AVP/VP, Endpoint & Device Management Engineer, Technology Group
Singapore, SG
GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.
Technology Group
We experiment, design, and lead a 24×7 global business where we support core capabilities in asset management, trading, investment operations, and risk management. We deliver secure, reliable, and integrated solutions, and provide insights on new, and emerging technologies.
What impact will you make in this role?
As an Endpoint and Device Management Engineer within End User Infrastructure Engineering, you will own the engineering of the platforms that provision, secure, patch, and manage every device our people work on — approximately 5,000 Windows endpoints, 500 macOS devices, and 3,000 mobile devices across iOS, iPadOS, and Android, spanning 11 offices and multiple time zones.
You will be accountable for turning our endpoint estate into a modern, cloud-managed, policy-driven platform: zero-touch from unboxing to productive, continuously compliant, measurably healthy, and hardened to the standards expected of a regulated financial institution. You will engineer by default rather than administer by exception — every configuration expressed as code, every repeatable task automated, every change evidenced and reversible.
What will you do as a AVP/VP, Endpoint & Device Management Engineer?
Endpoint Platform Engineering
- Own the design, build, and run engineering of the enterprise endpoint management platforms: Microsoft Intune, Entra ID, Windows Autopilot, MECM/Configuration Manager, and Jamf.
- Define and maintain the target-state endpoint architecture across Windows, macOS, iOS/iPadOS, and Android, including the co-management and MECM-to-Intune modernisation roadmap.
- Engineer device configuration profiles, security baselines, and compliance policies as reusable, version-controlled, configuration-as-code artefacts.
- Manage the full device lifecycle: enrolment, provisioning, configuration, certificate and identity binding, refresh, re-deployment, wipe, and retirement.
- Maintain platform currency — service releases, feature ring strategy, OS feature updates, and vendor roadmap adoption — with impact assessed ahead of Microsoft and Apple release cycles.
Zero-Touch Provisioning and Device Experience
- Engineer and continuously improve zero-touch provisioning across all platforms: Autopilot (including pre-provisioning and device preparation), Apple Business Manager with Jamf, and Android Enterprise / Apple User Enrolment for mobile.
- Reduce time-to-productive for new joiners, refreshes, and break-fix replacements, and eliminate manual build steps from the provisioning path.
- Engineer the Windows and macOS standard operating environments, including baseline applications, localisation, drivers and firmware, and profile and data migration.
Application Packaging and Deployment
- Own application packaging, sequencing, and deployment across Windows (Win32/MSI/MSIX) and macOS (PKG/DMG), including detection rules, requirement rules, dependency logic, and supersedence.
- Design ring-based, progressively staged deployments with automated health validation and defined rollback, covering both business applications and OS feature updates.
- Partner with application owners and vendors on packaging standards, compatibility testing, and end-of-life remediation, maintaining an evergreen application estate.
Patch and Vulnerability Remediation
- Engineer the patch management service across Windows, macOS, mobile, and third-party applications, with clear SLAs for critical and high-severity vulnerabilities.
- Partner with Information Security and Technology Risk to translate vulnerability findings into packaged, tested, tracked remediation, and drive down mean time to remediate.
- Build reporting that evidences patch compliance and remediation posture to management, internal audit, and regulators.
Device Compliance, Identity, and Conditional Access
- Engineer device compliance policies and their integration with Entra ID Conditional Access, ensuring only healthy, managed, trusted devices reach corporate data and applications.
- Implement and maintain modern authentication and passwordless capabilities on the endpoint, including Windows Hello for Business, certificate-based authentication, and device-bound credentials.
- Manage the endpoint side of data protection: app protection policies, MAM for unmanaged and BYOD scenarios, and controls over corporate data on mobile devices.
Endpoint Security Engineering
- Engineer the deployment, configuration, and health of endpoint security tooling in partnership with Information Security: EDR, DLP, disk encryption (BitLocker, FileVault), attack surface reduction, and application control.
- Maintain security baselines against recognised benchmarks (CIS, Microsoft Security Baselines, Apple platform guidance), with drift detection and automated remediation.
- Own endpoint hardening initiatives and support audit, penetration test, and regulatory findings through to closure.
Telemetry, Analytics, and Proactive Remediation
- Establish unified endpoint telemetry using Nexthink, Intune Endpoint Analytics, and platform data to measure device health, boot and logon performance, application stability, and crash and reliability trends.
