Sr Staff Endpoint Architect
Irvine, CA - USA
Job Summary
Position Overview
We are seeking an experienced Sr. Staff Endpoint Architect to lead the strategy architecture modernization and engineering of our global Apple and Windows endpoint platforms.
This role will serve as a senior technical authority for macOS Windows iOS and iPadOS. A key focus will be enabling the responsible expansion of Mac adoption by evaluating employee personas business workflows application compatibility security requirements support readiness cost and employee experiencenot simply providing Macs to more users.
The successful candidate will define the future-state endpoint architecture and build secure scalable automated and employee-centered capabilities across the device lifecycle. This individual will partner with Security Identity Infrastructure Networking Application teams Service Management Procurement and business functions to modernize the endpoint environment and deliver a consistent global employee experience.
Key Responsibilities
Endpoint Strategy and Architecture
Define the enterprise endpoint strategy reference architecture and modernization roadmap across Apple and Windows platforms.
Develop a persona-based device strategy that aligns endpoint selection with job responsibilities business workflows application requirements security mobility and employee experience.
Lead assessments of applications workflows peripherals and technical dependencies to identify appropriate Mac and Windows use cases.
Develop a data-driven roadmap for expanding Mac adoption across qualified employee personas and business functions.
Establish standards for endpoint hardware operating systems identity applications security compliance connectivity and lifecycle management.
Evaluate emerging Apple Microsoft digital employee experience automation and AI capabilities for enterprise use.
Present technical recommendations investment priorities risks and progress to technology and business leadership.
Apple and Windows Platform Engineering
Architect and modernize Apple device management using Jamf Pro Microsoft Intune Apple Business Manager Automated Device Enrollment and modern Apple management frameworks.
Architect Windows management using Microsoft Intune Windows Autopilot Microsoft Configuration Manager Entra ID and related cloud-management technologies.
Design secure zero-touch provisioning application delivery configuration compliance recovery replacement and decommissioning experiences for both platforms.
Define the appropriate use of Jamf Intune Configuration Manager co-management and cloud-native management within the endpoint ecosystem.
Establish operating-system testing patching upgrade enforcement exception and vulnerability-response strategies.
Architect identity capabilities using Entra ID Platform SSO Windows Hello for Business Conditional Access passwordless authentication and certificates.
Define endpoint security standards covering FileVault BitLocker privileged access endpoint protection data protection recovery keys local accounts and device compliance.
Engineer scalable application packaging deployment updating and retirement for macOS and Windows applications.
Provide senior technical leadership for complex endpoint identity security application and management-platform issues.
Application Readiness and Device Adoption
Establish a device eligibility framework that identifies the appropriate endpoint platform for each employee persona and business use case.
Maintain cross-platform application catalogs identifying supported conditional incompatible and remediation-required applications.
Partner with application owners and vendors to address compatibility licensing authentication performance and supportability requirements.
Develop solutions for platform-specific dependencies using SaaS alternatives browser-based applications modernization virtualization Windows 365 Azure Virtual Desktop or remote application delivery.
Lead pilots and phased deployments to validate application readiness security supportability and employee experience.
Develop repeatable migration approaches for user data applications identity settings collaboration tools and peripherals.
Partner with Change Management Communications Learning and Support teams to develop adoption campaigns training and migration guidance.
Automation and Modern Endpoint Operations
Build an automation-first engineering practice using PowerShell Bash Zsh Python Microsoft Graph Jamf APIs REST APIs and orchestration platforms.
Automate provisioning application deployment configuration compliance remediation patching inventory reporting and lifecycle management.
Establish source control peer review testing release management rollback and documentation standards for endpoint engineering.
Use endpoint telemetry and digital employee experience data to proactively identify reliability performance compliance and user-experience issues.
Develop self-service and self-healing capabilities that improve employee productivity and reduce support demand.
Explore the responsible use of AI and intelligent automation for troubleshooting compliance analysis proactive remediation and endpoint operations.
Operational Readiness and Technical Leadership
Ensure Global Service Desk and deskside teams are prepared to support Apple and Windows platforms at enterprise scale.
Define support models escalation paths diagnostic workflows knowledge requirements and engineering-to-operations handoffs.
