You will be a hands‑on technical leader and problem solver who thrives in fast‑paced enterprise environments. This role focuses on delivering secure, stable, and scalable Windows endpoint platforms through advanced desktop engineering practices. You will balance day‑to‑day operational demands while independently driving technical initiatives and leading desktop‑focused projects with PM support.
What you will do
Design, engineer, and deliver scalable, secure, and standardized desktop solutions aligned with the enterprise end‑user computing roadmap.
Act as a subject matter expert for desktop engineering, owning engineering standards, technical roadmaps, service improvements, and platform enhancements.
Serve as a technical lead on desktop initiatives, building, validating, testing, and documenting solutions while ensuring smooth operational handover and knowledge transfer.
Design, build, and maintain Windows 11 deployment strategies including imaging, provisioning, upgrade paths, and lifecycle management.
Engineer and maintain endpoint management solutions using SCCM and Microsoft Intune, including co‑management where applicable.
Support the Global Software Delivery teams Windows servicing strategies including deployment rings, update orchestration, and phased rollout of feature and quality updates using Windows Update for Business, SCCM, and Intune.
Develop, implement, and maintain desktop security baselines, compliance policies, and endpoint hardening standards aligned with security requirements.
Perform and remediate desktop baseline scanning and compliance assessments to ensure endpoints meet security and operational standards.
Manage hardware platforms including model onboarding, driver packaging, BIOS/firmware updates, and lifecycle refresh activities.
Implement solutions to improve desktop stability, performance, security, patching, and overall end‑user experience.
Maintain accurate and current technical documentation for all desktop services and solutions in accordance with service design standards.
Balance a busy operational workload while independently running desktop engineering projects from a technical perspective (with PM support).
Identify when additional capacity is required and engage or coordinate contract and partner resources to support delivery.
Collaborate with operations and support teams to analyze incident, problem, and trend data for continuous improvement.
Work closely with infrastructure, security, service desk, and front‑line support teams to ensure desktop solutions are supportable and aligned.
Execute projects in partnership with other teams involving:
Windows 11
SCCM
Microsoft Intune
Desktop imaging and provisioning
Endpoint security baselines and hardening
Hardware platforms, drivers, and firmware
What you need to succeed
Advanced experience with SCCM (applications, OS deployment, compliance, reporting)
Advanced experience with Windows 10/11 imaging, deployment, and in‑place upgrades
Advanced PowerShell scripting capabilities including module development and automation frameworks
Strong hands‑on experience with Microsoft Intune (device configuration, compliance, endpoint security)
Experience designing and implementing desktop security baselines and endpoint hardening
Experience with desktop compliance scanning and remediation
Strong knowledge of hardware platforms, driver management, BIOS/firmware updates, and vendor tooling
Experience with co‑management or hybrid endpoint environments
Experience designing and implementing Windows servicing rings and update deployment strategies
Experience working in large, globally distributed enterprise environments
Familiarity with BitLocker, endpoint protection, and device security controls
Knowledge of Windows Update for Business, update compliance reporting, and feature update management
Preferred skills
Strong technical leadership skills with experience driving engineering outcomes (without needing to be a formal PM)
Ability to work independently and take ownership of desktop engineering initiatives
Experience coordinating internal teams and external/contract resources
General knowledge of networking, servers, identity, and security concepts as they relate to endpoint computing
Proficiency with PowerShell scripting for endpoint automation, configuration management, and reporting (required)
Proven problem‑solving skills in large or complex enterprise environments
University degree / college diploma in a related discipline or equivalent practical experience
7+ years of experience in the IT industry, with significant focus on endpoint or desktop engineering
Benefits
Wellness programs that support mental, physical, and financial health
Opportunity to advance career through networking and development opportunities
Hybrid work model allowing flexibility between office and remote work based on business need
Security Clearance and Background Checks
As a condition of the role, the successful candidate must obtain a Government of Canada Reliability Status security clearance through Sun Life in advance of the start date. Must be able to satisfactorily complete applicable background checks prior to the start date and during employment, in accordance with Sun Life’s policies and practices.
The Base Pay range is for the primary location for which the job is posted. It may vary depending on the work location of the successful candidate or other factors. In addition to Base Pay, eligible Sun Life employees participate in various incentive plans, payment under which is discretionary and subject to individual and company performance.
Diversity and inclusion are at the core of our values at Sun Life. We welcome applications from qualified individuals from all backgrounds.
Persons with disabilities who need accommodation in the application process can request an alternative format.
Salary Range
90,000/90 000 - 140,000/140 000
Job Category
IT - Technology Services
Posting End Date
06/05/2026
#J-18808-Ljbffr