Principal Service Engineer

About Providence

Providence, one of the US’s largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world’, Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Providence has a network of 51 hospitals, 1,000+ care clinics, senior services, supportive housing, and other health and educational services in the US.

Providence India is bringing to fruition the transformational shift of the healthcare ecosystem to Health 2.0. The India center will have focused efforts around healthcare technology and innovation, and play a vital role in driving digital transformation of health systems for improved patient outcomes and experiences, caregiver efficiency, and running the business of Providence at scale.


Why Us?

  • Best In-class Benefits
  • Inclusive Leadership
  • Reimagining Healthcare
  • Competitive Pay
  • Supportive Reporting Relation

Organization Background:

The Endpoint Engineering Services team manages all the client endpoints across our enterprise: Windows and Apple desktops, laptops, iPhones, and iPads. We are responsible for ensuring that endpoints and their software are up to date with the latest approved OS version, patched, application delivery is maintained, and overall health is maintained. We ensure a seamless experience for caregivers through a centralized tool that automates many of these transactions.

What will you be responsible for?

  • The role owns end‑to‑end architecture for Apple device (IOS/IPADS/MAC) onboarding, compliance, data protection, app lifecycle, OS updates, and Zero Trust access—integrated with Entra ID (Azure AD), Defender for Endpoint, and enterprise PKI/VPN/Wi‑Fi/SSO systems.
  • Intune MDM & MAM policies and configuration profiles.
  • Jamf Pro for advanced macOS and iOS lifecycle management.
  • Define the reference architecture for iOS/iPadOS management:
  • Enrollment models: Automated Device Enrollment (ADE/DEP) via Apple Business Manager (ABM), User Enrollment, Device Enrollment, and Shared iPad for Business.
  • Supervision strategy for corporate devices (Single App Mode, Home screen layout, kiosk/line-of-business scenarios).
  • MAM‑WE (app protection without enrollment) for BYOD.
  • Implement data protection via MAM policies: cut/copy/paste restrictions, save-as control, conditional launch, pin requirements, and organizational data wipe on app retirement
  • Build touchless provisioning flows: ABM > ADE > Intune enrollment profiles; Managed Apple IDs governance; Apple Configurator workflows for special cases.
  • Design Zero Trust access with Conditional Access, device compliance signals, and integration with Defender for Endpoint.
  • Establish tenant segmentation patterns for global orgs, data residency, and role-based administration
  • Author and maintain iOS/iPadOS configuration profiles:
  • Restrictions (managed open-in, clipboard restrictions, account modification, iCloud services), App Config (managed app settings), Per App VPN, Wi Fi, eSIM/eUICC where applicable, Web Content Filter (network extension), SSO extensions, SCEP/PKCS certificates, Exchange/Google/IMAP profiles (if required).
  • Hands on expertise with Microsoft Intune (Endpoint Manager) including Device Configuration profiles (Settings catalog, templates), Endpoint Security policies (Antivirus, Firewall, Disk Encryption, ASR) and Application lifecycle management (Win32, Store, LOB, M365 Apps)
  • Automate device management tasks using PowerShell, Graph API, and Jamf API
  • Develop automation scripts (PowerShell, Bash, Python) to streamline operations, reporting, and remediation tasks, reducing manual effort and error rates.

What would your day look like?

  • Administering Microsoft Intune
  • Device Onboarding & Enrollment Operations.
  • Compliance & Conditional Access Monitoring.
  • App Lifecycle Management - Manage Apps and Books (VPP) licenses in Apple Business Manager and ensure correct assignment.
  • Policy & Configuration Management - Configuration profiles (Wi-Fi, VPN, restrictions, SSO extension, certificates). MAM App Protection Policies for BYOD. Device configuration baselines for frontline/iPad kiosk scenarios.
  • Triage and manage Requests, Incidents, and Project work through ServiceNow and Azure DevOps (ADO)
  • Evaluate new Microsoft/Apple roadmap features and perform POC and oversee planned rollouts.
  • Monitor, report out to management various security patching-related KPI and prepare and execute corrective action plans to meet KPIs

Who are we looking for?

  • 8 -12 years of experience in Intune/MDM/MAM/MECM/JAMF Technologies
  • Enterprise Architecture: Endpoint Management, Security & Compliance, Identity & Access Management (Entra ID, Active Directory)
  • Automation & Scripting: PowerShell, Bash, Python
  • Cloud & Mobility: Microsoft Intune, Azure AD, Mobile Device Management (MDM), Mobile Application Management (MAM)
  • Data & Reporting: Power BI, SQL, API Integration
  • Process & Documentation: ServiceNow, Azure DevOps, Solution Design, Process Optimization based access control.

Providence’s vision to create ‘Health for a Better World’ aids us to provide a fair and equitable workplace for all in our employment, whether temporary, part-time or full time, and to promote individuality and diversity of thought and background, and acknowledge its role in the organization’s success. This makes us committed towards equal employment opportunities, regardless of race, religion or belief, color, ancestry, disability, marital status, gender, sexual orientation, age, nationality, ethnic origin, pregnancy, or related needs, mental or sensory disability, HIV Status, or any other category protected by applicable law. In furtherance to our mission in building a more inclusive and equitable environment, we shall, from time to time, undertake programs to assist, uplift and empower underrepresented groups including but not limited to Women, PWD (Persons with Disabilities), LGTBQ+ (Lesbian, Gay, Transgender, Bisexual or Queer), Veterans and others. We strive to address all forms of discrimination or harassment and provide a safe and confidential process to report any misconduct.

Contact our Integrity hotline also, read our Code of Conduct.