Ensign Services

DevOps Engineer (Endpoint & Automation Engineering)

Ensign Services Singapore

Hospitals and Health Care · 10,001+ employees

8 h ago
devops Mid (2-5 yrs) Full-time Singapore
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Design, develop, and maintain Windows thick client applications and automate system administration using PowerShell and Infrastructure as Code. Manage device lifecycles and endpoint security through Microsoft Intune and integrate with the broader Microsoft ecosystem.

What they look for

Windows PowerShell Infrastructure as Code Microsoft Intune C# WPF WinForms Terraform Azure Bicep Ansible PowerShell DSC Windows Autopilot Microsoft Graph API CI/CD Azure DevOps Git Endpoint Security

Requirements

Requires proficiency in Windows PowerShell scripting, Infrastructure as Code tools, and .NET Framework development for Windows desktop applications. Candidates should have hands-on experience with Microsoft Intune and endpoint management.

Full description

Ensign is hiring !

About the Role

We are seeking DevOps Engineer with strong Windows platform engineering capabilities to design, build, and automate solutions across our enterprise endpoint environment. This role sits at the intersection of software development and infrastructure automation — you will build Windows thick client applications, drive automation through scripting and Infrastructure as Code, and manage modern device deployment at scale through Microsoft Intune.

This is a hands-on engineering role suited to someone who enjoys building tools that make enterprise IT environments more secure, consistent, and efficient.

Key Responsibilities

  • Design, develop, and maintain Windows thick client applications using the .NET Framework, including UI development, packaging, and deployment.
  • Develop, test, and maintain Windows PowerShell scripts and modules to automate system administration, configuration management, and operational workflows.
  • Build and manage infrastructure using Infrastructure as Code (IaC) practices — authoring, versioning, and deploying declarative configurations for repeatable, auditable environment provisioning.
  • Administer and engineer solutions on Microsoft Intune, including application packaging and deployment, compliance and configuration policies, device enrolment (Windows Autopilot), and endpoint security baselines.
  • Integrate Intune with broader Microsoft ecosystem components (Entra ID / Azure AD, Endpoint Analytics, Microsoft Graph API) to automate device lifecycle management and reporting.
  • Troubleshoot and resolve issues across the application, scripting, and endpoint management layers, performing root cause analysis and implementing permanent fixes.
  • Maintain source control hygiene, CI/CD pipelines, and technical documentation for all scripts, applications, and infrastructure definitions.
  • Collaborate with security, infrastructure, and application teams to ensure solutions meet security, compliance, and operational standards.

Requirements

  • Proficient in Windows PowerShell scripting — able to write production-grade scripts and modules for automation, system administration, and integration tasks (error handling, logging, remoting, module design).
  • Proficient in Infrastructure as Code — hands-on experience with tools such as Terraform, Azure Bicep/ARM templates, Ansible, or PowerShell DSC to provision and manage infrastructure declaratively.
  • Proficient in the .NET Framework for Windows thick client development — experience building desktop applications using WinForms and/or WPF in C#, including deployment and maintenance of enterprise desktop applications.
  • Hands-on experience with Microsoft Intune — application deployment (Win32 app packaging), device configuration profiles, compliance policies, and Windows Autopilot provisioning.

Good to Have

  • Experience with Microsoft Graph API for Intune/Entra ID automation.
  • Familiarity with Azure services (Azure Functions, Log Analytics, Automation Accounts).
  • Experience with CI/CD tooling (Azure DevOps, GitHub Actions) and Git-based workflows.
  • Knowledge of endpoint security concepts — device hardening, CIS benchmarks, Defender for Endpoint.
  • Relevant certifications such as MD-102 (Endpoint Administrator), AZ-104, or AZ-400.

Similar roles