Endpoint Engineering Specialist

Description: 

 

Permanent Full Time 

-

 

 

The Engineering Specialist is a senior technical role responsible for designing, implementing, securing, and continuously improving the organization's end-user computing and digital workplace platforms. This role combines endpoint engineering, desktop engineering, virtual desktop infrastructure, automation, security, compliance, and service improvement responsibilities to deliver secure, scalable, and user-focused workplace technology services.

The successful candidate will work across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), Microsoft Entra ID, Microsoft Defender, Windows Autopatch, Azure Virtual Desktop (AVD/AVDI), FSLogix, Microsoft 365 Apps, Jamf for macOS, automation frameworks, and enterprise analytics/DEX capabilities. The role requires strong technical depth, practical operational awareness, and the ability to collaborate across Architecture, Infrastructure, Security, Cloud, Network, Service Desk, Field Services, HCL/partner teams, and business stakeholders.

 

What you will do

Endpoint Platform Engineering & Automation

  • Design, develop, and maintain modern endpoint management capabilities across Windows, macOS, physical desktop, and virtual desktop environments.
  • Administer and enhance platforms including Microsoft Intune, MECM, Entra ID, Microsoft Defender, Windows Autopatch, Microsoft 365 Apps, Jamf, and related management services.
  • Develop automation using PowerShell, Microsoft Graph, REST APIs, Azure tooling, and other approved technologies to improve provisioning, software deployment, compliance, reporting, and operational efficiency.
  • Evaluate emerging endpoint, AI-enabled, and digital workplace technologies to improve service delivery, employee experience, resiliency, and supportability.


Azure Virtual Desktop & Cloud Desktop Services

  • Design, deploy, and manage Azure Virtual Desktop environments including host pools, session hosts, application groups, images, scaling plans, and user access models.
  • Implement and troubleshoot FSLogix profile containerization, user profile issues, session host performance, and service reliability concerns.
  • Integrate AVD/AVDI with Microsoft Entra ID, Conditional Access, MFA, network controls, and enterprise security requirements.
  • Optimize virtual desktop performance and health through Azure Monitor, Log Analytics, endpoint analytics, DEX insights, and operational reporting.
  • Support infrastructure-as-code and repeatable deployment practices using Terraform or other approved automation frameworks.


Patching, Security, Compliance & Risk

  • Develop, maintain, and continuously improve endpoint patching, vulnerability management, configuration baseline, compliance, and endpoint hardening processes.
  • Design and implement endpoint security controls, compliance policies, application control capabilities, software governance practices, and audit-supporting controls.
  • Monitor, assess, and remediate security, compliance, vulnerability, and audit findings through automation, reporting, risk assessment, and collaboration with Security and Infrastructure teams.
  • Support governance, change management, technical review, operational readiness, and positive risk-culture expectations across engineering deliverables.


Network, Access & Platform Reliability

  • Troubleshoot endpoint and AVD-related connectivity issues, including routing, firewall, segmentation, policy, and access control challenges.
  • Collaborate with Network, Cloud, Security, IAM, and Infrastructure teams to analyze traffic flows, resolve firewall rule conflicts, and ensure secure access to workplace services.
  • Identify root causes of recurring environmental issues and recommend proactive engineering improvements that reduce downtime, support incidents, and operational risk.


End User Experience, Tier 3 Support & Service Improvement

  • Provide Tier 3 support for complex endpoint, software, security, desktop, and virtual desktop incidents and escalations.
  • Partner with Service Desk, Field Services, End User Operations, Security, Cloud, and partner teams to drive timely resolution and knowledge transfer.
  • Use endpoint health, performance, DEX, and incident trends to identify opportunities for proactive remediation and measurable service improvement.
  • Develop support guidance, technical training, change enablement material, and adoption support for new technologies and workplace services.


Project Delivery, Lifecycle & Roadmap Contribution

  • Lead and participate in endpoint, desktop, AVDI, modernization, lifecycle, migration, and compliance-related projects.
  • Contribute to technology roadmaps, lifecycle planning, platform modernization, Windows servicing, device lifecycle, and continuous improvement initiatives.
  • Work within Agile delivery practices including sprint planning, backlog refinement, daily standups, retrospectives, release planning, and prioritization using Jira, ServiceNow, Azure DevOps, or other approved tools.
  • Provide technical leadership to ensure solutions are secure, supportable, operationally ready, and aligned with business, architectural, compliance, and service-management standards.


