Senior Desktop Engineer
The Senior Desktop Engineer will be heavily client focused leading Level 3 support, administration, and engineering of desktop systems and end-user applications. This role plays a key part in designing, optimizing, and maintaining the desktop ecosystem, ensuring a seamless and efficient user experience.
The ideal candidate is comfortable working directly with end users, troubleshooting complex issues, and collaborating cross-functionally with desktop engineering and support teams. Success in this role requires both hands-on technical expertise and the ability to contribute to strategic improvements in desktop infrastructure and application delivery.
Essential Duties and Responsibilities
- Deployment, tracking, and compliance reporting for all OS, software, and third-party patches.
- Identify bugs and deficiencies in client management tools or processes, come up with remediation plan(s), and successfully implement those plans.
- Application deployment and troubleshooting using MECM; MECM agent and patching troubleshooting.
- Experience with creating SSRS reports for MECM (some knowledge of MS SQL and PowerBI).
- Resolve issues with patching and software deployment through remote management tools.
- Third level Windows desktop/laptop support and administration.
- Microsoft 365 Apps administration โ deployment (C2R/ODT), update channel management, Microsoft 365 tenant configuration, and user/license administration via M365 Admin Center and PowerShell.
- Application Packaging - MSI & MSIX/MSIXbundle format using Flexera AdminStudio Tool preferred with experience converting to.intunewin (Win32 App).
- Working with and troubleshooting desktop builds (MECM OSD).
- Experience with Modern Driver Management.
- Participate in standard image development, management, QA testing, and deployment.
- Familiar with MECM hybrid-joined devices & co-management (Configuration, Compliance, Conditional Access, Scripts & Remediations) and Microsoft Intune (MEM/MDM) โ device configuration profiles, compliance policies, Conditional Access, application deployment, and Proactive Remediations; experience with Entra ID-joined, hybrid-joined, and co-managed devices.
- Strong skills in Active Directory, DNS, DHCP, GPO, and Microsoft Entra ID (Azure AD); experience with hybrid identity, Conditional Access policies, and MFA/SSPR administration.
- Strong troubleshooting skills with multi-tier application and systems.
- Strong knowledge of PowerShell scripting including automation against Microsoft Graph API and Entra ID; familiarity with scripted Intune remediation and Azure automation runbooks.
- Exposure to Windows server support including virtual machines.
- Experience with Azure Virtual Desktop (AVD) โ host pool provisioning, session host image management, FSLogix profile containers, and application delivery; familiarity with AVD scaling plans and monitoring via Azure Monitor.
- Exposure supporting highly mobile users and systems (iOS & iPadOS, Microsoft Intune).
Qualifications/Position Requirements
- Knowledge of Ivanti AppSense tools, Microsoft Entra ID administration (user/group lifecycle, RBAC, PIM), BitLocker with Intune key escrow, and Windows Autopilot deployment including Autopilot Reset and pre-provisioning.
- Exposure to supporting enterprise document management systems (e.g., iManage Work); experience with M365 integrations including SharePoint Online, OneDrive, and Teams administration is a plus.
- Experience with RECAST Application Workspace is a plus but not required.
- Very strong technical skills, attention to detail, and excellent oral and written communication skills. Strong ability to create and maintain detailed system documentation. In addition, must be a creative thinker with proven problem-solving ability. Strong interpersonal skills, including demonstrated ability to work in a highly collaborative flat organization.
- Platforms: Strong proficiency in Windows 365, Microsoft Intune, Azure Active Directory (Entra ID), and M365 apps.
- Automation: Demonstrated ability to use PowerShell and Microsoft Graph API for automation.
- Technical Skills: Deep understanding of OS deployment, GPO migration to Intune, and troubleshooting Virtual Desktop Infrastructure (VDI).
Education and/or Experience
- 7+ years in a related field.
- Experience in a professional services organization a plus.
- Bachelor's degree preferred.
Compensation
The expected base salary for this position is $170,000.00 - $180,000.00. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, anticipated assignment, and, where applicable, licensure or certifications obtained. Market and organizational factors are also considered. Davis Polk offers a competitive salary and comprehensive benefits package.