{"id":1198253,"url":"https://alion.io/job/takeda-pharmaceutical-windows-device-engineering-lead","title":"Windows Device Engineering Lead","company":{"id":5984,"name":"Takeda Pharmaceutical","domain":"takeda.com","url":"https://alion.io/company/takeda","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":80,"open_postings":22,"ghost_share":0,"stale_share":0.818,"repost_share":0,"time_to_fill_p50_days":22,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Management","role_family":"Management","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Cambridge, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":137000,"max":215270,"currency":"USD","period":"year","gross":null,"usd_annual":215270},"salary_estimate":null,"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Apache TVM","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"Git","optional":false},{"name":"ITIL","optional":false},{"name":"ITSM","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"PowerShell","optional":false},{"name":"ServiceNow","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false},{"name":"Crowdstrike","optional":true},{"name":"Tanium","optional":true}],"status":"live","first_seen_at":"2026-09-24T19:33:20Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-24T23:36:45Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further attest that all information I submit in my employment application is true to the best of my knowledge.\nJob Description\nPosition Summary\nWe are seeking an experienced and technically deep Windows Device Engineering Lead to own and drive the global endpoint management strategy for approximately 50,000 Windows devices across our worldwide operations. This is a high-impact technical leadership role responsible for the full device lifecycle - from provisioning and configuration to monthly patching, security hardening, and decommission - while coordinating a distributed team of contractors across time zones.\nThe ideal candidate combines hands-on technical mastery in Microsoft Intune, SCCM/MEMCM, PowerShell scripting, and application packaging with the organizational skills to lead, mentor, and direct an offshore delivery team. You will serve as the primary liaison between endpoint engineering, security, and business stakeholders, ensuring our endpoint estate is compliant, resilient, and operationally excellent.\nKey Responsibilities\nEndpoint Management & Strategy\nArchitect, maintain, and continuously improve the global Windows device management platform using Microsoft Intune and SCCM/MEMCM (co-management and cloud-only environments).\nDefine and own configuration baselines, enrollment profiles, compliance policies, and conditional access rules across the ~50,000 endpoint estate.\nDrive the organization's modernization roadmap toward cloud-native device management (Autopilot, Intune-only, co-management).\nOversee device lifecycle management including provisioning, imaging, refresh cycles, and decommissioning procedures.\nPatching & Vulnerability Management\nOwn the end-to-end monthly Patch Tuesday cycle: planning, ring-based deployment, remediation tracking, and executive reporting.\nManage software update servicing (WSUS/SUP, Intune Update Rings, Windows Autopatch) and ensure SLA compliance across all global regions.\nPartner with the Security Operations team to remediate critical and high vulnerabilities within agreed SLO windows.\nMaintain a documented patching run book and escalation path for failures and exceptions.\nSecurity Policy & Compliance (CIS & MDE)\nImplement and enforce CIS Benchmark controls for Windows (Level 1 and Level 2) across the global fleet via Intune configuration profiles and SCCM baselines.\nOwn the Microsoft Defender for Endpoint (MDE) deployment, configuration, and health monitoring - including onboarding policies, ASR rules, tamper protection, and threat & vulnerability management.\nCollaborate with the Security team to operationalize MDE alerts, Secure Score improvements, and endpoint detection & response (EDR) posture.\nConduct periodic compliance reporting against CIS benchmarks and remediate drift; maintain audit-ready documentation.\nManage and tune Intune compliance and conditional access policies to enforce Zero Trust principles.\nPowerShell & Scripting\nDevelop, maintain, and peer-review PowerShell scripts for automation across device management tasks including compliance remediation, reporting, inventory, and configuration drift detection.\nBuild and maintain CI/CD-friendly script repositories with version control (Git), testing frameworks, and documentation standards.\nLeverage Graph API and PowerShell SDK for Intune to automate tenant configuration, bulk operations, and reporting.\nChampion scripting best practices and provide guidance/code reviews to contractor team members.\nApplication Packaging & Deployment\nLead application packaging efforts including Win32 apps (Intune), MSI/EXE/MSIX transforms, and SCCM packages/task sequences.\nDefine and maintain application packaging standards, testing procedures, and approval workflows.\nManage the application catalog, ensuring software is current, licensed, and securely deployed.\nCoordinate with software vendors and internal stakeholders to resolve packaging challenges and dependency conflicts.\nTeam Leadership & Offshore Coordination\nLead, coordinate, and quality-assure the work of a team of offshore contractors based primarily in India, including task assignment, sprint planning, and performance feedback.\nEstablish clear SLAs, runbooks, and escalation paths to ensure consistent delivery quality across time zones.\nConduct regular stand-ups, knowledge-transfer sessions, and technical mentorship for the contractor team.\nManage staffing levels, onboarding, and knowledge continuity to minimize single points of failure.\nCollaborate closely with IT leadership to prioritize the team's backlog against project and operational demands.\nDocumentation, Reporting & Governance\nMaintain comprehensive documentation for all device management processes, configurations, and operational procedures.\nProduce regular management reporting on endpoint health, patch compliance, security posture, and KPIs.\nParticipate in change management processes (CAB), ensuring all changes to the endpoint platform are risk-assessed and communicated.\nRepresent the endpoint team in cross-functional meetings with IT Security, Networking, Help Desk, and business units.\nRequired Qualifications\nExperience\n7+ years of hands-on experience in Windows endpoint management at enterprise scale (10,000+ endpoints).