Identify recurring incidents and engineer permanent scalable solutions.
Maintain architecture diagrams engineering standards technical decisions operational procedures and support documentation.
Mentor endpoint engineers lead technical design reviews and establish consistent engineering practices.
Influence cross-functional architecture security application and investment decisions without relying on direct authority.
Qualifications :
Required Qualifications
10 years of experience in endpoint engineering workplace technology enterprise infrastructure or related discipline.
Extensive experience architecting and supporting Apple and Windows endpoints in a large complex or global enterprise.
Demonstrated experience leading an endpoint modernization Mac adoption cloud-management or device-transformation initiative.
Deep expertise with Jamf Pro and strong experience with Microsoft Intune Windows Autopilot and Microsoft Configuration Manager.
Hands-on experience with Apple Business Manager Automated Device Enrollment and Apple application management.
Advanced knowledge of macOS and Windows architecture security configuration deployment and troubleshooting.
Strong experience with Entra ID Platform SSO Windows Hello for Business Conditional Access certificates and passwordless authentication.
Advanced automation skills using PowerShell and at least one of the following: Bash Zsh Python Microsoft Graph Jamf APIs or REST APIs.
Experience implementing enterprise security baselines encryption endpoint protection privileged-access controls and compliance policies.
Experience assessing employee personas business workflows application compatibility and device requirements.
Strong knowledge of enterprise networking including Wi-Fi VPN DNS proxies certificates and Zero Trust.
Ability to translate business requirements into architecture roadmaps execution plans and measurable outcomes.
Strong communication documentation stakeholder management and technical leadership skills.
Experience developing device standards total-cost-of-ownership models technical pilots migration programs and employee enablement.
Familiarity with AI-assisted endpoint operations and self-healing capabilities.
Additional Information :
Preferred Qualifications
Jamf 300 or Jamf 400 certification.
Relevant Microsoft Apple security automation or enterprise architecture certifications.
Experience with Jamf Connect Jamf Protect Microsoft Defender for Endpoint or comparable technologies.
Experience with declarative device management Platform SSO Windows Autopatch Windows 365 or Azure Virtual Desktop.
Familiarity with AutoPkg Installomator PSAppDeployToolkit or similar tools.
Experience with digital employee experience platforms endpoint telemetry and proactive remediation.
Knowledge of CIS NIST ISO 27001 SOC 2 or comparable compliance frameworks.
#LI-TD1
Compensation & Benefits Details
- An employees pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills ability knowledge of the job; (3) performance contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
- The salary range is what we believe to be the range of possible compensation for this role at the time of this posting. We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California Colorado New York or remote jobs that can be performed in California Colorado and New York. This range may be modified in the future.
- If your position is non-exempt you are eligible for overtime pay pursuant to company policy and applicable laws. You may also be eligible for shift differential pay depending on the shift to which you are assigned.
You will be eligible to be considered for bonuses under either WDs Short Term Incentive Plan (STI Plan) or the Sales Incentive Plan (SIP) which provides incentive awards based on Company and individual performance depending on your role and your performance. You may be eligible to participate in our annual Long-Term Incentive (LTI) program which consists of restricted stock units (RSUs) or cash equivalents pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires subject to WDs Standard Terms and Conditions for Restricted Stock Unit Awards.
- We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D legal plan pet insurance critical illness accident and hospital indemnity; tuition reimbursement; transit; the Applause Program; employee stock purchase plan; and the WD Savings 401(k) Plan.
- Note: No amount of pay is considered to be wages or compensation until such amount is earned vested and determinable. The amount and availability of any bonus commission benefits or any other form of compensation and benefits that are allocable to a particular employee remains in the Companys sole discretion unless and until paid and may be modified at the Companys sole discretion consistent with the law.
Notice To Candidates: Please be aware that WD and its subsidiaries will never request payment as a condition for applying for a position or receiving an offer of employment. Should you encounter any such requests please report it immediately to WD Ethics Helpline or email .
Remote Work :
No
Employment Type :
Full-time
About Company
At Western Digital, our vision is to power global innovation and push the boundaries of technology to make what you thought was once impossible, possible. At our core, Western Digital is a company of problem solvers. People achieve extraordinary things given the right technology. For ... View more