Largeton Group · 11 hours ago
Mac Endpoint Engineer (macOS + Intune)
Largeton Group is seeking a Mac Endpoint Engineer to enhance the macOS experience within a Microsoft-centric enterprise. The role focuses on building and hardening a modern Intune-managed macOS environment, ensuring seamless enrollment and compliance while collaborating with various teams for effective deployment and security measures.
ConsultingInformation TechnologyTraining
Responsibilities
Design/operate zero-touch enrollment with ABM + ADE (PreStage through post-enrollment fixes)
Build a consistent first sign-in experience using PSSO + Intune
Improve enrollment flows, bootstrap content, and post-enrollment automations
Lead macOS app packaging for Intune (PKG/DMG + pre/post scripts, detection rules, dependencies, retries, uninstall logic)
Create a scalable third-party app deployment model with staged rings, rollback plans, and change control
Collaborate with Packaging/QA on versioning, testing, and release notes
Manage Intune baseline configs & compliance policies; suggest UX/reliability improvements
Enforce CIS macOS benchmark controls (macOS 26+); own configuration/enforcement, partner with InfoSec
Integrate/support: Entra ID, Defender for Endpoint (DLP), CrowdStrike, CyberArk EPM, Qualys, GlobalProtect ZTNA
Automate via scripting (bash/zsh/Python; PowerShell for Graph) – provisioning, remediations, health checks, reporting
Deliver actionable Intune dashboard metrics (enrollment success, sign-in time, compliance drift, packaging SLAs)
Write KB articles/how-tos; transfer knowledge to Support; provide occasional Tier 3 guidance (no on-call)
Partner with Identity, Security, Networking, and Support to prepare for go-live and scale across US users
Contribute to standards, guardrails, and SOPs for long-term stability
Qualification
Required
3–5+ years enterprise macOS MDM (Intune required)
Strong Intune macOS packaging expertise (PKG/DMG, scripts, detection, rings, rollback)
Hands-on ADE zero-touch + PSSO implementation
Scripting: bash/zsh/Python (PowerShell/Graph as needed)
Experience enforcing CIS controls via Intune profiles/policies
Familiarity with Defender, CrowdStrike, CyberArk EPM, Qualys, and GlobalProtect
Excellent documentation & knowledge-transfer skills
Self-healing remediations / drift correction
Preferred
iOS/iPadOS in Intune (bonus)
Entra ID Conditional Access for macOS
Current Apple management trends (PSSO, macOS security/privacy)