Lead Mobility Engineering SME

Lead
CompanyAIG Seguros Brasil
LocationNY-New York, NC-Charlotte, GA-Atlanta
CategorySoftware Engineering
SeniorityLead
Workplace-
Posted2026-09-23
Estimated salary$12K - $21K (a market estimate, not the employer's figure)
Viaworkday

Description

At AIG, we are reimagining the way we help customers to manage risk. Join us as a Lead Mobility Engineering SME  to play your part in that transformation. It’s an opportunity to grow your skills and experience as a valued member of the team.

Make your mark in Information Technology

At AIG, technology is at the heart of everything we do, from underwriting risks to processing claims. The Information Technology (IT) team equips our colleagues with the latest tools to complete their work efficiently, with the highest standards of excellence. The team is responsible for shielding the company’s systems from security risks, while designing technology strategies that enable AIG’s businesses to achieve their goals. Innovation in IT drives innovation across the organization.

How you will create an impact

The Lead Mobility Engineering SME is the senior hands-on engineer accountable for the architecture, engineering, security, automation, and operational health of the enterprise mobile and modern endpoint ecosystem — Microsoft 365 mobile services, Microsoft Intune, MDM and MAM, Apple iOS/iPadOS, Android Enterprise, and modern Windows provisioning including Autopilot. This is not a coordination or console-administration role, and it is deliberately not a single-discipline one: the estate depends on mobility platform engineering, modern authentication, endpoint security and network connectivity, and automation, and strength across all four is the bar. The role designs, builds, tests, automates, troubleshoots to root cause, documents, and leads controlled production change end to end.

Mobility platform engineering. Own the architecture and configuration standards for Intune, enrollment, MAM and app protection, compliance policies, configuration profiles, app deployment, certificates, and secure access. Own the Apple stack end to end — Apple Business Manager, Automated Device Enrollment, APNs certificate lifecycle, VPP, supervision, Declarative Device Management, managed software updates — and Android Enterprise in every mode: fully managed, dedicated/kiosk, COPE, and work profile, including managed Google Play, zero-touch enrollment, OEMConfig and Knox. Define compatibility, ring-based rollout, and lifecycle plans so major OS releases are planned events, not fire drills.

Multi-platform UEM breadth. Apply working knowledge of other enterprise mobility platforms — Omnissa Workspace ONE UEM (formerly VMware Workspace ONE / AirWatch), MobileIron/Ivanti Neurons, Jamf, SOTI or BlackBerry UEM — to migration, coexistence, and platform-selection decisions, and translate legacy profile, policy, and app configurations into their modern Intune equivalents without loss of control coverage.

Modern authentication and identity. Engineer device authentication across Entra ID registration, Entra join and hybrid join, Primary Refresh Token behavior, device-based Conditional Access, and token and session controls. Deliver passwordless and phishing-resistant authentication on mobile — platform credentials, FIDO2 and passkeys, certificate-based authentication, Authenticator broker behavior. Own certificate infrastructure: SCEP and PKCS, the Intune Certificate Connector, Cloud PKI, NDES, trusted roots, and renewal automation. Design Conditional Access and prove blast radius in report-only mode before production. Debug OAuth 2.0, OIDC, SAML, and MSAL failures at protocol level.

Modern endpoint management and Autopilot. Own Windows Autopilot end to end — user-driven and self-deploying modes, pre-provisioning, Autopilot device preparation, Enrollment Status Page tuning, hardware hash and attestation, and the OEM supply process. Operate settings catalog, security baselines, filters, scope tags and RBAC, Windows Update for Business and Autopatch rings. Retire legacy through co-management transition and GPO migration. Own Win32 and MSIX packaging, detection logic, and supersedence chains.

Security and governance. Engineer controls with Cybersecurity, IAM, Privacy and Legal: compliance, app protection, DLP, encryption, and certificate-based access. Integrate Defender for Endpoint and mobile threat defense signal into compliance and Conditional Access; apply ASR rules and jailbreak and root detection. Own key escrow, device wipe and departure lifecycle, Endpoint Privilege Management and LAPS. Maintain secure baselines, remediate drift and unsupported OS versions to defined targets, and supply audit evidence from reporting rather than screenshots.

Network engineering for mobility. Design and troubleshoot 802.1X and EAP-TLS Wi-Fi, RADIUS and NPS integration, roaming and captive portal behavior; per-app and always-on VPN, Global Secure Access and ZTNA patterns, and split-tunneling decisions. Diagnose DNS, proxy and TLS inspection effects on certificate pinning and push notifications, APNs and FCM egress, IPv6, and carrier and eSIM behavior — converting a capture or trace into a configuration change rather than a handoff.

Automation and engineering practice. Automate with PowerShell, Microsoft Graph, REST and JSON: bulk policy deployment, lifecycle operations, compliance and expiry reporting, and drift detection against baseline. Apply source-controlled policy-as-code with peer review and promotion across rings. Close operational loops with Power Automate, Azure Automation or Functions, proactive remediations, and ITSM integration. Build proactive monitoring and alerting for enrollment failure, noncompliance, deployment error and service degradation.

Change, operations, and technical leadership. Own changes from scope and impact through test evidence, pilot, implementation, validation, communications and tested backout. Lead Tier 3/4 troubleshooting and root-cause analysis; drive vendor escalations with complete diagnostic evidence. Maintain architecture diagrams, designs, runbooks and decision records complete enough for another qualified engineer to operate and recover the service. Mentor engineers, set engineering quality standards, and maintain a prioritized roadmap and technical debt backlog.

What you'll need to succeed

##

  • 7+ years in endpoint, mobility, or digital workplace engineering, with significant ownership of enterprise mobile services in a large or complex environment.
  • Deep hands-on Intune engineering: enrollment, compliance, configuration profiles, app deployment, app protection, reporting, troubleshooting.
  • Strong MDM and MAM architecture knowledge across corporate-owned and BYOD scenarios, plus iOS/iPadOS and Android Enterprise management models and OS lifecycle.
  • Hands-on exposure to at least one additional UEM platform such as Workspace ONE UEM (AirWatch), Ivanti/MobileIron, Jamf or SOTI, including migration or coexistence work.
  • Modern Windows provisioning experience including Autopilot, ESP troubleshooting, and update ring strategy.
  • Entra ID, modern authentication, Conditional Access dependencies, and certificate-based secure access.
  • Practical mobility network competence: 802.1X and certificate-based Wi-Fi, VPN and per-app VPN, DNS, proxy and TLS inspection effects.
  • Demonstrated automation with PowerShell, Graph, REST APIs and JSON, and root-cause troubleshooting using logs, telemetry and structured testing.
  • Enterprise change, incident and problem discipline, high-quality technical documentation, and clear communication to technical and nontechnical stakeholders.

Preferred Qualifications

  • Advanced End-to-end ownership of the  Microsoft Intune platform  — design, engineering, and Tier 3/4 support across tenant and RBAC architecture, enrollment, policy, app deployment, and certificate services — with equivalent hands-on design, engineering and support experience on  Omnissa Workspace ONE UEM (AirWatch) .
  • Deep mobile platform specialization — Apple Business Manager and Declarative Device Management at scale, Android Enterprise dedicated and kiosk fleets, mobile threat defense, and zero-touch provisioning.
  • Large-scale UEM