\nDemonstrated experience managing a globally distributed Windows device fleet across multiple geographies.\n3+ years of experience directly leading or coordinating technical teams, including offshore/nearshore resources.\nPrior experience working within a 24/7 global IT operations model preferred.\nTechnical Skills - Must Have\nMicrosoft Intune - Deep, hands-on expertise in Intune device enrollment (AADJ, Hybrid AADJ, Autopilot), configuration profiles, compliance policies, app deployment, and update rings. Experience with Intune co-management and tenant-attach scenarios. Microsoft Intune:\nSCCM / MEMCM - Strong working knowledge of SCCM site design, client deployment, task sequences, OSD, software update management, and reporting (SSRS). Experience migrating workloads to Intune preferred. SCCM / MEMCM:\nPowerShell - Advanced scripting ability; able to write production-grade scripts without supervision. Proficient with PowerShell modules for Intune (Microsoft.Graph), Active Directory, and Windows management. Comfortable with error handling, logging, and modular script design. PowerShell:\nApp Packaging - Proficient with Win32 app packaging for Intune (IntuneWinAppUtil), MSI/MSIX repackaging, silent install parameters, detection rules, and dependency management. Experience with SCCM packages and task sequences. App Packaging:\nCIS Benchmarks - Working knowledge of CIS Microsoft Windows Benchmark controls; experience translating CIS controls into Intune/SCCM policies and tracking compliance. CIS Benchmarks:\nMicrosoft Defender for Endpoint (MDE) - Experience deploying and managing MDE at scale, including onboarding, policy configuration, ASR rules, threat & vulnerability management (TVM), and integration with Microsoft Sentinel or SIEM platforms. Microsoft Defender for Endpoint:\nTechnical Skills - Strong Plus\nWindows Autopatch and Autopilot self-deploying / pre-provisioning scenarios.\nAzure Active Directory / Entra ID - Conditional Access, device compliance integration, hybrid identity.\nMicrosoft Endpoint Analytics and Intune reporting workbooks.\nExperience with ITSM tooling (ServiceNow) for change management and incident integration.\nFamiliarity with Microsoft Sentinel or Defender XDR for endpoint telemetry correlation.\nKnowledge of ITIL frameworks, particularly incident, change, and problem management.\nPreferred Qualifications\nMicrosoft 365 Certified: Endpoint Administrator Associate (MD-102) or equivalent certification.\nMicrosoft Certified: Security, Compliance, and Identity Fundamentals or Security Operations Analyst Associate (SC-200).\nExperience in highly regulated industries (financial services, healthcare, government) with strict compliance requirements.\nFamiliarity with additional endpoint security tools (Microsoft Defender, CrowdStrike, Tanium) is a plus.\nExposure to non-Windows platforms (macOS, iOS/Android via Intune) in a mixed-OS environment.\nExperience with software license management and hardware asset management processes.\nCore Competencies\nTechnical Leadership\nAble to set technical direction, make defensible architectural decisions, and elevate team capability through mentorship.\nCross-Cultural Communication\nCommunicates clearly and effectively with offshore teams across time zones; adapts communication style for diverse audiences.\nSecurity-First Mindset\nTreats endpoint security as a non-negotiable baseline; proactively identifies and closes posture gaps.\nOwnership & Accountability\nTakes full ownership of outcomes - not just tasks. Escalates early, communicates risk, and drives issues to resolution.\nContinuous Improvement\nSeeks automation-first solutions to operational toil; champions process documentation and repeatability.\nWork Environment & Expectations\nAvailability to overlap with India-based contractor team for daily stand-ups and escalations (early morning or late afternoon flexibility required).\nParticipation in on-call rotation for critical P1/P2 endpoint incidents and change windows.\nTravel may be required occasionally for team on-sites or major project deployments (estimate: 0-10% annually).\nMust be comfortable operating in a fast-paced, geographically distributed enterprise IT environment with competing priorities.\nTakeda Compensation and Benefits Summary\nWe understand compensation is an important factoras you consider the next step in your career. We are committed to equitablepay for all employees, and we strive to be more transparent with our pay practices.\nFor Location:\nCambridge, MAU.S. Base Salary Range:\n$137,000.00 - $215,270.00The estimated salary range reflects an anticipated range for this position. The actual base salary offered may depend on a variety of factors, including the qualifications of the individual applicant for the position, years of relevant experience, specific and unique skills, level of education attained, certifications or other professional licenses held, and the location in which the applicant lives and/or from which they will be performing the job. The actual base salary offered will be in accordance with state or local minimum wage requirements for the job location.\nFor information about our benefits, please click here.\nEEO Statement\nTakeda is proud in its commitment to creating a diverse workforce and providing equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, parental status, national origin, age, disability, citizenship status, genetic information or characteristics, marital status, status as a Vietnam era veteran, special disabled veteran, or other protected veteran in accordance with applicable federal, state and local laws, and any other characteristic protected by law.\nLocations\nCambridge, MAWorker Type\nEmployeeWorker Sub-Type\nRegularTime Type\nFull timeJob Exempt\nYesIt is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.","description_format":"text","description_chars":11544,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Biotechnology","Health Care","Pharmaceuticals","Biopharma"],"lifecycle":[{"event":"open","at":"2026-09-24T19:33:20Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":22,"reasons":["conf:2","win:early","comp:brand"],"computed_at":"2026-09-25T02:16:34Z"},"pay":{"stated_usd_annual":215270,"is_top_pay":true},"html_url":"https://alion.io/job/takeda-pharmaceutical-windows-device-engineering-lead","json_url":"https://alion.io/job/takeda-pharmaceutical-windows-device-engineering-lead.json","meta":{"generated_at":"2026-09-25T02:16:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2380,"day_limit":5000,"remaining_today":2620,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}