Systems Engineering Advisor-MDM L3+ MAC
Apply now »Date: Jul 24, 2026
Location: Noida, UP, IN
Company: NTT DATA Services
Req ID: 373594
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Systems Engineering Advisor-MDM L3+ MAC to join our team in Noida, Uttar Pradesh (IN-UP), India (IN).
Role Overview
The Grade 10 Lead Specialist – MDM Engineer(Intune and JAMF Pro) is a senior platform engineering and delivery lead role within NTT DATA's Enterprise Endpoint Management (EPM) practice. This individual owns the design, implementation, and operational governance of Mobile Device Management (MDM) solutions across enterprise client environments, with Microsoft Intune as the primary platform and JAMF Pro as extended platform competencies.
At Grade 10 lead level, this engineer drives complex MDM deployments end-to-end — from architecture and enrolment strategy through compliance policy design, conditional access integration, and application management — across iOS, Android, Windows 10/11, and macOS device populations. The role combines deep technical platform expertise with client-facing advisory capability, lead-level governance ownership, and active mentoring of Grade 7–9 MDM engineers within the practice. This individual owns the design, implementation, and operational governance of Mobile Device Management (MDM) solutions across enterprise client environments using Microsoft Endpoint Configuration Manager (SCCM/MECM) and Microsoft Intune as the definitive dual platforms.
Key Responsibilities
Microsoft Intune – MDM Lead Engineering
- Lead Microsoft Intune architecture and design for enterprise client environments — device enrolment strategy, policy framework, RBAC model, and scope tag governance.
- Design and govern Windows enrolment pipelines — Windows Autopilot (AADJ/HAADJ), bulk enrolment, and co-management-based enrolment methods.
- Architect compliance policy frameworks and Conditional Access integration with Microsoft Entra ID — named locations, sign-in risk, device compliance signals, and app-based CA policies.
- Lead configuration profile design for Windows 10/11 — restrictions, VPN, Wi-Fi, certificate delivery, and security configuration baselines.
- Own Endpoint Security policy design in Intune — Microsoft Defender for Endpoint integration, Firewall, BitLocker, ASR rules, and security baselines aligned to CIS and Microsoft hardening standards.
- Design and govern Mobile Application Management (MAM) policies for BYOD and corporate-owned device scenarios — app protection policies, selective wipe, and conditional launch rules.
- Manage certificate infrastructure integration — SCEP/PKCS certificate profiles via NDES/Intune Certificate Connector for Wi-Fi, VPN, and email authentication.
- Lead Windows Update for Business (WUfB) update ring and Feature Update policy governance within Intune.
- Govern Intune app deployment lifecycle — Win32, LOB, Microsoft Store, and MSIX package deployment and management.
- Act as L3 escalation authority for all Priority-1/Priority-2 Intune incidents across assigned client accounts.
JAMF Pro – Apple Device Management
- Lead JAMF Pro deployment and administration for macOS and iOS/iPadOS device fleets in enterprise client environments.
- Design and manage JAMF enrolment strategies — Automated Device Enrolment (ADE/DEP), User-Initiated Enrolment (UIE), and PreStage Enrolment configuration.
- Build and maintain JAMF configuration profiles, Smart Groups, and static group targeting for policy and application scoping.
- Govern JAMF policy design — software installation, script execution, patch management, and maintenance workflows for macOS fleets.
- Manage JAMF Software Distribution — DMG/PKG deployment, patch management titles, and self-service catalogue configuration.
- Configure JAMF Connect for macOS identity federation — Azure AD/Okta integration, single sign-on, and login window management.
- Lead JAMF compliance reporting — inventory queries, smart group-based compliance views, and patch currency dashboards.
- Manage JAMF Pro server health, database maintenance, and upgrade planning for on-premises and JAMF Cloud deployments.
Microsoft SCCM / MECM – Platform Lead Engineering
- Lead SCCM/MECM architecture and administration for enterprise client environments — site hierarchy, boundary groups, DP management, and content distribution governance.
