Information Technology Security Manager

Dariel

Endpoint Security Management

  • Design, implement and manage Microsoft Intune security configurations across Windows, macOS, iOS and Android devices.
  • Compliance Policies
  • Configuration Profiles
  • Endpoint Security Policies
  • Security Baselines
  • Device Restrictions
  • App Protection Policies (MAM)
  • Ensure endpoint security controls remain aligned to Microsoft security best practices, CIS benchmarks and organisational standards.
  • Continuously review and optimise endpoint security configurations to reduce risk and improve user experience.

Intune & Device Management

  • Administer Microsoft Intune as the primary endpoint management platform.
  • Drive adoption of modern endpoint management capabilities and cloud-native device management practices.
  • Support co-management strategies between Intune and SCCM/MECM.
  • Lead workload transitions from on-premise management solutions to Intune where appropriate.
  • Maintain device lifecycle security standards across enrolment, compliance, monitoring and decommissioning processes.

SCCM/MECM Administration

  • Patch deployment
  • Software distribution
  • Endpoint configuration management
  • Compliance reporting
  • Ensure timely deployment of security updates and critical patches.
  • Support patch governance and vulnerability remediation initiatives.
  • Collaborate with infrastructure and EUC teams to improve endpoint management maturity.

BYOD Security Governance

  • Design and implement BYOD security frameworks that balance corporate security requirements with user convenience.
  • App Protection Policies (MAM)
  • MAM without MDM
  • Device enrolment controls
  • Conditional Access device requirements
  • Corporate application access controls
  • Ensure corporate data remains protected on personal devices through appropriate security controls and data separation mechanisms.
  • Review BYOD adoption and security posture regularly and recommend improvements where necessary.

Endpoint Protection & Hardening

  • Endpoint Detection and Response (EDR)
  • Antivirus
  • Attack Surface Reduction (ASR)
  • Threat and Vulnerability Management
  • Automated Investigation and Remediation
  • BitLocker
  • Windows Security Baselines
  • Firewall Policies
  • Device Control Policies
  • CIS Benchmarks
  • Monitor emerging endpoint risks and recommend mitigation strategies.

Compliance Monitoring & Risk Reduction

  • Monitor device health, compliance status and security posture across the endpoint estate.
  • Investigate and remediate non-compliant devices in collaboration with EUC and Service Desk teams.
  • Support vulnerability management and patch compliance initiatives.
  • Develop reporting and dashboards to track endpoint security performance and trends.

Incident Response & Security Operations

  • Provide technical support during endpoint security incidents.
  • Device isolation
  • Investigation support
  • Forensic artefact collection
  • Malware remediation
  • Work closely with Security Operations Centre (SOC) teams during investigations and recovery activities.
  • Assist in identifying root causes and implementing preventative measures.

Zero Trust Enablement

  • Support the organisation's Zero Trust security strategy by integrating endpoint compliance with identity and access controls.
  • Collaborate with IAM and security engineering teams to align Conditional Access policies with device trust signals.
  • Ensure device compliance data is effectively leveraged to strengthen access control decisions.
  • Contribute to broader cloud and modern workplace security initiatives.

Decision-Making Authority

The successful candidate will:

  • Implement and manage endpoint security configurations within delegated authority.
  • Recommend security baselines, compliance controls and BYOD security requirements.
  • Escalate high-risk devices, unresolved security issues and persistent non-compliance concerns to cyber leadership.
  • Influence endpoint security standards and best practices across the organisation.

Essential Skills & Experience

Technical Experience

  • Minimum 5-8 years' experience in endpoint security, endpoint management or modern workplace security engineering.
  • Strong hands-on experience administering Microsoft Intune in enterprise environments.
  • Experience managing SCCM/MECM and co-managed endpoint environments.
  • Extensive experience implementing Microsoft Defender for Endpoint security controls.
  • Proven experience managing BYOD and mobile device security frameworks.
  • Experience with Windows, macOS, iOS and Android device management and security.
  • Strong understanding of endpoint hardening, patch management and vulnerability remediation.

Security & Governance Knowledge

  • Zero Trust security principles
  • CIS Benchmarks
  • Microsoft Security Baselines
  • Device compliance frameworks
  • Endpoint risk management
  • Data protection controls
  • Understanding of Conditional Access, identity-driven security and device trust concepts.
  • Experience supporting audits, compliance reviews and security assessments.

Professional Skills

  • Strong troubleshooting and problem-solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to work effectively with EUC, Service Desk and Security Operations teams.
  • Strong attention to detail and commitment to security best practice.
  • Ability to prioritise work effectively within a fast-paced environment.

Preferred Qualifications

  • Microsoft Certified: Endpoint Administrator Associate (MD-102)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • CompTIA Security+
  • CISSP, CISM or equivalent security certification advantageous

Core Technologies

Endpoint Management

  • Microsoft Intune
  • Endpoint Security Policies
  • Compliance Policies
  • Configuration Profiles
  • App Protection Policies (MAM)

Endpoint Protection

  • Microsoft Defender for Endpoint
  • Endpoint Detection and Response (EDR)
  • Antivirus
  • Attack Surface Reduction (ASR)
  • Threat & Vulnerability Management

Legacy & Co-Management Platforms

  • SCCM / MECM
  • Software Deployment
  • Patch Management
  • Co-Management

Device Hardening & Compliance

  • BitLocker
  • Windows Security Baselines
  • CIS Benchmarks
  • Device Compliance Policies
  • Firewall Management

BYOD Security

  • Mobile Application Management (MAM)
  • MAM without MDM
  • BYOD Conditional Access
  • Corporate Data Protection Controls

Identity Integration

  • Microsoft Entra ID
  • Device Registration
  • Hybrid Azure AD Join
  • Conditional Access Integration

Why Join Us?

This is an exciting opportunity to play a key role in securing a modern workplace environment through best-in-class endpoint and BYOD security practices. You will work with leading Microsoft technologies, contribute to critical Zero Trust initiatives, and help shape the future of endpoint security across the organisation.