Overview
In this EUC Engineer role, you own and optimize the firm’s endpoint estate, focusing on Microsoft Intune, Defender for Endpoint, and Entra ID. You will strengthen security, compliance, and operational stability across Windows 11, iOS, and Android devices. You’ll partner with a small IT team to deliver improvements, investigate incidents, and drive automation. This hybrid role offers genuine ownership in a security-focused, SME/financial services environment with a clear impact on risk management and user experience.
Pay / Benefits
- hybrid work arrangement (4 days in London office, 1 day remote)
- salary range 45,000–60,000 per annum
Responsibilities
- Own and manage Windows 11, iOS, and Android endpoints via Microsoft Intune (Autopilot, configuration, compliance, patching, deployment)
- Maintain endpoint security standards, lifecycle management, and secure baselines
- Administer Defender for Endpoint (alert triage, investigations, isolation, remediation, EDR operations)
- Manage Attack Surface Reduction policies, device controls, and Intune security baselines
- Create and improve endpoint compliance frameworks aligned to security policies
- Manage Entra ID (Conditional Access, MFA, device compliance, device registration) and related troubleshooting
- Investigate and resolve complex endpoint/identity/security incidents as senior escalation point
- Deliver vulnerability remediation and patch management per risk requirements
- Develop automation using PowerShell, Microsoft Graph, and security tooling
- Contribute to IT projects (endpoint refreshes, office moves, upgrades) and maintain technical documentation
- Produce high-quality end-user knowledge articles
Key requirements
- 4–5 years in endpoint/EUC engineering or similar within financial services, SME, or MSP
- Hands-on ownership of Microsoft Intune and endpoint configuration
- Strong experience with Microsoft Defender for Endpoint including EDR and remediation
- Understanding of endpoint security baselines, hardening, ASR, vulnerability management, and compliance controls
- Experience with Entra ID (Azure AD) including Conditional Access and MFA
- Strong Windows 11 troubleshooting and endpoint engineering skills
- Experience with PowerShell and Microsoft Graph for automation
- Proactive troubleshooting of complex endpoint/identity/security issues
- Excellent communication and ownership mindset
- proactive and ownership-driven approach
- excellent communication
- ability to work in a small, collaborative team
- Microsoft Intune (device management, compliance, deployment)
- Microsoft Defender for Endpoint (EDR, alert investigation, remediation)
- Entra ID (Azure AD) including Conditional Access and MFA
…
