Lead Endpoint Engineering Architect
Iovance Biotherapeutics aims to be the global leader in innovating, developing and delivering tumor infiltrating lymphocyte (TIL) therapy for people with cancer. We are pioneering a transformational approach to treating cancer by harnessing the ability of the human immune system to recognize and attack diverse cancer cells in each patient. The Iovance TIL platform has demonstrated promising clinical data across multiple solid tumors. We are committed to continuous innovation in cell therapy, including gene-edited cell therapy, which may be a promising option for patients with cancer.
Overview
The Lead Endpoint Engineering Architect will own the architecture and build-out of Iovance’s endpoint management platform, covering roughly 1,000 Windows devices across corporate, lab, and field locations. This role exists to design a modern, reliable endpoint platform on Microsoft Intune, Autopilot, and Entra ID, build it, document it, and hand off day-to-day operations to the existing support team with clear runbooks. This is a hands-on technical role, not a management role. The Lead Endpoint Engineering Architect will partner with IT Security, Quality Assurance, and business stakeholders across the company, but the core of the job is engineering work: designing configurations, packaging applications, writing PowerShell, testing deployments, and solving problems.
Essential Functions and Responsibilities
- Own the design and implementation of our Intune and Autopilot environment end-to-end: enrollment profiles, configuration profile architecture, compliance policies, Conditional Access, and update ring strategy.
- Build Autopilot provisioning workflows that let us ship a factory-sealed laptop to any employee and have it arrive fully configured without a technician touching it. This includes selecting the right deployment modes for different device scenarios and troubleshooting the enrollment edge cases that inevitably come up.
- Create a layered configuration profile structure in Intune: security baselines that apply to everything, role-specific profiles for different groups, and exception policies where needed.
- Set up Windows Update for Business with proper ring management so updates deploy in controlled phases.
- Design and own application deployment approach using Intune’s Win32 packaging model. This means proper dependency chains, detection rules that actually verify successful installs, and a consistent test-before-deploy process. Application packaging is a significant part of this role, especially during the initial platform build-out.
- Build Proactive Remediations that detect and auto-fix common problems like dropped network drives, configuration drift, and application health issues before users have to call the help desk.
- Establish and maintain laptop performance baselines and remediation workflows — including startup time optimization, memory and CPU utilization profiling, background service rationalization, and bloatware removal — using Intune Proactive Remediations (detection + remediation script pairs), Endpoint Analytics scores, and Windows performance counters to identify degradation patterns before they generate tickets, and to enforce consistent performance standards across both hardware models.
- Work with IT Security to implement compliance policies and Conditional Access rules that give us continuous, auditable proof that our endpoints meet our security baseline.
- Write and maintain the documentation that makes this platform operable by others on the team: architecture diagrams, runbooks, application packaging standards, and troubleshooting guides.
- Train and mentor our deskside and help desk staff on Intune operations, including how to look up a device, check compliance, verify app assignments, trigger syncs, and know when to escalate.
- Evaluate endpoint management tools and technologies as needed, particularly OEM driver management solutions for our hardware fleet.
- Design, build, and maintain