Endpoint Engineer
Company Description
At Swissquote, we’re all in.
All in to shake things up. All in to build the bank people actually want to use. All in to make finance less boring — and a lot more powerful.
We’re Switzerland’s leading digital bank — 1,400+ people across Europe, the Middle East and Asia, building real financial solutions for over a million clients worldwide. From trading and investing to everyday banking, we cover the full picture. We move fast, but we build things we’re genuinely proud of. Have a look behind the scenes by checking Humans of Swissquote on Instagram.
Growing fast creates room. Room to try things, own things, and grow at a pace most places can’t offer. Whether you like the spotlight or prefer to just put your head down and do great work, there’s space for both here.
We’ve ditched the dress code — but never the chance to celebrate. Big win or small, we make it count. The kind of place where the atmosphere takes care of itself.
As an equal opportunity employer, we welcome candidates from all backgrounds, experiences and perspectives to join our team and contribute to our shared success.
Feeling it? It’s a good start. Apply.
Job Description
The Endpoint Engineer is a key member of the Endpoint Administration & Protection team, responsible for the management, compliance, protection and lifecycle of corporate endpoints across the organisation. The role brings specialist expertise in macOS and mobile platforms including iOS, iPadOS and Android, complementing the team's existing Windows capabilities. Working primarily with Microsoft Intune and Microsoft Defender for Endpoint, the Endpoint Engineer ensures that endpoints remain secure, compliant, operational and aligned with business and security requirements. The successful candidate is curious, adaptable and proactive, continuously seeking opportunities to improve the endpoint experience, increase automation and strengthen endpoint security posture.
macOS and Mobile Device Management
- Act as the primary technical specialist for macOS, iOS, iPadOS and Android endpoint management.
- Design, implement and maintain device management capabilities using Microsoft Intune and platform-native technologies.
- Manage Apple Business Manager integration, Automated Device Enrollment (ADE) and Apple device lifecycle processes.
- Manage Android Enterprise enrollment models and operational administration.
- Ensure devices are enrolled, compliant, properly configured and supported throughout their lifecycle.
- Troubleshoot complex device management, enrollment and configuration issues across supported platforms.
- Provide technical guidance and documentation for endpoint administrators, Service Desk teams and stakeholders.
Intune Compliance and Configuration Management
- Design, implement and maintain Microsoft Intune configuration profiles, device restrictions and endpoint management policies.
- Develop and maintain device compliance policies and compliance reporting across all supported platforms.
- Support integration between compliance policies and Conditional Access controls in collaboration with Identity and Information Security teams.
- Maintain enrollment methods and provisioning workflows, including awareness of Windows Autopilot processes and integration points.
- Monitor platform health, configuration drift and policy effectiveness.
- Continuously evaluate new Microsoft Intune capabilities and recommend adoption where business value exists.
Endpoint Protection and Microsoft Defender for Endpoint
- Own the operational health and enforcement of Microsoft Defender for Endpoint across Windows, macOS and mobile platforms.
- Ensure Defender onboarding, deployment, policy assignment, reporting and agent health remain at target service levels.
- Implement and maintain endpoint security controls defined by Information Security.
- Monitor protection coverage, health status and deployment gaps across the endpoint estate.
- Produce operational reporting and remediation plans for non-compliant or unprotected devices.
- Collaborate with Security Operations during investigations requiring endpoint visibility or remediation actions.
- Maintain endpoint protection platforms to supported and secure versions.
Information Security defines security standards, baselines and control requirements. This role is responsible for implementing, enforcing, operating and maintaining those controls on endpoint platforms and reporting on compliance, coverage and operational gaps.
Application Packaging and Deployment
- Package, test, deploy and maintain applications through Microsoft Intune for both Windows and macOS devices.
- Manage Win32 applications, MSI deployments, executable wrappers, Microsoft Store applications, Line-of-Business applications and macOS application packages.
- Develop deployment strategies that minimise user disruption and maximise reliability.
- Manage application lifecycle processes including onboarding, updating, supersedence, retirement and removal.
- Support update rings and deployment strategies for operating systems and applications.
- Maintain documentation, testing procedures and deployment standards.
Operations and Continuous Improvement
- Monitor service health, platform performance and compliance metrics across endpoint technologies.
- Investigate root causes of recurring issues and implement permanent corrective actions.
- Identify opportunities for automation, simplification and service improvement.
- Maintain accurate technical documentation, standards and operational procedures.
- Participate in incident resolution, problem management and change processes.
- Stay current with Microsoft roadmap developments, endpoint security trends and modern management practices.
- Take ownership of problems and initiatives through to completion, ensuring solutions are documented and operationally sustainable.
Qualifications
- 4+ years of experience in endpoint engineering, endpoint administration or modern workplace management roles.
- Strong hands-on experience with Microsoft Intune administration and endpoint management.
- Experience managing macOS devices in enterprise environments.
- Experience managing iOS, iPadOS and Android devices using enterprise MDM solutions.
- Strong understanding of device compliance policies, configuration profiles and enrollment methods.
- Experience implementing and operating Microsoft Defender for Endpoint.
- Experience with application packaging and deployment for Windows and macOS platforms.
- Knowledge of Microsoft Entra ID and Conditional Access integration.
- Experience troubleshooting endpoint, operating system and device management issues.
- Strong documentation and operational process discipline.
- Excellent communication and stakeholder management skills.
Desirable Skills
- Scripting experience using PowerShell, Bash, Mac Shell Scripts or Python.
- Experience with Apple Business Manager and Automated Device Enrollment.
- Experience with Windows Autopilot.
- Experience with Jamf Pro or comparable Apple management platforms.
- Experience with endpoint automation and reporting using Microsoft Graph.
- Familiarity with security operations processes and endpoint incident response.
- Microsoft MD-102 certification.
- Microsoft security, endpoint management or modern workplace certifications.
Mindset, Behaviours and Ways of Working
We are looking for someone who combines strong technical capability with a continuous improvement mindset.
- Dynamic and adaptive, comfortable working in environments where technology, security requirements and business priorities evolve frequently.
- Demonstrates a growth mindset by actively learning new technologies and continuously improving professional knowledge.
- Naturally curious and focused on understanding root causes, not simply addressing symptoms.
- Takes initiative, identifies improvement opportunities and follows them through to completion.
- Demonstrates ownership and accountability for operational outcomes.
- Approaches incidents and challenges as opportunities to learn and strengthen services.
- Communicates clearly with technical and non-technical stakeholders.
- Collaborates effectively across engineering, security and support teams.
- Maintains a strong customer and service-oriented mindset while balancing risk and security requirements.
What We Offer
- The opportunity to work with modern endpoint management and security technologies at enterprise scale.
- A collaborative engineering culture that values ownership, curiosity and continuous improvement.
- Exposure to cross-functional initiatives involving Information Security, Security Operations and Workplace Technology teams.
- Opportunities for professional development, certification and ongoing technical learning.
- The ability to influence endpoint strategy, platform evolution and service improvement initiatives.
- Flexible ways of working and a supportive team environment focused on knowledge sharing and engineering excellence.
Additional Information
Please note that Swissquote never requests sensitive personal information or payment of any kind during the recruitment process. Any such request is fraudulent.
SQ2
Job Details
Experience
Mid · 4+ yrs