Governance, Documentation & Knowledge Management

  • Develop and maintain engineering standards, technical documentation, architecture diagrams, operational procedures, configuration baselines, compliance controls, and support documentation.
  • Promote process standardization, knowledge sharing, handoff readiness, and continuous improvement across End User Technology and partner support teams.
  • Ensure documentation supports effective transition of operational activities where appropriate while preserving engineering accountability for design and lifecycle ownership.


What you will bring
Required Qualifications

  • 5-7 years of experience in endpoint engineering, desktop engineering, workplace technology, virtual desktop, infrastructure engineering, or related technical roles.
  • Strong experience supporting and engineering enterprise Windows environments, with working knowledge of macOS management in enterprise settings.
  • Deep knowledge of Microsoft endpoint and workplace technologies including Intune, MECM, Entra ID, Microsoft Defender, Windows Autopatch, Microsoft 365 Apps, endpoint analytics, and related management capabilities.
  • Hands-on experience with Azure Virtual Desktop, FSLogix, virtual desktop operations, image management, session host troubleshooting, and performance optimization.
  • Strong understanding of endpoint lifecycle management, configuration baselines, software deployment, vulnerability management, patching, compliance, and audit-supporting processes.
  • Proficiency with PowerShell and experience leveraging Microsoft Graph, REST APIs, automation technologies, reporting, and operational scripting.
  • Practical understanding of Azure networking and security concepts relevant to endpoint and virtual desktop services, including VNets, NSGs, access controls, firewall rules, routing, and segmentation.
  • Experience collaborating with Security, Cloud, Network, Architecture, IAM, Service Desk, Field Services, Operations, and business stakeholders in a large enterprise environment.
  • Familiarity with Agile delivery methodologies and enterprise work-management platforms such as Jira, ServiceNow, Azure DevOps, or equivalent tools.
  • Strong analytical, troubleshooting, communication, documentation, stakeholder management, and technical leadership skills.


Preferred Assets

  • Microsoft certifications related to Intune, Endpoint Management, Azure, Security, Entra ID, Modern Workplace, or Azure Virtual Desktop.
  • Microsoft Certified: Azure Virtual Desktop Specialty, Microsoft Certified: Endpoint Administrator Associate, or equivalent experience.
  • HashiCorp Certified: Terraform Associate or demonstrable infrastructure-as-code experience in Azure environments.
  • ITIL, Security+, CISSP, or equivalent security, governance, or service-management certifications.
  • Experience with Digital Employee Experience (DEX) platforms, endpoint analytics, and AI-enabled productivity technologies such as Microsoft Copilot and Copilot Studio.
  • Experience with Windows 365, cloud PC, AVDI modernization, enterprise automation frameworks, and large-scale hybrid or cloud-first deployments.
  • Experience operating in a large, regulated enterprise environment with strong governance, change management, compliance, and audit expectations.

-

The base salary for this position is between $58,700.00 - $108,700 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

Grow with Canada Life 

We’re united by a shared purpose: to improve the financial, physical and mental well-being of Canadians. Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.  

We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other. Are you someone who always strives to do the right thing, who steps up for themselves and others, and who delivers with impact? Then we want to hear from you! 

What we offer:  

We’re committed to supporting our employees through every stage of their career. Here’s what you can expect as a full-time or part-time permanent team member: 

  • Career Development: Opportunities for career advancement, access to industry-leading learning programs and up to $2,000 annually towards education reimbursement. 
  • Health & Wellness: Flexible health and dental benefits, plus a $5,000 mental health benefit to support your well-being. 
  • Time Off: In addition to regular vacation and personal days, we support community involvement with a volunteer day.  
  • Financial Security: Company-matching pension plan, share ownership program and additional investment options. 
  • Rewards and Recognition: Employee recognition programs, service milestone celebrations, employee discounts and more!  
  • Emphasis on Community: We provide a workplace where employees feel connected and supported through Employee Resource Groups (ERGs), mentorship programs, social clubs and events.  

Learn more about Canada Life.  

We’re committed to removing barriers and ensuring equal access to employment. Applicants requiring reasonable accommodation during the application process may contact  talentacquisitioncanada@canadalife.com. All information provided will be handled in accordance with applicable laws and Canada Life policies.  

Canada Lifewould like to thank all applicants, however only those who qualify for an interview will be contacted

#LI-Hybrid 

Requisition ID:  6854
Category:  Digital Technology
Location: 

London, ON, CA Winnipeg, MB, CA Toronto, ON, CA

Date:  Sep 1, 2026

If you are not finding suitable opportunities now, please click below to join our talent community!