Salary
—
Posted
Aug 16, 2026
Location
—
Last confirmed open
Sep 25, 2026

What this job asks for AI summary

This senior individual-contributor role owns enterprise patch management, endpoint engineering, and vulnerability remediation across roughly 3,000 endpoints spanning Windows, Linux, macOS, mobile, and Azure-hosted systems. The engineer serves as the technical authority for Microsoft Intune, Entra ID, CrowdStrike Falcon, and Windows Autopilot, and is expected to build advanced PowerShell and KQL-based automation to drive compliance, reduce cyber risk, and support security operations.

Senior level · 7+ years

Must have (11)
Microsoft IntuneMicrosoft Entra IDMicrosoft Defender XDRCrowdStrike FalconPowerShellPKIAzure Update ManagerPatch My PCKQLWindows AutopilotMicrosoft Graph API
Nice to have (12)
PowerShell DSCAzure Logic AppsAzure FunctionsMicrosoft SentinelAzure Log AnalyticsMicrosoft Configuration ManagerAzure ArcConditional AccessSAMLOAuthOpenID ConnectSCIM

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
KQL3%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Microsoft Entra ID50%PowerShell45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 18, 2026. It is a model, not a headcount.

Why we read it this way (8)

Remote status is not stated; defaulted to false (on-site/unspecified).

SOC classification required judgment: the role's primary day-to-day work is security analysis, vulnerability management, and compliance enforcement (15-1212), but a substantial portion involves endpoint and identity infrastructure administration (15-1244). 15-1212 was chosen because vulnerability remediation, security posture management, and compliance reporting are the stated primary mission.

The 7+ years figure is the stated overall experience floor; the 5+ years for patch/vulnerability leadership is a domain-specific sub-requirement captured in context.

No compensation is mentioned in the posting.

Preferred certifications (Microsoft Cybersecurity Architect Expert, Identity and Access Administrator, Security Operations Analyst, Endpoint Administrator, Azure Administrator, Azure Security Engineer, CompTIA Security+, CrowdStrike Falcon Certification, ITIL Foundation) are not emitted as skills — they are credentials, not technologies.

PowerShell DSC, Microsoft Graph PowerShell SDK, Azure Logic Apps, Azure Functions, Microsoft Sentinel, Azure Log Analytics, Microsoft Configuration Manager, Azure Arc, Conditional Access, SAML, OAuth, OpenID Connect, and SCIM appear in the responsibilities/stack narrative rather than in a hard-gated requirements block, so they are marked preferred.

No degree requirement is stated anywhere in the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Azure Automation, Microsoft Graph PowerShell SDK.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