MKS2 Technologies logo

InTune Architect - Remote

MKS2 Technologies

RemoteRemoteJob$100–115K/yrPosted 1w agoVerified open 1w ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$100–115K/yr
Location
RemoteRemote
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

Public Trust Clearance EligibilityPublic Trust clearance

Job overview

MKS2 Technologies is hiring an InTune Architect - Remote. MKS2 Technologies seeks an experienced Intune Architect to lead design and implementation of large‑scale Microsoft Intune solutions for the TSA TALON program, driving endpoint management, security compliance, and migration from Blackberry UEM while collaborating with security, identity, networking, and engineering teams.

Key focus areas include Design and implement enterprise Microsoft Intune architecture and governance, Lead Blackberry UEM to Intune migration strategy and SCCM/Configuration Manager co-management initiatives, and Develop device compliance policies, configuration profiles, application deployment standards, and update management strategies.

Important skills include Microsoft Intune, Autopilot, Device Compliance, Configuration Profiles, Application Lifecycle Management, and Win32. Preferred (not required): Zero Trust Architecture, NIST 800-53, FedRAMP, and ATO Processes.

Skills & qualifications

RequiredNice to have

Skills

Microsoft IntuneAutopilotDevice ComplianceConfiguration ProfilesApplication Lifecycle ManagementWin32MSIXMAMRBACScope ManagementConditional AccessMicrosoft Defender for EndpointMicrosoft Entra IDSCCMConfiguration ManagerCo-ManagementPowerShellMDMMAM AdministrationZero Trust ArchitectureNIST 800-53FedRAMPATO ProcessesKQLLog AnalyticsAttack Surface ReductionCertificate ManagementSCEPPKCSWi‑Fi ArchitectureVPN ArchitectureTerraformBicepGitInfrastructure as CodeIncident ManagementDisaster RecoveryChange Management

Qualifications

8+ Years Endpoint Management Experience3+ Years Intune Architecture ExperiencePublic Trust Clearance EligibilityExperience Supporting Federal AgenciesExperience With Public Trust Environments

Full job description

MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our “Mission First” orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.


InTune Architect

Program: Transportation Security Administration (TSA) Technology for Applications, Logistics, Operations, and Network (TALON)

Start Date: 9/15/2026 - 5 year POP

Pay: $100,000 - $115,000 - benefits available

Location: Fully Remote

Position Overview

MKS2 is seeking an experienced Intune Architect to support the TALON Program under Accenture Federal Services (AFS). This role will lead the design and implementation of a large-scale Microsoft Intune architecture, supporting Windows, iOS/iPadOS, and Android environments. The architect will drive modern endpoint management, security compliance, and Blackberry UEM to Intune migration efforts while partnering with Security, Identity, Networking, and Engineering teams to deliver a Zero Trust-aligned endpoint platform.

Key Responsibilities

  • Design and implement enterprise Microsoft Intune architecture and governance.
  • Lead Blackberry UEM to Intune migration strategy and SCCM/Configuration Manager co-management initiatives.
  • Develop device compliance policies, configuration profiles, application deployment standards, and update management strategies.
  • Design Conditional Access, security baselines, BitLocker governance, and Defender for Endpoint integrations.
  • Architect Entra ID device identity, authentication, and access management solutions.
  • Develop PowerShell automation, reporting, and configuration-as-code practices.
  • Lead pilot deployments, migration waves, executive briefings, and stakeholder communications.
  • Create technical standards, architecture documentation, and operational procedures.

Required Qualifications

  • Minimum 8 years of experience in endpoint management, systems engineering, or related field.
  • 3+ years architecting Microsoft Intune solutions in enterprise environments.
  • Expert knowledge of:
    • Microsoft Intune
    • Autopilot
    • Device Compliance & Configuration Profiles
    • Application Lifecycle Management (Win32, MSIX, MAM)
    • RBAC and Scope Management
  • Experience with:
    • Conditional Access
    • Microsoft Defender for Endpoint
    • Entra ID (Azure AD)
    • SCCM/Configuration Manager Co-Management
    • PowerShell Automation
    • MDM/MAM Administration
  • Strong experience leading large-scale enterprise endpoint modernization projects.

Preferred Qualifications

  • Experience supporting federal agencies or Public Trust environments.
  • Knowledge of Zero Trust architecture and NIST 800-53 controls.
  • Experience with FedRAMP and ATO processes.
  • Advanced expertise with:
    • Defender for Endpoint
    • KQL and Log Analytics
    • Attack Surface Reduction (ASR)
    • Certificate Management (SCEP/PKCS)
    • Wi-Fi and VPN Architecture
  • Experience with Terraform, Bicep, Git-based governance, and Infrastructure as Code.
  • Strong incident response, disaster recovery, and change management experience.

Clearance: Must be eligible to obtain and maintain a Public Trust clearance or higher.


Diversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

You've read the whole posting — now see how you match it.