APAC IT Windows Endpoint Engineer
Unlock your potential with Dassault Systèmes, a global leader in Scientific Software Engineering as an APAC IT Windows Endpoint Engineer in Pune, Maharashtra!
In our APAC IT organization, we are looking for a responsible for leading the regional strategy, operations, security, and compliance of Windows endpoints and mobile devices across APAC.
You will join the WW Endpoint and Technical Compliance team which is responsible for managing Windows Endpoints, Patching, Security hardening and vulnerabilities compliance, MDM, JAMF infrastructure and part of NAC and EDR management. You will manage the integration of third-party companies in the context of acquisitions. You will participate in the definition and deployment of security best practices. You will have the opportunity to implement new products to better facilitate the business and integrate new hardware based on market study.
As part of an international team of about 27 people, you will work in collaboration with global teammates in Vélizy, France, Pune, US, Canada. As a global service provider, you will work with the central and local IT teams and R&D organizations across all of Dassault Systèmes sites.
Role Description & Responsibilities:
We are seeking an experienced Engineer providing L3 technical leadership and architecture for the Windows Endpoint environment, ensuring secure, scalable, compliant, and reliable endpoint services.
· Provide L3 engineering and technical escalation for complex Windows endpoint issues.
· Design and maintain endpoint architecture using Intune, Autopilot, SCCM/MECM, Entra ID, and Group Policy.
· Lead Windows 10/11 deployment, patching, application packaging, and endpoint lifecycle management.
· Own and improve Windows endpoint security, including security baselines, hardening, encryption, Defender, vulnerability remediation, and device compliance.
· Implement and manage security controls such as BitLocker, Microsoft Defender for Endpoint, Conditional Access, endpoint attack-surface reduction (ASR), firewall, antivirus, and application controls.
· Monitor and remediate endpoint vulnerabilities, configuration drift, and security compliance gaps.
· Troubleshoot complex OS, application, configuration, performance, and security issues.
· Drive endpoint modernization, automation, standardization, and continuous improvement.
· Support technical design, solution architecture, and proof-of-concepts for new endpoint and security technologies.
· Produce technical documentation, security standards, architecture designs, and operational procedures.
· Produce knowledge transfer to L1/ L2 teams to elevate them to support L3 teams
Qualifications:
· B. Tech / B.E (CS / IT / E&TC) from premier institutions with good academic track records.
· 5+ years of experience in Windows Endpoint / EUC / Modern Workplace engineering.
· Strong hands-on experience with Microsoft Intune, Autopilot, SCCM/MECM, Entra ID, and Group Policy.
· Strong knowledge of Windows 11 administration, troubleshooting, patching, hardening, and endpoint security.
· Strong PowerShell scripting and automation skills.
· Strong understanding of BitLocker, Conditional Access, security baselines, vulnerability management, and endpoint compliance.
· Experience supporting security incidents, vulnerability remediation, and audit/compliance requirements.
· Proven experience providing L3 support and technical escalation.
· Experience contributing to or leading endpoint architecture and technical design.
· Strong analytical, troubleshooting, documentation, and stakeholder management skills.
· Relevant Microsoft certifications such as MD-102 / Endpoint Administrator are desirable.
What’s in it for you?
· Working across APAC or multinational environments provides experience with large-scale deployments, different business requirements, and senior stakeholders.
· Build experience with Microsoft's modern cloud-managed endpoint ecosystem, which is highly relevant to digital workplace transformation.
· Develop valuable hands-on experience in endpoint hardening, vulnerability management, Zero Trust, Conditional Access, EDR, NAC
· The role has direct influence on security, compliance, employee productivity, and user experience.
As a game-changer in sustainable technology and innovation, Dassault Systèmes is striving to build more inclusive and diverse teams across the globe. We believe that our people are our number one asset and we want all employees to feel empowered to bring their whole selves to work every day. It is our goal that our people feel a sense of pride and a passion for belonging. As a company leading change, it’s our responsibility to foster opportunities for all people to participate in a harmonized Workforce of the Future.