- Turn telemetry into action: build proactive detection and machine-led remediation for recurring endpoint issues before they generate tickets.
- Define and report the endpoint health scorecard — compliance, patch currency, provisioning success rate, device reliability, and digital employee experience.
Automation and Engineering Practice
- Work automation-first: PowerShell, Microsoft Graph API, and Python (Terraform where applicable) to eliminate manual effort across provisioning, policy, packaging, reporting, and remediation.
- Maintain automation assets in source control with peer review, testing, and CI/CD-style release pipelines; write runbooks as code that are safe, auditable, and reversible.
- Contribute to engineering standards across End User Infrastructure, including code quality, secrets handling, and least-privilege service principal design.
Key Technologies & Domains
Endpoint & Device Management
- Microsoft Intune / Endpoint Manager
- MECM / Configuration Manager (including co-management)
- Windows Autopilot, Apple Business Manager, Android Enterprise
- Jamf Pro
- Windows 11, macOS, iOS, iPadOS, Android
Identity & Access
- Entra ID (Azure AD), Conditional Access, device identity and compliance
- Active Directory, Group Policy, hybrid join and cloud-native join models
- Certificate services, SCEP/PKCS, Windows Hello for Business
Endpoint Security
- EDR platforms (e.g., Microsoft Defender for Endpoint, CrowdStrike)
- DLP, disk encryption (BitLocker, FileVault), application control, ASR
- Vulnerability management and remediation tooling
- Security baselines and benchmarks (CIS, Microsoft, Apple)
Experience & Telemetry
- Nexthink or equivalent digital experience monitoring
- Intune Endpoint Analytics, Microsoft 365 Apps health and update telemetry
- Log Analytics / Kusto for endpoint reporting
Automation & Engineering
- PowerShell (advanced)
- Microsoft Graph API and REST API integration
- Python; Terraform and Infrastructure-as-Code concepts
- Git-based source control and CI/CD pipelines (e.g., Azure DevOps)
- Application packaging: Win32, MSI, MSIX, PKG, PSADT, Intune Win32 content prep
What makes you a successful candidate?
Experience
- 12+ years of hands-on engineering experience in endpoint, device, or digital workplace infrastructure at enterprise scale.
- Demonstrated ownership of a multi-platform fleet of comparable size and geographic spread, including Windows, macOS, and mobile.
- Experience operating in a regulated environment — financial services, or another sector with equivalent audit, change, and control obligations.
- Track record of delivering a modernisation programme (for example, MECM to Intune, imaging to Autopilot, or on-premises to cloud-native management) in a live production estate.
Technical & Domain Expertise
- Deep, hands-on expertise with Microsoft Intune and Entra ID, including policy design, compliance, Conditional Access, and Autopilot.
- Strong working knowledge of MECM/Configuration Manager and co-management, with a clear point of view on where workloads should sit.
- Practical macOS management experience with Jamf Pro, and mobile management across iOS/iPadOS and Android Enterprise.
- Strong application packaging and deployment capability across Windows and macOS, including detection logic, dependencies, and supersedence.
- Solid grounding in endpoint security engineering — EDR, DLP, encryption, hardening, and vulnerability remediation — and comfort partnering with Information Security as a peer.
- Advanced PowerShell and Microsoft Graph API skills, with working knowledge of Python; familiarity with Terraform and Infrastructure-as-Code practice is an advantage.
- Experience using digital experience monitoring (Nexthink or similar) to drive proactive remediation rather than passive reporting.
- Relevant certifications are valued but not required (e.g., Microsoft MD-102/SC-300, Jamf Certified Admin or Expert).
Work at the Point of Impact
We need to be forward-looking to attract the right people to help us become the Leading Global Long-term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day-to-day decisions. We strive to inspire. To make an impact.
GIC is a Great Place to Work
At GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection. At the same time, we believe that flexibility allows us to do our best work and be our best selves. Thus, our teams come into the office four days per week to harness the benefits of in-person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise. This role will be in our Tampines Office.
GIC is an equal opportunity employer
As an employer, we passionately believe every individual brings with them unique diversity of thought and perspectives to meaningfully enrich perspectives of GIC teams to drive competitive performance. An inclusive environment yields exceptional contribution.
Learn more about our Technology Group here:
https://gic.careers/group/technology-group/