Job Title: Senior Microsoft Intune Engineer
Location: Kuala Lumpur, Malaysia
Work Mode: Onsite
Employment Type: Contract
Experience Level: 7–10 years
Work Eligibility: Applicants must have the legal right to work in Malaysia. Visa sponsorship is not available for this position.
About the Role
We are seeking a Senior Microsoft Intune Engineer to lead and support the endpoint management workstream for a major Microsoft 365 migration project. You will play a key role in designing, planning, and executing the migration of Windows 11 devices from Workspace ONE to Microsoft Intune, collaborating closely with cross-functional teams to deliver a secure and scalable endpoint management solution.
Key Responsibilities
Assess existing Workspace ONE, Microsoft Configuration Manager, Microsoft Intune, and Windows endpoint management environments.Review device inventory, operating system versions, management status, user groupings, application requirements, and policy configurations.Identify migration prerequisites, technical constraints, dependencies, security gaps, and operational readiness requirements.Support and facilitate workshops to confirm device scope, migration priorities, sequencing, and design decisions.Develop and maintain risk, issue, dependency, and remediation inputs for the Intune workstream.Develop high-level and detailed designs for the target endpoint management solution, including device enrolment, provisioning, configuration, compliance, application deployment, and update management.Define Intune role-based access control, scope tags, assignment groups, and dynamic membership rules.Design endpoint security settings, encryption standards, security baselines, and policy alignment.Collaborate with identity and security teams on Conditional Access, Microsoft Entra ID, Microsoft Defender for Endpoint, and related controls.Configure or provide guidance for Intune tenant settings, enrolment profiles, configuration profiles, compliance policies, update rings, and endpoint security policies.Support the preparation, validation, and attestation of scripts used for migration or configuration activities.Develop migration approaches, pilot plans, migration waves, and deployment schedules for Workspace ONE to Intune migration.Support device unenrolment from Workspace ONE and enrolment into Microsoft Intune, including application deployment and configuration assignment.Validate enrolment status, policy application, application availability, and device compliance post-migration.Track migration progress, exceptions, defects, and remediation actions across deployment waves.Produce design documents, implementation guidance, configuration standards, operational guides, and migration runbooks.Conduct knowledge transfer sessions for administrators, engineering teams, and support teams.Ensure documentation reflects approved design decisions, implemented configurations, known issues, and operational ownership.Must-have Requirements
Bachelor's degree in any related discipline.Microsoft Certified: Endpoint Administrator Associate (MD-102) or an equivalent current Microsoft endpoint management certification.Microsoft identity, security, or Microsoft 365 certifications.Applicants must have the legal right to work in Malaysia. Visa sponsorship is not available.Strong hands-on experience with Microsoft Intune and enterprise endpoint management.Experience designing and delivering Windows 11 device management solutions.Experience with Workspace ONE to Intune migration or comparable endpoint management platform migrations.Experience with RBAC, scope tags, dynamic groups, security baselines, Group Policy assessment, and policy migration.Experience producing architecture documents, technical designs, migration plans, runbooks, configuration guides, and operational documentation.Experience with Microsoft Defender for Endpoint, Windows Hello for Business, PKI, NDES, SCEP, certificate-based authentication, VPN, and Wi-Fi profile deployment.Nice-to-have Requirements
Experience with automation of Intune configuration or migration activities using PowerShell or other scripting tools.Experience with Azure Active Directory Premium features (e.g., Privileged Identity Management, Identity Protection).Familiarity with device management in macOS or mobile platforms (iOS/Android) using Intune.Experience supporting large, geographically distributed enterprise environments.Strong knowledge of Microsoft Entra ID, Conditional Access, device compliance, configuration profiles, application protection policies, Windows update rings, endpoint security, and encryption controls.Ability to facilitate technical workshops and work across infrastructure, identity, security, application, service management, and project teams.Experience supporting endpoint transformation within financial services or another regulated industry.Strong troubleshooting, analytical, documentation, and stakeholder communication skills.Experience with Microsoft Configuration Manager and Intune co-management.Why Join Us
Join a dynamic team driving a high-impact Microsoft 365 migration project for a leading organization. You will have the opportunity to work with the latest endpoint management technologies, collaborate with talented professionals, and contribute to the transformation of enterprise IT operations. This is an excellent opportunity to further your expertise in Microsoft Intune and enterprise device management in a challenging and rewarding environment.