, check-in gaps, stale devices) as tickets rather than informal notes, to prevent lost follow-up.
Backup, Recovery & Onboarding/Offboarding
- Backup health: Monitor Druva (or equivalent) backup coverage and remediate gaps, including executive and VIP devices, contractors, and Linux endpoints.
- Zero-touch onboarding: Maintain prestage enrollment and automated provisioning to minimize Helpdesk involvement in new-hire device setup.
- Offboarding reliability: Support consistent, auditable offboarding, including device lock, data preservation, and asset recovery, for contractors and employees alike.
Automation & Documentation
- Scripting: Write and maintain scripts (Bash, Python, or PowerShell) and Jamf extension attributes/smart groups to automate compliance checks and reduce manual fleet management.
- SOPs and knowledge sharing: Document standard operating procedures for fleet management, patching, and audits so processes are repeatable across sites and shifts.
- Cross-team coordination: Partner with Helpdesk, InfoSec, Facilities, and site leads across Bay Area, San Diego, and Cambridge to align on device installs, vendor visits, and support escalations.
Minimum Qualifications
- Bachelor's degree in Computer Science, Information Technology, or equivalent hands-on experience. Experience in early-stage companies or life sciences/research environments is a plus.
- 3+ years of hands-on endpoint or systems administration experience across macOS, Windows, and/or Linux in a professional environment.
- Hands-on experience administering an MDM platform at scale (Jamf Pro required; exposure to FleetDM, PDQ, or Intune).
- Working knowledge of Okta for SSO and device trust.
- Familiarity with an EDR/endpoint security tool such as CrowdStrike, and comfort collaborating with a security team on remediation.
- Scripting proficiency in Bash, Python, or PowerShell for automating repetitive fleet tasks.
- Experience with an ITSM/ticketing platform (Fresh Service, ServiceNow, or similar) and asset/CMDB tracking.
- Strong communication skills and comfort working directly with end users, lab staff, and cross-functional stakeholders in a hybrid, multi-site organization.
Preferred Qualifications
- Experience managing Chrome/ChromeOS devices in an enterprise setting (Google Admin console).
- Familiarity with Apple Business Manager and zero-touch/prestage enrollment workflows.
- Exposure to backup and disaster recovery tooling (Druva or similar) for endpoint fleets.
- Experience supporting a life sciences, biotech, or other regulated research environment.
- Familiarity with Zero Trust concepts and phishing-resistant authentication (e.g., WebAuthn/FIDO2).
- ITIL Foundation certification or equivalent service management experience.
- Apple Certified Support Professional certification or equivalent
- Apple Business Manager: Maintain ABM hygiene, including enrollment tokens, prestage/zero-touch enrollment, and removal of retired or e-wasted devices to prevent unauthorized re-enrollment.
- Shared and lab devices: Support shared-use and lab instrument endpoints alongside standard user devices, coordinating maintenance windows with lab and facilities teams to minimize disruption.