Surya Technologies
Website:
suryatechnologies.com
Job details:
About Us
Surya Technologies engineers and operates the endpoint estate for healthcare, manufacturing, and professional services operators in the United States. We run a device logistics facility in Research Triangle Park, North Carolina, and our engineering practice is based in Bengaluru.
We do not sell blocks of hours or run a ticket queue as the product. We build engineered, repeatable units of work — a device configuration, a compliance baseline, a conditional access model, an onboarding path — and we operate them at scale across customers. Tickets are the exception layer, not the operating model.
We are building out a dedicated endpoint engineering practice and hiring engineers into it now.
The Role
You will own the design and operation of customer endpoint environments on the Microsoft stack Entra ID, Intune, and the Zero Trust controls around them. This is build-and-operate work, not support escalation. You are expected to design a baseline, prove it, write it down once, and then run it across a portfolio.
You will work directly with US-based customers and with our RTP logistics operation, which physically provisions and ships the devices you configure.
Job Responsibilities:
- Design and operate Intune configurations end to end: enrolment, Autopilot, compliance policies, configuration profiles, app deployment and packaging, update rings and driver management.
- Build and maintain Zero Trust access models in Entra ID — Conditional Access, device compliance as an access signal, privileged access, and identity protection policy.
- Stand up new customer tenants against a defined baseline and shorten the time it takes to do so with each one.
- Operate Defender for Endpoint and the security posture that sits on top of the estate, including remediation of what it surfaces.
- Work with our device logistics facility so that what leaves the warehouse matches what the tenant expects — zero-touch, first boot, day one ready.
- Write and record the runbook for every engineered outcome you produce. We do not teach the same thing twice; training sessions are recording sessions.
- Provide human-in-the-loop oversight for the AI agents that run inside our delivery platform — reviewing, approving, and correcting automated actions on customer environments.
Requirements:
- Bachelor's degree in [Computer Science / Engineering]
- 3–6 years of hands-on engineering experience with Microsoft Intune and Entra ID in production environments.
- Demonstrated ownership of a Conditional Access or Zero Trust access design, not just administration of one someone else built.
- Practical experience with Windows Autopilot, device compliance policy, and application deployment at fleet scale.
- Working knowledge of Microsoft 365 E5 security services — Defender for Endpoint, Defender for Identity, and the signal flow between them.
- Scripting competence in PowerShell and comfort working against the Microsoft Graph API.
- Fluent, daily use of AI coding and reasoning tools in your engineering work, with the judgement to verify their output.
- Written English strong enough to produce customer-facing documentation without editing.
- Availability to overlap with US Eastern business hours and to work scheduled maintenance windows.
Preferred Skills:
- Multi-tenant experience — MSP, CSP, or a platform serving several customer tenants.
- Microsoft SC-300, MD-102, or SC-200 certification.
- Experience with imaging and provisioning at the hardware layer (iPXE, SmartDeploy, or equivalent).
- Exposure to regulated environments — healthcare or manufacturing.
This Role is Not:
- A helpdesk, L1, or L2 support position.
- A tenant-administration seat following someone else's design.
- A ServiceNow or ITSM process role
Click on Apply to know more.