Advertising Summary:
We are seeking an IT Security Engineer to join our team. This position leads the Endpoint Computing team within the Information Security office, providing strategic direction, technical oversight, and people management for the systems administrators responsible for enterprise endpoint management, virtual application delivery, and endpoint security platforms supporting the university. The role is responsible for driving the modernization of VCU's endpoint estate, including the transition to cloud-native, Entra ID–joined device management, and for ensuring the team's priorities and technical decisions align with the Information Security office's broader security strategy and initiatives.
Unit: Technology Services
Department: Information Security
Department Summary: Virginia Commonwealth University (VCU) Technology Services is a central IT organization supporting the academic, research, and administrative missions of the university. Technology Services provides scalable, secure, and innovative technology solutions to all VCU units.
This position is part of the Technology Services Information Security team, providing technical and administrative expertise in the support, integration, and modernization of VCU’s enterprise architecture. The role focuses on identity modernization, SSO integration, certificate lifecycle automation, and overall application administration across university systems and units.
Duties & Responsibilities:
This position leads the Endpoint Computing team within the Information Security office, providing strategic direction, technical oversight, and people management for the systems administrators responsible for enterprise endpoint management, virtual application delivery, and endpoint security platforms supporting the university. The role is responsible for driving the modernization of VCU's endpoint estate, including the transition to cloud-native, Entra ID–joined device management, and for ensuring the team's priorities and technical decisions align with the Information Security office's broader security strategy and initiatives.
Team Leadership & Operations Management
-
Directly manage a team of four system administrators responsible for enterprise endpoint computing systems, including hiring, coaching, performance management, and professional development.
-
Set priorities, assign work, and establish operational standards, documentation practices, and change management procedures for the endpoint computing team.
-
Serve as an escalation point for complex or high-impact endpoint, virtualization, and endpoint security issues.
-
Represent the endpoint computing function in cross-functional planning with server, network, identity, security, and application teams.
-
Manage vendor relationships and licensing for endpoint management, virtualization, and endpoint security platforms.
Endpoint Management (Intune & ConfigMgr)
-
Oversee the administration of Microsoft Intune and Microsoft Configuration Manager (ConfigMgr) for Windows device management, including policy, compliance, application deployment, and patching.
-
Guide the team's co-management and migration strategy as workloads shift from ConfigMgr to cloud-native Intune management.
-
Ensure endpoint configuration baselines align with university security and compliance requirements.
Apple Device Management (Jamf Pro)
-
Oversee administration of Jamf Pro for macOS and iOS/iPadOS device management, including enrollment, configuration profiles, application deployment, and patching.
-
Support integration of Jamf Pro with Entra ID for identity-based device management and conditional access.
Virtual Application & Desktop Delivery (Citrix DaaS)
-
Oversee the administration and availability of Citrix Desktop-as-a-Service (DaaS) environments supporting faculty, staff, and student application access.
-
Guide capacity planning, image management, and performance tuning for virtual desktop and application delivery.
Endpoint Security (CrowdStrike EDR)
-
Oversee deployment, health, and policy tuning of the CrowdStrike endpoint detection and response (EDR) platform across managed endpoints.
-
Partner with the Security Operations team on incident response, threat containment, and remediation involving managed endpoints.
-
Monitor endpoint security posture and compliance metrics and report on trends to university leadership.
Modernization & Cloud-Native Initiatives
-
Lead the team's roadmap for migrating endpoints to cloud-native, Entra ID–joined management, reducing reliance on legacy on-premises infrastructure.
-
Evaluate and pilot new endpoint technologies and approaches, developing migration and rollback plans for enterprise rollout, in alignment with Information Security priorities.
-
Partner with the identity and IAM teams on conditional access, device compliance, and Zero Trust alignment for managed endpoints.
Automation & Process Improvement
-
Champion the use of scripting and automation (e.g., PowerShell, Python, Bash) to reduce manual effort in provisioning, patching, and reporting.
-
Establish metrics and reporting for endpoint compliance, patch levels, and security posture across managed platforms.
-
Participate in an on-call rotation, or ensure appropriate team coverage, for after-hours endpoint or availability issues.
The summary outlines the primary duties of this role. However, other duties may be assigned as needed.
Minimum Qualifications
-
Demonstrated experience managing or leading a technical team, including assigning work, coaching staff, and managing performance.
-
Demonstrated experience administering enterprise endpoint management platforms such as Microsoft Intune, Configuration Manager, or Jamf Pro.
-
Experience with virtual application or desktop delivery platforms (e.g., Citrix, VMware Horizon) or comparable enterprise technologies.
-
Familiarity with endpoint detection and response (EDR) or other endpoint security tooling.
-
Ability to communicate complex technical concepts to both technical and nontechnical stakeholders, including university leadership.
-
Strong organizational skills with the ability to manage multiple projects and competing priorities simultaneously.
-
Foundational understanding of identity and access management concepts, including Entra ID / Azure AD and conditional access.
-
Demonstrated ability to work in and foster an environment of respect, professionalism and civility with a population of faculty, staff, and students from all backgrounds and experiences, or a commitment to do so as a staff member at VCU.
Preferred Qualifications
-
Bachelor's degree in Information Systems, Computer Science, Information Technology, or a related field, or equivalent combination of education and experience.
-
Hands-on experience with Microsoft Entra ID–joined (cloud-native) device management strategies and co-management transitions from ConfigMgr to Intune.
-
Experience with CrowdStrike or comparable EDR platforms in an enterprise environment.
-
Experience in higher education or a large, decentralized enterprise IT environment.
-
Relevant certifications such as Microsoft Certified: Endpoint Administrator Associate, Jamf Certified Admin, CompTIA Security+, or equivalent.
Salary Range: $90,000- $100,000
Benefits: All full-time university staff are eligible for VCU’s robust benefits package that includes comprehensive health benefits, paid annual and holiday leave, generous tuition benefits, retirement planning and savings options, tax-deferred annuity and cash match programs, employee discounts, well-being resources, abundant opportunities for career development and advancement, and more.
FLSA Exemption Status: Exempt
Hours per Week: 40
Restricted Position: No
ORP Eligible: Yes
Flexible Work Arrangement: Hybrid
University Job Title: 24342Y - Security Systems Manager 2
Contact Information:
Contact Name: Mary Teller
Contact Email: mkteller@vcu.edu