- Own Software Update Management in SCCM — SUP/WSUS architecture, ADR design, phased deployment rings, maintenance windows, and patch compliance reporting.
- Lead application deployment design and governance — MSI/MSIX/EXE deployments, detection rules, supersedence chains, phased rollouts, and software lifecycle management.
- Govern OS Deployment (OSD) and task sequence engineering — Windows 11 deployment, in-place upgrade (IPU), and golden image integration within SCCM.
- Lead SCCM co-management configuration — workload transition planning, policy authority management, and Cloud Attach/CMG enablement for internet-based device management.
- Manage SCCM client health — client installation, push deployment, health monitoring, and remediation across large device populations.
- Govern SCCM reporting infrastructure — SSRS compliance dashboards, custom WQL collection queries, and Power BI integration for operational reporting.
- Lead SCCM CB upgrade planning and execution — site server upgrades, console updates, and post-upgrade validation.
- Act as L3 escalation authority for Priority-1/Priority-2 SCCM incidents, driving root cause analysis and permanent resolution.
Co-Management – Intune & SCCM Integration
- Lead co-management architecture design — defining workload split between SCCM and Intune, phased workload transition planning, and pilot group targeting.
- Configure and govern Cloud Management Gateway (CMG) for internet-based SCCM client management and co-managed device support.
- Manage Cloud Attach enablement — Tenant Attach, Endpoint Analytics, and Microsoft Defender for Endpoint integration via SCCM.
- Define and govern co-management enrolment policies — automatic Intune enrolment for co-managed devices and compliance workload alignment.
- Lead patch workload authority decisions within co-management — determining SCCM vs Intune/WUfB patch ownership per device population.
- Drive full Intune migration planning for SCCM-managed estates — discovery, readiness assessment, phased execution, and post-migration stabilisation.
Identity, Conditional Access & Security Integration
- Lead Entra ID (Azure AD) and MDM integration — device compliance signals, Conditional Access policy enforcement, and hybrid Azure AD join configuration.
- Design and govern Conditional Access policies for BYOD and corporate-owned device scenarios — MFA enforcement, compliant device requirements, and app-based CA.
- Manage certificate authority integration — NDES, Intune Certificate Connector, SCEP proxy, and PKCS certificate delivery and lifecycle management.
- Lead Zero Trust endpoint security posture design — device health attestation, compliance-based access, and continuous access evaluation integration.
- Lead Microsoft Defender for Endpoint onboarding via Intune and SCCM for unified device security signal and vulnerability management.
Automation, Scripting & Reporting
- Develop Microsoft Graph API automation for Intune bulk operations, compliance reporting, enrolment management, and device lifecycle workflows.
- Build PowerShell automation for SCCM administration — ADR management, collection queries, client health remediation, and patch compliance operations.
- Design and maintain endpoint compliance dashboards in Power BI integrating Intune and SCCM data — device posture, patch currency, and deployment health.
- Automate device enrolment registration, Autopilot profile assignment, and compliance remediation workflows using Microsoft Graph API.
Mentoring, Documentation & Governance
- Lead, mentor, and provide L3 technical guidance to Grade 7–9 engineers across Intune and SCCM workstreams.
- Conduct peer reviews of enrolment configurations, compliance policies, SCCM deployments, and platform design documents produced by junior engineers.
- Author and maintain comprehensive MDM and SCCM SOPs, platform runbooks, enrolment guides, and troubleshooting playbooks.
- Represent MDM and SCCM changes in client CAB processes — RFC preparation, risk assessment, and post-implementation review.
- Lead platform knowledge-sharing sessions, Show & Tell presentations, and EPM practice CoP contributions.
- Support audit and compliance activities — provide evidence for device enrolment records, policy configurations, and compliance state reporting.
