Application Administrator
Description
Department: Innovation and Technology Department
Salary: $81,226.00 - $116,762.94 Commensurate with Experience
Welcome to the City of Charlotte
Charlotte is America’s Queen City, opening her arms to a diverse and inclusive community of residents, businesses and visitors alike. Here you will find a safe, family-oriented city where people work together to help everyone thrive. The mission of the City of Charlotte is to deliver quality public services and promote the safety, health, and quality of life for all residents.
Our guiding principles include:
-
Attracting and retaining a skilled and diverse workforce
-
Valuing teamwork, openness, accountability, productivity, and employee development
-
Providing all customers with courteous, responsive, accessible, and seamless quality services
-
Taking initiative to identify, analyze, and solve problems
-
Collaborating with stakeholders to make informed decisions
SUMMARY
We are looking for a skilled Unified Endpoint Engineer specializing in Microsoft Endpoint Configuration Manager (MECM/SCCM), Microsoft Intune, and related endpoint technologies to support and enhance the City's enterprise Unified Endpoint Management (UEM) environment. This position is part of a team responsible for engineering, implementing, maintaining, and supporting endpoint management solutions across a large enterprise environment.
The Unified Endpoint Engineer will support the lifecycle of Windows endpoints, including operating system provisioning and upgrades, application deployment, patch management, configuration management, automation, security compliance, and troubleshooting. The position will also support the City's continued adoption of Microsoft Intune, co-management, modern provisioning, and mobile device management technologies.
Major Duties and Responsibilities
- Administer, maintain, and enhance enterprise endpoint management solutions using Microsoft Endpoint Configuration Manager (MECM/SCCM), Microsoft Intune, and related technologies.
- Engineer and support Windows 11 provisioning, operating system deployment, feature upgrades, configuration management, and device lifecycle processes across the enterprise.
- Package, test, deploy, maintain, and troubleshoot enterprise applications using MECM/SCCM, Intune, PowerShell, and other endpoint management technologies.
- Coordinate and execute monthly Windows security patching and endpoint remediation activities, including testing, deployment, troubleshooting, compliance monitoring, and resolution of deployment failures.
- Develop, maintain, test, and troubleshoot PowerShell scripts and other automation used for endpoint administration, software deployment, configuration management, reporting, and remediation.
- Configure, test, deploy, and maintain Group Policy Objects (GPOs), endpoint configuration policies, compliance policies, and related controls in accordance with enterprise standards and security requirements.
- Support Microsoft Intune and co-management capabilities, including device enrollment, configuration profiles, compliance policies, application deployment, and migration of endpoint management capabilities to modern management platforms.
- Monitor endpoint health, deployment status, patch compliance, configuration compliance, and other operational metrics; investigate issues and implement corrective actions as needed.
- Troubleshoot complex Windows endpoint issues involving operating systems, applications, registry settings, services, file systems, Active Directory, Group Policy, networking, security controls, and endpoint management technologies.
- Support endpoint security and vulnerability management activities by implementing approved security configurations, remediating vulnerabilities, and assisting with zero-trust, PCI, and other enterprise security requirements.
- Support management of mobile and Apple devices using technologies such as Microsoft Intune, Apple Business Manager, Mobile Device Management (MDM), and Mobile Application Management (MAM).
- Participate in testing and implementation of endpoint changes through established change management processes, including documenting changes, evaluating implementation impacts, coordinating deployments, and supporting rollback or remediation activities when necessary.
- Participate in endpoint technology projects and coordinate technical activities with Cybersecurity, Identity, Service Desk, Infrastructure, Networking, Application Teams, departmental IT liaisons, vendors, and other stakeholders.
- Create and maintain technical documentation, operational procedures, deployment documentation, troubleshooting guides, and knowledge articles supporting endpoint management services.
- Provide technical guidance and assistance to Service Desk personnel, departmental technology staff, other UEM team members, and internal customers regarding endpoint management technologies and issues.
- Evaluate endpoint management technologies and identify opportunities to improve automation, reliability, security, user experience, and operational efficiency.
- Use modern productivity and AI-assisted tools, where appropriate, to improve scripting, documentation, troubleshooting, knowledge sharing, and operational efficiency.
Knowledge, Skills & Abilities
- Strong working knowledge of Microsoft Endpoint Configuration Manager (MECM/SCCM) and enterprise endpoint management concepts.
- Experience with Microsoft Intune and an understanding of co-management between MECM/SCCM and Intune.
- Experience with Windows 10/11 operating system deployment, provisioning, feature upgrades, patching, application deployment, and endpoint configuration management.
- Experience packaging, testing, deploying, and troubleshooting Windows applications in an enterprise environment.
- Proficiency with PowerShell scripting for endpoint administration, automation, troubleshooting, and remediation.
- Working knowledge of Windows operating system components including registry, services, file systems, security, and operating system configuration.
- Experience administering and troubleshooting Active Directory and Group Policy Objects (GPOs).
- Knowledge of Microsoft Entra ID and its relationship to enterprise endpoint management and device identity.
- Working knowledge of networking concepts including DNS, DHCP, TCP/IP, and endpoint connectivity troubleshooting.
- Understanding of endpoint security, vulnerability management, secure configuration, compliance policies, and data protection practices.
- Experience using endpoint reporting, monitoring, and analytics to identify deployment, compliance, performance, and operational issues.
- Knowledge of Microsoft Intune device enrollment, configuration profiles, compliance policies, application management, and related modern management capabilities.
- Familiarity with Apple Business Manager, iOS, Android, macOS, MDM, and MAM technologies.
- Ability to troubleshoot complex technical problems, identify root causes, and implement effective solutions.
- Ability to manage multiple assignments and technical initiatives while coordinating effectively with infrastructure, security, service desk, application, and departmental stakeholders.
- Strong customer service, communication, documentation, and organizational skills with the ability to communicate effectively with technical and non-technical audiences.
- Ability to work effectively as part of a technical engineering team while independently managing assigned responsibilities.
Required Qualifications
- Three (3) or more years of progressively responsible IT experience involving enterprise endpoint management, systems administration, desktop engineering, or related technologies.
- Hands-on experience administering Microsoft Endpoint Configuration Manager (MECM/SCCM) in an enterprise environment.
- Experience supporting Windows 10/11 endpoint lifecycle activities, including operating system deployment or provision