Level 2 Support Engineer
Key Responsibilities
Endpoint Management
· Manage and support Windows endpoints using SCCM, Microsoft Intune, and Microsoft Entra ID (Azure AD).
· Administer and maintain endpoint lifecycle management, including provisioning, configuration, deployment,compliance, and retirement.
· Monitor endpoint health,performance, and compliance across the enterprise.
· Support endpoint modernization and workplace technology initiatives.
Mobile Device Management
· Administer iPads and mobile devices through Microsoft Intune.
· Manage the complete mobile device lifecycle, including enrolment, configuration, compliance, application deployment, and decommissioning.
· Troubleshoot mobile device management (MDM) issues and enforce organizational security policies.
Microsoft Intune Administration
· Manage Intune device enrolment,compliance policies, configuration profiles, application deployments, and security baselines.
· Support co-management environments integrating SCCM and Intune.
· Implement and manage Conditional Access and device compliance requirements.
· Troubleshoot Intune- related deployment and policy issues.
SCCM Administration
· Administer and maintain Microsoft Endpoint Configuration Manager (SCCM/MECM).
· Manage collections, deployments,software distribution points, task sequences, and client health.
· Develop and maintain deployment strategies for applications, operating systems, and updates.
· Monitor deployment effectiveness and remediate failures.
Software Deployment &Application Lifecycle Management
· Deploy applications, updates, and scripts through SCCM and Intune.
· Package, test, and deploy enterprise applications.
· Manage application lifecycle activities, including onboarding, upgrades, updates, and retirement.
· Perform customized Microsoft Office installations using Office Deployment Tool (ODT).
· Ensure successful deployment of business-critical applications with minimal disruption.
Patch Management & SoftwareUpdates
· Monitor patch compliance across the enterprise.
· Deploy Windows updates, security patches, feature updates, and third-party application updates.
· Utilize Patch My PC to automate third-party application patching and deployment.
· Investigate and remediate devices failing compliance or update requirements.
· Produce patch compliance and deployment success reports.
Group Policy Administration
· Design, implement, and maintain Group Policy Objects (GPOs).
· Manage endpoint security configurations and administrative policies.
· Troubleshoot Group Policy processing and inheritance issues.
· Implement and maintain corporate desktop standards.
Vulnerability & Security Management
· Conduct vulnerability scanning using Tenable.
· Analyze vulnerability findings and identify remediation requirements.
· Coordinate and implement endpoint vulnerability remediation activities.
· Collaborate with Security Operations, Infrastructure, and Engineering teams to reduce security risks.
· Support compliance, audit, and security initiatives.
Automation & Scripting
· Develop and maintain advanced PowerShell and Batch scripts for automation, remediation, reporting, and operational efficiency.
· Automate repetitive endpoint management and administration tasks.
· Enhance service delivery through process optimization and workflow automation.
Technical Escalation &Incident Management
· Act as the primary technical escalation point for the IT Service Desk.
· Provide advanced Level 2 and Level 3 support for endpoint, mobility, and application-related incidents.
· Troubleshoot complex endpoint and mobility issues escalated from L1 support.
· Perform root cause analysis and implement long-term corrective solutions.
· Coordinate problem resolution with vendors and internal technical teams.
Stakeholder Management &Cross-Team Collaboration
· Serve as the primary liaison between IT Service Desk and End User Development Technology teams.
· Facilitate communication and coordination between support, engineering, infrastructure, and security teams.
· Participate in change management,problem management, and service improvement initiatives.
· Provide technical guidance and mentorship to junior engineers.
Monitoring, Reporting &Documentation
· Generate reports on device health, compliance, patch status, and vulnerability remediation progress.
· Monitor endpoint management KPIs and service performance metrics.
· Maintain technical documentation,operating procedures, standards, policies, and knowledge base articles.
· Ensure documentation remains current and audit-ready.
Core Technologies
- Microsoft SCCM / MECM
- Microsoft Intune
- Microsoft Entra ID (Azure AD)
- Patch My PC
- Windows 10 & Windows 11
- iPadOS Management
- Microsoft Office Deployment Tool (ODT)
- Active Directory
- Group Policy (GPO)
- PowerShell
- Batch Scripting
- Tenable Vulnerability Management
- Endpoint Security & Compliance
- Software Packaging & Deployment
Key Competencies
- Endpoint Management
- Mobile Device Management (MDM)
- Technical Escalation Management
- Vulnerability Management
- Patch Management
- Application Lifecycle Management
- PowerShell Automation
- Incident & Problem Management
- Cross-Functional Collaboration
- Stakeholder Management
- Technical Leadership & Mentoring
- Documentation & Knowledge Management
Level 2 / Team Lead
In addition to the services specified in Section 1.1, the Engineer shall act as the technical and operational lead for the Level 1 MSS team, including:
· Day-to-day operational oversight
· Technical guidance and escalation support
· Performance and quality monitoring
· Knowledge transfer and skills development
· Coordination with Level 2, Level 3, and customer stakeholders, and
· Ensuring compliance with service level agreements (SLAs)and operational KPIs.