Assoc Prin Eng MDM VMware WorkspaceOne
Job Summary
What success looks like in this role:
About the Role
This position is for a L3 Engineer will act as a subject-matter expert for a multi-tenant Workspace ONE MSP environment supporting approximately 30 clients spanning shared managed-service tenants dedicated customer SaaS consoles and legacy on-premises deployments. The L3 Engineer is accountable for integrations escalated incident resolution upgrade planning automation strategy and technical governance across all supported customer environments.
Key Responsibilities
- Platform Architecture & Environment Management: Own the end-to-end Workspace ONE architecture across SaaS Hybrid and On-Premises models covering UEM Workspace ONE Access Unified Access Gateway (UAG) Assist Intelligence ACC/AWCM connectors and gateways.
- Define Organization Group hierarchies (tenant sub-OGs staging platform-based and business-unit OGs) global UEM settings and environment segregation across dev/test/pre-prod/production controlling configuration promotion between environments.
- Plan document and execute upgrades for UEM Access UAG Assist and related components including rollback readiness and post-upgrade validation.
- Enrollment & Device Lifecycle: Design enrollment strategies for Android iOS macOS Windows and rugged devices across Corporate-Owned Corporate-Shared and BYOD models including Autodiscovery zero-touch DEP/Automated Device Enrollment Windows OOBE and PPKG provisioning and staging scenarios.
- Policies Profiles & Baselines: Define profile and baseline architecture per platform; design and debug custom ADMX/OMA-URI payloads; resolve conflicts between ADMX profiles CIS/security baselines custom settings and legacy GPOs.
- Application Lifecycle: Own the application lifecycle strategy: Win32/MSI/EXE PKG APK/AAB and Managed Google Play ABM/VPP delivery Omnissa SDK integration deployment ring design (pilot to broad) dependency and rollback planning.
- Android Enterprise & Rugged: Architect Android Enterprise deployments (Work Profile Fully Managed COPE Dedicated) including rugged fleets Secure Launcher kiosk designs corporate-shared device workflows and OS/app update strategy.
- Apple Ecosystem: Maintain the Apple ecosystem integrations: ABM/DEP profiles with supervision and user affinity APNs certificate lifecycle VPP token management and resolution of ABMVPPUEM synchronization issues.
- Identity SSO & Access: Design identity and access integrations: AD via ACC/LDAP Microsoft Entra ID Workspace ONE Access IdPs and access policies SAML federations with third-party IdPs and SaaS applications Android CertProxy SSO iOS Kerberos SSO conditional access design and custom role/delegated administration models.
- UAG & Secure Access: Architect and operate UAG: OVA/OVF deployment in vSphere Photon OS administration one/two/three-NIC DMZ designs HA behind enterprise load balancers (F5 or equivalent) session persistence design and SSL passthrough/bridging/offloading topologies with correct certificate cipher and SNI handling.
- Design and troubleshoot Per-App VPN / Workspace ONE Tunnel with Device Traffic Rules SEG (with/without Kerberos) Content Gateway and ENS including end-to-end network path analysis (routing firewall NAT DNS ports).
- PKI & Certificates: Define PKI strategy for certificate-based authentication; manage CAs SCEP and issuance workflows public SSL certificate lifecycles Java keystores for AWCM and deep trust-chain troubleshooting using OpenSSL (chains CSR validation TLS handshakes CRL/OCSP SAN/hostname mismatches).
- Automation & Intelligence: Design Freestyle Orchestrator workflows for onboarding remediation and change automation; integrate Workspace ONE Intelligence for dashboards automations webhooks/SIEM/ticketing integration and management-level reporting.
- Privacy & Governance: Define privacy governance for BYOD/Corporate-Owned/Corporate-Shared scenarios aligned with customer contractual and data-protection expectations (Work Profile iOS User Enrollment data-collection minimization).
- L3 Troubleshooting & Incident Ownership: Serve as final internal escalation for complex incidents across UEM Access UAG ACC/AWCM Assist SEG Content Gateway and ENS; perform root-cause analysis; troubleshoot Windows communication stack (AWCM/WNS) issues; lead service restoration across heterogeneous customer architectures.
- Vendor Escalation Documentation & Mentoring: Manage vendor escalations to Omnissa Support (case creation evidence and log collection reproduction fix validation); maintain runbooks architecture diagrams and best-practice standards; mentor L1/L2/L2.5 associates and act as technical decision-maker for projects and transitions.
Required Skills & Experience
- 7-8 years in enterprise End User Computing / mobility with 5 years of expert hands-on Workspace ONE UEM administration and architecture in multi-tenant or MSP environments.
- Proven l expertise across Workspace ONE UEM Access UAG Assist Intelligence ACC AWCM SEG Content Gateway ENS and Tunnel.
Preferred Qualifications
- Omnissa/VMware certification (e.g. VCP/VCAP Digital Workspace or equivalent).
- French language proficiency
#LI-UG1
You will be successful in this role if you have:
BA/BS degree and 7-8 years relevant experience OR equivalent combination of education and experience
Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age blood type caste citizenship color disability family medical history family status ethnicity gender gender expression gender identity genetic information marital status national origin parental status pregnancy race religion sex sexual orientation transgender status veteran status or any other category protected by law.
Local employment practices and rights may vary by jurisdiction and are subject to applicable local laws. This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers.
If you are a US job seeker unable to review the job opportunities herein or cannot otherwise complete your expression of interest without additional assistance and would like to discuss a request for reasonable accommodation please contact our Global Recruiting organization at . US job seekers can find more information about Unisys EEO commitment here.
About Company
Unisys is a global information technology company that specializes in providing industry-focused solutions integrated with leading-edge security to clients in the government, financial services and commercial markets. Unisys offerings include security solutions, advanced data analytic ... View more