Intune, EUC & BYOD Security Engineer

JMR Software (Pty) Ltd · Gauteng

Posted 29 July 2026

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

Own and operate the security posture of the Client's endpoint estate including

corporate and BYOD devices using Microsoft Intune, SCCM/MECM and Defender

for Endpoint. Ensure that all user devices meet compliance, hardening and patch

requirements, and that BYOD usage is governed in a way that protects corporate

data without unnecessary friction for end users.

Duties & Responsibilities

Key Responsibilities

  • Design, implement and maintain Intune policies for Windows, macOS,

mobile and tablet devices: configuration profiles, compliance policies, App

Protection Policies (MAM) and security baselines.

  • Manage SCCM/MECM for patch deployment, software distribution and

configuration management; lead workload migration to modern Intune based management where appropriate.

  • Implement and manage BYOD security controls: App Protection Policies,

conditional access device requirements, device registration rules, and

MAM/MDM tiering to protect corporate data on personal devices.

  • Configure and tune EDR, antivirus, disk encryption (BitLocker), firewall and

device hardening policies via Intune and Defender for Endpoint, aligned to

CIS and Microsoft security benchmarks.

  • Monitor endpoint and BYOD compliance health; respond to non-compliant

devices; work with EUC and help desk teams to remediate issues and reduce

attack surface.

  • Support incident response for endpoint-related security events: device

isolation, forensic artefact collection and remediation coordination.

  • Produce regular reports on device compliance, patch levels and BYOD

adoption for cyber leadership, audit and Group stakeholders.

  • Contribute to Zero Trust endpoint posture by aligning device compliance

signals with Conditional Access and IAM policies in collaboration with the

IAM Security Engineer.

Desired Experience & Qualification

Scope Boundaries

  • EUC and help desk teams retain operational ownership of the device estate;

this role provides security configuration, policy governance and security

escalation.

  • Conditional Access policies that are identity-driven are owned in

coordination with the IAM Security Engineer.

  • Strategic device procurement and EUC tooling investment decisions remain

with IT management.

Decision Rights

  • Recommend and implement endpoint security configurations, compliance

policies and BYOD controls within delegated authority.

  • Escalate devices presenting material security risk or persistent noncompliance to cyber leadership and the Senior M365/Azure Lead.
Auto-apply to this jobView original posting ↗
Intune, EUC & BYOD Security Engineer at JMR Software (Pty) Ltd — Gauteng · JobAlertsZA