
Modern Workplace Engineer (Interim)
- Hybrid
Job description
About the role
Optics11 is looking for a hands-on modern workplace engineer for a 3-month assignment. The goal is to finish our Microsoft Intune implementation, move existing devices over to Intune management and bring the device management functions of our current RMM tool into Intune. Optics11 is a precision fibre optic sensing company in the Netherlands, and we work with a mixed Windows, macOS and Linux environment. You will extend and complete Intune management across all three platforms.
You will work alongside the IT team and report to the IT & Security Manager. The role focuses on endpoints; network and server infrastructure are out of scope.
Responsibilities
In short: every device managed by Intune, secured to CIS baselines and documented, so day-to-day device management no longer depends on the RMM.
Finish the Intune setup on all three platforms.
Windows: complete and harden the setup, including configuration and compliance policies, Autopilot profiles and the Enrollment Status Page, update rings and app packaging (Win32/MSIX).
macOS: enrollment through Apple Business Manager, configuration and compliance profiles, FileVault and app deployment.
Linux: enrollment and compliance policies for supported distributions, with scripted configuration where Intune falls short.
2. Implement CIS baselines. Translate the CIS Benchmarks for Windows, macOS and Linux into Intune configuration policies and scripts. Pilot first, handle exceptions and record every deviation with its rationale.
3. Migrate current installs to Intune management. Inventory existing devices, choose a migration path per platform (re-enrollment, Autopilot registration or rebuild), run pilots and migrate in waves with minimal disruption for users.
4. Move RMM device management to Intune. List everything the RMM does today and rebuild its management functions in Intune: software deployment, scripts, patching, configuration and remote support, or an agreed alternative where Intune falls short. Document clearly which functions remain in the RMM and why.
5. Deliver a full documentation set. Device baselines per platform, CIS implementation and exceptions register, enrollment and migration runbooks, app packaging guide, script repository with usage notes, and device procedures for joiners, movers and leavers.
6. Transfer knowledge. Hand over so the internal team can run and change the setup independently.
Job requirements
Must have
A VOG (Verklaring Omtrent het Gedrag) with the military/defence screening profile.
Strong hands-on knowledge of Windows, macOS and Linux endpoints. You are comfortable supporting and configuring all three.
Production experience with Microsoft Intune: configuration profiles, settings catalog, compliance policies and app deployment.
Proven experience implementing CIS Benchmarks or other security baselines through configuration policies, including pilots and exception handling.
Windows Autopilot and the Enrollment Status Page in production.
macOS management in Intune with Apple Business Manager (enrollment, configuration profiles, FileVault).
Experience migrating devices from an existing management setup (RMM, on-premises or co-management) to Intune.
Proficient in PowerShell and Bash: writing, testing and maintaining deployment, remediation and configuration scripts.
Good working knowledge of Entra ID: groups, dynamic membership, licensing and how Conditional Access uses device compliance.
You write clear documentation and runbooks that others can follow.
Nice to have
Experience working in tightly restricted or controlled environments, such as defence, government or other high-security settings.
Linux enrollment in Intune and configuration management tooling (for example Ansible).
Microsoft Defender for Endpoint onboarding through Intune.
Experience with a Microsoft 365 tenant-to-tenant migration.
Dutch language.
Certifications
Preferred: MD-102, Microsoft 365 Certified: Endpoint Administrator Associate. This is the closest match to the role and covers Intune, Autopilot, Defender for Endpoint and automation with PowerShell and Microsoft Graph.
A plus: MS-102 (Microsoft 365 Administrator Expert), SC-300 (Identity and Access Administrator) or SC-200 (Security Operations Analyst).
A plus for macOS and Linux: Apple deployment and management or Jamf certification, LFCS or RHCSA.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
Thank you for your interest - we've already received your application, so this new submission can't be accepted. Your previous application is on file.
If you need assistance or believe this is an error, please email us at apply@optics11.recruitee-mailbox.com
