Intune, EUC & BYOD Security Engineer
JMR Software (Pty) Ltd · Gauteng
Posted 29 July 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
Own and operate the security posture of the Client's endpoint estate including
corporate and BYOD devices using Microsoft Intune, SCCM/MECM and Defender
for Endpoint. Ensure that all user devices meet compliance, hardening and patch
requirements, and that BYOD usage is governed in a way that protects corporate
data without unnecessary friction for end users.
Duties & Responsibilities
Key Responsibilities
- Design, implement and maintain Intune policies for Windows, macOS,
mobile and tablet devices: configuration profiles, compliance policies, App
Protection Policies (MAM) and security baselines.
- Manage SCCM/MECM for patch deployment, software distribution and
configuration management; lead workload migration to modern Intune based management where appropriate.
- Implement and manage BYOD security controls: App Protection Policies,
conditional access device requirements, device registration rules, and
MAM/MDM tiering to protect corporate data on personal devices.
- Configure and tune EDR, antivirus, disk encryption (BitLocker), firewall and
device hardening policies via Intune and Defender for Endpoint, aligned to
CIS and Microsoft security benchmarks.
- Monitor endpoint and BYOD compliance health; respond to non-compliant
devices; work with EUC and help desk teams to remediate issues and reduce
attack surface.
- Support incident response for endpoint-related security events: device
isolation, forensic artefact collection and remediation coordination.
- Produce regular reports on device compliance, patch levels and BYOD
adoption for cyber leadership, audit and Group stakeholders.
- Contribute to Zero Trust endpoint posture by aligning device compliance
signals with Conditional Access and IAM policies in collaboration with the
IAM Security Engineer.
Desired Experience & Qualification
Scope Boundaries
- EUC and help desk teams retain operational ownership of the device estate;
this role provides security configuration, policy governance and security
escalation.
- Conditional Access policies that are identity-driven are owned in
coordination with the IAM Security Engineer.
- Strategic device procurement and EUC tooling investment decisions remain
with IT management.
Decision Rights
- Recommend and implement endpoint security configurations, compliance
policies and BYOD controls within delegated authority.
- Escalate devices presenting material security risk or persistent noncompliance to cyber leadership and the Senior M365/Azure Lead.