Advertising Summary:
We are seeking an IT Security Engineer to join our team. This
position leads the Endpoint Computing team within the Information
Security office, providing strategic direction, technical
oversight, and people management for the systems administrators
responsible for enterprise endpoint management, virtual application
delivery, and endpoint security platforms supporting the
university. The role is responsible for driving the modernization
of VCU's endpoint estate, including the transition to cloud-native,
Entra ID–joined device management, and for ensuring the team's
priorities and technical decisions align with the Information
Security office's broader security strategy and initiatives.
Unit: Technology Services
Department: Information Security
Department Summary: Virginia Commonwealth University
(VCU) Technology Services is a central IT organization supporting
the academic, research, and administrative missions of the
university. Technology Services provides scalable, secure, and
innovative technology solutions to all VCU units.
This position is part of the Technology Services Information
Security team, providing technical and administrative expertise in
the support, integration, and modernization of VCU’s enterprise
architecture. The role focuses on identity modernization, SSO
integration, certificate lifecycle automation, and overall
application administration across university systems and
units.
Duties & Responsibilities:
This position leads the Endpoint Computing team within the
Information Security office, providing strategic direction,
technical oversight, and people management for the systems
administrators responsible for enterprise endpoint management,
virtual application delivery, and endpoint security platforms
supporting the university. The role is responsible for driving the
modernization of VCU's endpoint estate, including the transition to
cloud-native, Entra ID–joined device management, and for ensuring
the team's priorities and technical decisions align with the
Information Security office's broader security strategy and
initiatives.
Team Leadership & Operations Management
- Directly manage a team of four system administrators
responsible for enterprise endpoint computing systems, including
hiring, coaching, performance management, and professional
development.
Set priorities, assign work, and establish operational
standards, documentation practices, and change management
procedures for the endpoint computing team.
Serve as an escalation point for complex or high-impact
endpoint, virtualization, and endpoint security issues.
Represent the endpoint computing function in cross-functional
planning with server, network, identity, security, and application
teams.
Manage vendor relationships and licensing for endpoint
management, virtualization, and endpoint security platforms.
Endpoint Management (Intune & ConfigMgr)
- Oversee the administration of Microsoft Intune and Microsoft
Configuration Manager (ConfigMgr) for Windows device management,
including policy, compliance, application deployment, and
patching.
- Guide the team's co-management and migration strategy as
workloads shift from ConfigMgr to cloud-native Intune
management.
- Ensure endpoint configuration baselines align with university
security and compliance requirements.
Apple Device Management (Jamf Pro)
- Oversee administration of Jamf Pro for macOS and iOS/iPadOS
device management, including enrollment, configuration profiles,
application deployment, and patching.
- Support integration of Jamf Pro with Entra ID for
identity-based device management and conditional access.
Virtual Application & Desktop Delivery (Citrix DaaS)
- Oversee the administration and availability of Citrix
Desktop-as-a-Service (DaaS) environments supporting faculty, staff,
and student application access.
- Guide capacity planning, image management, and performance
tuning for virtual desktop and application delivery.
Endpoint Security (CrowdStrike EDR)
- Oversee deployment, health, and policy tuning of the
CrowdStrike endpoint detection and response (EDR) platform across
managed endpoints.
- Partner with the Security Operations team on incident response,
threat containment, and remediation involving managed
endpoints.
- Monitor endpoint security posture and compliance metrics and
report on trends to university leadership.
Modernization & Cloud-Native Initiatives
- Lead the team's roadmap for migrating endpoints to
cloud-native, Entra ID–joined management, reducing reliance on
legacy on-premises infrastructure.
- Evaluate and pilot new endpoint technologies and approaches,
developing migration and rollback plans for enterprise rollout, in
alignment with Information Security priorities.
- Partner with the identity and IAM teams on conditional access,
device compliance, and Zero Trust alignment for managed
endpoints.
Automation & Process Improvement
- Champion the use of scripting and automation (e.g., PowerShell,
Python, Bash) to reduce manual effort in provisioning, patching,
and reporting.
- Establish metrics and reporting for endpoint compliance, patch
levels, and security posture across managed platforms.
- Participate in an on-call rotation, or ensure appropriate team
coverage, for after-hours endpoint or availability issues.
The summary outlines the primary duties of this role. However,
other duties may be assigned as needed.
Minimum Qualifications
- Demonstrated experience managing or leading a technical team,
including assigning work, coaching staff, and managing
performance.
- Demonstrated experience administering enterprise endpoint
management platforms such as Microsoft Intune, Configuration
Manager, or Jamf Pro.
- Experience with virtual application or desktop delivery
platforms (e.g., Citrix, VMware Horizon) or comparable enterprise
technologies.
- Familiarity with endpoint detection and response (EDR) or other
endpoint security tooling.
- Ability to communicate complex technical concepts to both
technical and nontechnical stakeholders, including university
leadership.
- Strong organizational skills with the ability to manage
multiple projects and competing priorities simultaneously.
- Foundational understanding of identity and access management
concepts, including Entra ID / Azure AD and conditional
access.
- Demonstrated ability to work in and foster an environment of
respect, professionalism and civility with a population of faculty,
staff, and students from all backgrounds and experiences, or a
commitment to do so as a staff member at VCU.
Preferred Qualifications
- Bachelor's degree in Information Systems, Computer Science,
Information Technology, or a related field, or equivalent
combination of education and experience.
- Hands-on experience with Microsoft Entra ID–joined
(cloud-native) device management strategies and co-management
transitions from ConfigMgr to Intune.
- Experience with CrowdStrike or comparable EDR platforms in an
enterprise environment.
- Experience in higher education or a large, decentralized
enterprise IT environment.
- Relevant certifications such as Microsoft Certified: Endpoint
Administrator Associate, Jamf Certified Admin, CompTIA Security+,
or equivalent.
Salary Range: $90,000- $100,000
Benefits : All full-time university staff are eligible for
VCU’s robust
benefits
package that includes comprehensive health benefits, paid annual
and holiday leave, generous tuition benefits, retirement planning
and savings options, tax-deferred annuity and cash match programs,
employee discounts, well-being resources, abundant opportunities
for career development and advancement, and more.
FLSA Exemption Status: Exempt
Hours per Week: 40
Restricted Position: No
ORP Eligible: Yes
Flexible Work Arrangement: Hybrid
University Job Title: 24342Y - Security Systems Manager
2
Contact Information:
Contact Name: Mary
Teller
Contact Email: mkteller@vcu.edu