Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Lead macOS Intune MDM/MAM Engineer

Evolution Cloud Services (EVOCS)
CompanyEvolution Cloud Services (EVOCS)
CategoryEngineering
LocationDenver
RemoteOn-site (inferred)
EmploymentNot stated
LevelLead
SalaryNot stated by the employer
Posted1 Jul 2026
Last verified4 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
EVOCS OVERVIEW EVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with idealtechnologies to provide them with comprehensive solutions to grow and prosper. Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success. If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let’s talk! 🎯 Role Overview We’re looking for an experienced Lead macOS Intune Engineer to own Apple device management across our enterprise. You’ll architect and drive the full lifecycle of macOS endpoints, from zero-touch provisioning through Apple Business Manager all the way to advanced security hardening with FileVault, Secure Enclave, and passwordless authentication. This is a high-impact individual contributor role sitting at the intersection of endpoint engineering, identity & access management, and security. You’ll collaborate closely with our Identity, Security, and IT Support teams to ensure every Mac, corporate or BYOD, meets our security posture and delivers a seamless user experience. 🧩 What you will do In this role, you will: macOS Endpoint Management Architect, deploy, and manage the lifecycle of macOS devices using Microsoft Intune MDM Design and tune configuration profiles, compliance policies, and security rules that keep Mac devices secure, performant, and user-friendly Apple Business Manager & Zero-Touch Provisioning Own the integration between Microsoft Intune and Apple Business Manager (ABM) Configure Automated Device Enrollment (ADE) for zero-touch Mac provisioning — corporate devices enroll and configure themselves out of the box Mobile Application Management (MAM) Manage app deployment and updates (App Store, VPP, and enterprise apps) through Intune Enforce app protection policies to secure corporate data on both managed and BYOD macOS devices Passwordless Authentication & Single Sign-On Implement Microsoft Entra ID Platform SSO on macOS using the Enterprise SSO plug-in Enable Secure Enclave-based authentication (hardware-backed keys, Touch ID) to deliver a Windows Hello–equivalent experience on Mac Ensure cloud accounts are properly linked to local Mac accounts, eliminating repeated password prompts Device Security & Encryption Manage FileVault full-disk encryption via Intune, including key escrow and recovery workflows Leverage Apple’s T2 / Apple Silicon security features and deploy Microsoft Defender for Endpoint on macOS Configure endpoint protection and compliance policies (password, screen lock, threat response) BYOD Strategy Design policies that apply MAM app protection and Conditional Access to personal Macs without intruding on personal data Define clear enrollment and access rules for non-corporate devices accessing company resources Identity & Security Best Practices Monitor and mitigate identity-related risks on Mac endpoints — password spray attacks, brute-force attempts, and unauthorized access Champion Zero Trust principles: least privilege, device compliance-gated access, and continuous verification Troubleshooting & Support Lead root-cause analysis for complex Intune enrollment, SSO, SecureToken/FileVault, and authentication failures Resolve misconfigurations quickly and provide durable fixes that prevent recurrence Documentation, Training & Continuous Improvement Develop and maintain runbooks, configuration guides, and incident response playbooks for macOS management Train and mentor IT support staff on Mac device support, Intune policy management, and security best practices Stay current with new Microsoft Endpoint Man