Endpoint Security Management

  • CONTRACTOR
  • West Rand View on Map
  • posted 14 hours ago
  • Posted : July 30, 2026 -Accepting applications

Job Detail

  • Experience  no-experience

Job Description

Vacancy Details

Employer: Araxi Group

Endpoint Security Management

  • Design, implement and manage Microsoft Intune security configurations across Windows, macOS, iOS and Android devices.
  • Develop and maintain:
  • Compliance Policies
  • Configuration Profiles
  • Endpoint Security Policies
  • Security Baselines
  • Device Restrictions
  • App Protection Policies (MAM)
  • Ensure endpoint security controls remain aligned to Microsoft security best practices, CIS benchmarks and organisational standards.
  • Continuously review and optimise endpoint security configurations to reduce risk and improve user experience.
  • Intune & Device Management

    • Administer Microsoft Intune as the primary endpoint management platform.
    • Drive adoption of modern endpoint management capabilities and cloud-native device management practices.
    • Support co-management strategies between Intune and SCCM/MECM.
    • Lead workload transitions from on-premise management solutions to Intune where appropriate.
    • Maintain device lifecycle security standards across enrolment, compliance, monitoring and decommissioning processes.

    SCCM/MECM Administration

    • Manage SCCM/MECM environments supporting:
    • Patch deployment
    • Software distribution
    • Endpoint configuration management
    • Compliance reporting
  • Ensure timely deployment of security updates and critical patches.
  • Support patch governance and vulnerability remediation initiatives.
  • Collaborate with infrastructure and EUC teams to improve endpoint management maturity.
  • BYOD Security Governance

    • Design and implement BYOD security frameworks that balance corporate security requirements with user convenience.
    • Configure and manage:
    • App Protection Policies (MAM)
    • MAM without MDM
    • Device enrolment controls
    • Conditional Access device requirements
    • Corporate application access controls
  • Ensure corporate data remains protected on personal devices through appropriate security controls and data separation mechanisms.
  • Review BYOD adoption and security posture regularly and recommend improvements where necessary.
  • Endpoint Protection & Hardening

    • Configure and optimise Microsoft Defender for Endpoint security capabilities including:
    • Endpoint Detection and Response (EDR)
    • Antivirus
    • Attack Surface Reduction (ASR)
    • Threat and Vulnerability Management
    • Automated Investigation and Remediation
  • Implement and maintain endpoint hardening standards using:
    • BitLocker
    • Windows Security Baselines
    • Firewall Policies
    • Device Control Policies
    • CIS Benchmarks
  • Monitor emerging endpoint risks and recommend mitigation strategies.
  • Compliance Monitoring & Risk Reduction

    • Monitor device health, compliance status and security posture across the endpoint estate.
    • Investigate and remediate non-compliant devices in collaboration with EUC and Service Desk teams.
    • Support vulnerability management and patch compliance initiatives.
    • Develop reporting and dashboards to track endpoint security performance and trends.

    Incident Response & Security Operations

    • Provide technical support during endpoint security incidents.
    • Perform endpoint containment activities including:
    • Device isolation
    • Investigation support
    • Forensic artefact collection
    • Malware remediation
  • Work closely with Security Operations Centre (SOC) teams during investigations and recovery activities.
  • Assist in identifying root causes and implementing preventative measures.
  • Zero Trust Enablement

    • Support the organisation’s Zero Trust security strategy by integrating endpoint compliance with identity and access controls.
    • Collaborate with IAM and security engineering teams to align Conditional Access policies with device trust signals.
    • Ensure device compliance data is effectively leveraged to strengthen access control decisions.
    • Contribute to broader cloud and modern workplace security initiatives.

    Decision-Making Authority

    The successful candidate will:

    • Implement and manage endpoint security configurations within delegated authority.
    • Recommend security baselines, compliance controls and BYOD security requirements.
    • Escalate high-risk devices, unresolved security issues and persistent non-compliance concerns to cyber leadership.
    • Influence endpoint security standards and best practices across the organisation.

    Essential Skills & Experience

    Technical Experience

    • Minimum 5-8 years’ experience in endpoint security, endpoint management or modern workplace security engineering.
    • Strong hands-on experience administering Microsoft Intune in enterprise environments.
    • Experience managing SCCM/MECM and co-managed endpoint environments.
    • Extensive experience implementing Microsoft Defender for Endpoint security controls.
    • Proven experience managing BYOD and mobile device security frameworks.
    • Experience with Windows, macOS, iOS and Android device management and security.
    • Strong understanding of endpoint hardening, patch management and vulnerability remediation.

    Security & Governance Knowledge

    • Knowledge of:
    • Zero Trust security principles
    • CIS Benchmarks
    • Microsoft Security Baselines
    • Device compliance frameworks
    • Endpoint risk management
    • Data protection controls
  • Understanding of Conditional Access, identity-driven security and device trust concepts.
  • Experience supporting audits, compliance reviews and security assessments.
  • Professional Skills

    • Strong troubleshooting and problem-solving capabilities.
    • Excellent stakeholder engagement and communication skills.
    • Ability to work effectively with EUC, Service Desk and Security Operations teams.
    • Strong attention to detail and commitment to security best practice.
    • Ability to prioritise work effectively within a fast-paced environment.

    Preferred Qualifications

    • Microsoft Certified: Endpoint Administrator Associate (MD-102)
    • Microsoft Certified: Security Operations Analyst Associate (SC-200)
    • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
    • Microsoft Certified: Azure Administrator Associate (AZ-104)
    • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
    • CompTIA Security+
    • CISSP, CISM or equivalent security certification advantageous

    Core Technologies

    Endpoint Management

    • Microsoft Intune
    • Endpoint Security Policies
    • Compliance Policies
    • Configuration Profiles
    • App Protection Policies (MAM)

    Endpoint Protection

    • Microsoft Defender for Endpoint
    • Endpoint Detection and Response (EDR)
    • Antivirus
    • Attack Surface Reduction (ASR)
    • Threat & Vulnerability Management

    Legacy & Co-Management Platforms

    • SCCM / MECM
    • Software Deployment
    • Patch Management
    • Co-Management

    Device Hardening & Compliance

    • BitLocker
    • Windows Security Baselines
    • CIS Benchmarks
    • Device Compliance Policies
    • Firewall Management

    BYOD Security

    • Mobile Application Management (MAM)
    • MAM without MDM
    • BYOD Conditional Access
    • Corporate Data Protection Controls

    Identity Integration

    • Microsoft Entra ID
    • Device Registration
    • Hybrid Azure AD Join
    • Conditional Access Integration

    Why Join Us?

    This is an exciting opportunity to play a key role in securing a modern workplace environment through best-in-class endpoint and BYOD security practices. You will work with leading Microsoft technologies, contribute to critical Zero Trust initiatives, and help shape the future of endpoint security across the organisation.

    Required skills