Required Skills
Microsoft Intune
- Device enrolment — Windows Autopilot (AADJ/HAADJ), bulk enrolment, co-management enrolment (advanced level)
- Compliance policies and Conditional Access — Entra ID device compliance signal integration
- Configuration profiles — Windows 10/11 restrictions, VPN, Wi-Fi, certificates, email
- Endpoint Security policies — Defender for Endpoint, Firewall, BitLocker, ASR, Security Baselines
- MAM / App Protection Policies — BYOD and corporate device scenarios
- App deployment — Win32, LOB, MSIX, Microsoft Store lifecycle management
- Certificate delivery — SCEP/PKCS via NDES/Intune Certificate Connector
- Windows Update for Business (WUfB) — update rings, Feature Update policies
- Microsoft Graph API for Intune automation and bulk device management
JAMF Pro
- JAMF Pro — ADE/DEP, PreStage Enrolment, Smart Groups, configuration profiles, policies (advanced level)
- JAMF Software Distribution — DMG/PKG deployment, patch management, self-service
- JAMF Connect — macOS identity federation, Azure AD/Okta integration
- JAMF Pro API (Classic and Universal API) for automation and reporting
Microsoft SCCM / MECM
- SCCM Current Branch — site administration, hierarchy, CB upgrade management (advanced level)
- Software Update Management — SUP, WSUS, ADR, maintenance windows, phased deployment rings
- Application deployment — MSI/MSIX/EXE, detection rules, supersedence, phased rollouts
- OS Deployment — task sequences, Windows 11 OSD, in-place upgrade (IPU)
- Co-management — workload transition, Cloud Attach, CMG, Tenant Attach, Endpoint Analytics
- SCCM client health — monitoring, push deployment, remediation at scale
- Reporting — SSRS, WQL collection queries, Power BI integration
Co-Management & Migration
- SCCM/Intune co-management architecture — workload split, pilot targeting, phased transition
- Cloud Management Gateway (CMG) — design, deployment, and internet-based client management
- SCCM to Intune full migration planning and execution
Identity & Security
- Microsoft Entra ID (Azure AD) — device compliance, Conditional Access, hybrid join, RBAC
- Zero Trust endpoint security design — device health attestation, compliance-gated access
- Microsoft Defender for Endpoint — Intune and SCCM onboarding, security baseline management
- Certificate authority integration — NDES, SCEP proxy, PKCS, certificate lifecycle management
Scripting & Automation
- PowerShell — advanced scripting for SCCM administration, Intune automation, and compliance operations
- Microsoft Graph API — Intune device management, compliance reporting, bulk operations
- Power BI — endpoint compliance and patch management dashboard development
Preferred Qualifications
- Microsoft Certified: Endpoint Administrator Associate (MD-102) — held or in progress
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- ITIL v4 Foundation
- Experience managing Windows endpoint estates of 10,000+ devices via SCCM and Intune
- Familiarity with Windows 365 Cloud PC and Microsoft Intune Suite capabilities
- Exposure to Windows Autopatch assessment and onboarding
- Experience with Microsoft Defender Vulnerability Management integration with SCCM/Intune
- Prior experience in managed services, IT outsourcing, or SI delivery environments
Experience Profile
- 10–14 years of progressive experience in enterprise endpoint management.
- Minimum 5 years of hands-on Microsoft Intune design and delivery experience across Windows device estates.
- Minimum 5 years of SCCM/MECM Current Branch administration and platform engineering experience.
- Demonstrated experience architecting and delivering SCCM/Intune co-management solutions in enterprise environments.
- Track record of delivering SCCM-to-Intune migration or co-management transition programmes.
- Experience in managed services, IT outsourcing, or multi-client delivery models preferred.
Minimum Education
- B.E. / B.Tech in Computer Science, Information Technology, or a related engineering discipline.
MCA or equivalent postgraduate qualification considered with commensurate experience.
About NTT DATA
NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.
Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.
NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.
Job Segment:
Cloud, Developer, Computer Science, Consulting, Database, Technology