Senior Client Endpoint & Identity Engineer – Technology Operations (Full time)
Salary: £53,408 – £62,309 (dependent on experience)
Working pattern: Hybrid working
Location: OSHQ Southampton
About the Team
Our growing Technology and Design team plays a key role in ensuring OS is at the cutting edge of geospatial capability. We work across the business to provide customer‑centric design and technology services.
About the Role
We’re seeking a proactive Senior Client Endpoint & Identity Engineer to join our high‑performing Client Endpoint and Identity Service. In this senior role, you’ll be the technical lead in designing, implementing, and supporting enterprise‑level endpoint and identity solutions. You will shape strategic improvements, deliver roadmap initiatives, and ensure secure, scalable, and user‑focused access to corporate resources. As a senior team member, you’ll provide mentorship, coaching, and guidance, champion best practices, and promote effective collaboration.
Responsibilities
- Design, implement, and maintain enterprise‑level endpoint security, identity governance, and device management solutions.
- Automate processes using PowerShell and develop scripts for configuration management.
- Define and enforce device configuration and security standards across platforms.
- Manage patching, compliance, software distribution, and cross‑platform device support.
- Select and implement effective technical solutions, troubleshooting issues.
- Engage stakeholders and provide excellent customer service.
- Act as an escalation point for complex issues and support system performance monitoring.
- Collaborate with security, infrastructure, and service desk teams to deliver integrated solutions.
- Create automation, maintain documentation, and contribute to team development.
- Participate in project planning, risk assessment, and continuous improvement initiatives.
- Lead engagements with key stakeholders, working with Service Management and external suppliers.
- Understand application packaging and deployment.
- Communicate technical concepts to both technical and non‑technical audiences.
Essential Qualifications
- Experience in endpoint security, compliance, identity governance, and modern device management.
- Expertise in designing, implementing, and maintaining IT platforms.
- Proficiency in PowerShell for automation, scripting, and configuration management.
- Ability to define and enforce device configuration and security standards.
- Skilled in managing patching, compliance, software distribution, and cross‑platform device support.
- Strong problem‑solving skills and experience selecting effective technical solutions.
- Excellent stakeholder engagement and customer service skills.
- Acts as an escalation point for complex issues and supports system performance monitoring.
- Collaborates with security, infrastructure, and service desk teams to deliver integrated solutions.
- Creates automation, maintains documentation, and contributes to team development.
- Participates in project planning, risk assessment, and continuous improvement through technology evaluation.
- Experience leading engagements with key stakeholders, working with Service Management and External Suppliers.
- Understanding of application packaging and deployment.
- Experience leading projects, technical implementations and continuous improvements.
- Excellent communication skills, with the ability to translate technical concepts for both technical and non‑technical audiences.
Desirable Qualifications
- Advanced knowledge of Microsoft Endpoint Manager (Intune), including device configuration, compliance, application deployment, Windows Autopatch, and Autopilot.
- Strong experience with Azure Active Directory / Entra ID, conditional access, identity protection, and modern authentication methods (MFA, password‑less, certificate‑based authentication).
- Extensive expertise in Windows client OS, including lifecycle management, performance optimisation, security configuration, and troubleshooting.
- Hands‑on experience with Microsoft Defender for Endpoint and wider Defender suite integrations.
- Experience with identity lifecycle management, including provisioning, deprovisioning, and role‑based access models.
Benefits
- Competitive salary and pension (OS contributes up to 12.07%).
- Performance‑related bonus (where applicable).
- 28 days annual leave plus bank holidays (increasing with service).
- Enhanced family leave, including paid partner leave.
- Hybrid and flexible working options.
- Learning and development support, coaching and mentoring.
- Free subscription to OS Maps and access to wellbeing support.
- Volunteering leave and matched fundraising.
Location & Working Pattern
Hybrid working. You will be based at our HQ in Southampton, Hampshire, spending approximately 50 % of your week collaborating face‑to‑face with colleagues.
Security & Eligibility
OS conducts pre‑employment checks for all offers, including identity, right to work, employment history, and criminal record checks. Some roles may require additional security vetting, which will be discussed during the recruitment process. This role requires the right to work in the UK; OS cannot provide visa sponsorship.
Inclusion
We are committed to building a diverse, inclusive, and welcoming workplace. We encourage applicants whose experience may not match every qualification to apply, as we consider reasonable adjustments throughout the recruitment process.
Closing date: Sunday 14 June 2026
#J-18808-Ljbffr…
