Microsoft Endpoint Configuration Manager

9 hours ago

makati, metro manila, Philippines Optum, a UnitedHealth Group Company Full-time ₱1 Contract

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.

As an I O Engineering Consultant, you will deliver reliable and secure device management services in a Dual UEM environment using Microsoft Endpoint Configuration Manager (MECM/SCCM), Microsoft Intune, and Omnissa Workspace ONE UEM. You will own day-to-day endpoint engineering and operational outcomes across application lifecycle (packaging to deployment), OS servicing, patch compliance, vulnerability remediation, and endpoint configuration. The role is execution-focused with solid troubleshooting depth and disciplined ITSM practices. You will routinely participate in major incident bridges/war rooms, ensuring service restoration within agreed SLAs and contributing to measurable MTTR reduction. You will also contribute to AI adoption by proposing and piloting practical ideations (e.g., ticket triage assist, automated log parsing, runbook generation) to improve reliability, speed, and user experience, while adhering to organizational security, privacy, and data handling standards.

Primary Responsibilities:

  • Platform Operations, Health & Availability
  • Administer MECM components (collections, boundaries, deployments, content distribution, client health monitoring, reporting)
  • Administer Intune (enrollment, configuration profiles, compliance policies, app assignments, RBAC) and support coexistence with MECM
  • Administer Workspace ONE UEM (profiles, Smart Groups, compliance, app deployments) and support coexistence with Intune (Dual UEM)
  • Monitor platform health and availability: enrollment success, policy/app success rates, client health, content distribution health, and remediation backlogs
  • Maintain device inventory accuracy and operational hygiene; perform routine health checks and standard validations
  • Application Lifecycle, OS Servicing & Operations
  • Package and deploy applications (MSI/EXE/MSIX/Win32) with detection methods, dependencies, supersedence, and phased ring deployments
  • Support OS deployment and servicing (Task Sequences, feature updates, in-place upgrades), driver/BIOS packaging coordination, and rollback plans
  • Execute post-deployment validation and remediation for failed installs, policy conflicts, and provisioning issues
  • Patching, Vulnerability Remediation & Compliance
  • Operate software update/patching via MECM (ADRs, maintenance windows, deployment schedules, compliance reporting) and coordinate exception handling
  • Support vulnerability remediation initiatives by deploying security patches and approved mitigations within defined timelines
  • Track compliance posture and drive remediation for non-compliant endpoints; support dashboards and reporting
  • Troubleshooting, ITSM & War Rooms
  • Troubleshoot endpoint deployment and client issues using logs and diagnostics (e.g., AppEnforce/AppDiscovery, WUAHandler, CAS, CCMExec)
  • Work within ITSM processes (Incident/Problem/Change) including change documentation, risk assessment, and post-change validation
  • Participate in major incident war rooms/bridges; provide technical inputs, implement mitigations, and document restoration actions
  • Track and drive SLA adherence; contribute to MTTR reduction via faster triage, known error documentation, and repeat-incident prevention
  • Automation & AI Adoption / Ideation
  • Create and maintain PowerShell-based operational automations (health checks, compliance reporting, remediation scripts)
  • Propose AI-assisted improvements (e.g., Copilot-assisted draft runbooks, KB articles, ticket summarization, and log pattern identification)
  • Pilot small-scale AI/automation ideations with measurable success criteria (time saved, reduced rework, improved compliance)
  • Ensure AI usage adheres to organizational security, privacy, and data handling policies (no sensitive data leakage)
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary