Apply now »

Endpoint Engineer

Requisition ID:  49422
Business Unit:  Fitch Group
Category:  Information Technology
Location: 

London, GB

Date Posted:  Jul 1, 2026

Fitch Group is currently seeking a Endpoint Engineer based out of our London office. 

 

As a leading, global financial information services provider, Fitch Group delivers vital credit and risk insights, robust data, and dynamic tools to champion more efficient, transparent financial markets. With over 100 years of experience and colleagues in over 30 countries, Fitch Group’s culture of credibility, independence, and transparency is embedded throughout its structure, which includes Fitch Ratings, one of the world’s top three credit ratings agencies, and Fitch Solutions, a leading provider of insights, data and analytics. With dual headquarters in London and New York, Fitch Group is owned by Hearst.  

  

 Fitch's Technology & Data Team is a dynamic department where innovation meets impact. Our team includes the Chief Data Office, Chief Software Office, Chief Technology Office, Emerging Technology, Shared Technology Services, Technology, Risk and the Executive Program Management Office (EPMO). Driven by our investment in cutting-edge technologies like AI and cloud solutions, we’re home to a diverse range of roles and backgrounds united by a shared passion for leveraging modern technology to drive projects that matter to our organization and clients. We are also proud to be recognized by Built In as a Best Place to Work in Technology 3 years in a row. Whether you're an experienced professional or just starting your career, we offer an exciting and supportive environment where you can grow, innovate, and make a difference.  

  

 

 Want to learn more about a career in technology and data at Fitch? Visit:  

https://careers.fitch.group/content/Technology-and-Data/?locale=en_US

  

  

About the role:

 

The Endpoint Engineer is a key technical contributor within the global infrastructure organization, providing advanced (Tier 2/3) support, endpoint management, and platform engineering across Windows, Microsoft Intune, and related technologies. This role delivers secure, reliable, and frictionless user experiences through modern device management practices, automation, observability, and Zero Trust principles.

 

How You’ll Make an Impact:  

 

Endpoint Platform Engineering (Windows CSP / Intune)

  • Own the migration of legacy Group Policy configurations to modern CSP-based Intune policy, resolving conflicts to protect platform consistency and compliance posture.
  • Design and maintain consolidated, well-governed CSP policy structures across the fleet.

 

Hardware Fleet & Device Lifecycle

  • Drive vendor-led firmware and driver lifecycle management — including HP Image Assist and Dell Command Update automations — to improve device stability and end-user experience.
  • Troubleshoot and remediate audio, video, and conferencing reliability issues.
  • Perform hardware and performance testing/benchmarking to support fleet standardization decisions.

 

Autopilot & Provisioning Modernization

  • Modernize Windows Autopilot and provisioning workflows to reduce legacy dependencies and improve consistency.
  • Resolve drive-mapping dependencies and CSP conflicts affecting the provisioning pipeline.
  • Complete remaining GPO-to-CSP transitions in support of provisioning consistency.

 

Application & Configuration Management

  • Package, test, and deploy enterprise applications using MECM/Intune and modern deployment frameworks, ensuring compliance with internal and regulatory requirements.
  • Collaborate with engineering leadership to design, implement, and operationalize endpoint policies, configurations, and standards in support of global infrastructure initiatives.

 

Developer Tooling & AI Workload Enablement

  • Configure, package, and support core developer tooling across the fleet (VS Code, Python, Git, CLI utilities), balancing developer flexibility with security and compliance standards.
  • Define and support endpoint requirements for AI/ML workloads, including GPU driver management, containerization/WSL2, and local model runtime resource sizing.
  • Partner with engineering and data teams to evaluate, standardize, and roll out AI-assisted developer tools (e.g., Claude Code, Copilot) within governance and device-management guardrails.

 

Operations & Support

  • Deliver advanced incident and problem resolution with a strong focus on user experience and root-cause elimination.
  • Execute recurring operational activities, including patching, vulnerability remediation, compliance reporting, and endpoint health monitoring.
  • Partner closely with the Service Desk to drive continuous improvement, streamline workflows, and reduce recurring issues through automation or policy enhancement.
  • Participate in an on-call rotation to support critical after-hours incidents or high-priority escalations.

 

Documentation & Cross-Functional Collaboration

  • Create and maintain technical documentation, runbooks, and cross-team knowledge resources.
  • Engage in cross-functional project work spanning cloud identity, automation, security hardening, and software lifecycle management.
  • Act as an owner by proactively driving issues to resolution across business  

 

 

You May be a Good Fit if: 

 

3–5+ years in enterprise endpoint engineering or advanced support, with hands-on experience in:

  • Windows 11, Azure AD / Entra ID
  • Microsoft Intune (Endpoint Manager), MECM, and co-management services
  • Active Directory and Directory Services, including Group Policy and RSAT tools
  • Intune configuration and compliance policy management
  • LAPS and least-privilege / privilege elevation models (e.g., Privilege Management)
  • Microsoft 365 Apps deployment, configuration, and update servicing
  • Networking fundamentals (DNS, DHCP, VPN, Proxy)

 

Strong experience with modern Intune management, including:

  • Windows Autopilot (user-driven, pre-provisioning, self-deploying)
  • Zero-touch provisioning and cloud-first imaging strategies
  • Intune application management (Win32, MSI, MSIX, store apps, managed apps)
  • Settings Catalog, Compliance Policies, and Configuration Profiles
  • Device Filters, Dynamic Groups, and scalable targeting strategies
  • Endpoint Analytics and digital experience monitoring (DEX)

 

Hardware validation and lifecycle management, including:

  • Hardware and performance testing/benchmarking to support fleet standardization decisions
  • Firmware and BIOS update management and deployment (e.g., HP, Dell)
  • Wi-Fi driver troubleshooting and remediation across the device fleet
  • 802.1X / WPA2-Enterprise network authentication troubleshooting (EAP-TLS, RADIUS)

 

Proficiency with Windows PowerShell, including:

  • Running, creating, and editing PowerShell scripts
  • Managing system processes and services via PowerShell
  • Understanding basic command syntax and parameters
  • Troubleshooting errors using PowerShell
  • Experience supporting Zero Trust, conditional access, and identity-based access controls.

 

Developer tooling and AI workload support, including:

  • Configuring and troubleshooting VS Code, Python, and common CLI/developer environments
  • Git-based version control workflows
  • Endpoint requirements for AI/ML workloads (GPU drivers, WSL2/containers, local model runtimes, resource sizing)
  • Applying governance and device-management guardrails to developer and AI tooling without blocking productivity
  • Ability to collaborate effectively, communicate clearly, and produce high-quality documentation and runbooks.
  • Demonstrated ownership mindset, with a focus on eliminating root causes and improving user experience.

 

  

 

What Would Make You Stand Out:  

 

  • PowerShell App Deployment Toolkit (PSADT) — creating/modifying deployment scripts, packaging and deploying applications, customizing user prompts, troubleshooting logs, and managing detection/remediation logic.
  • Advanced MECM collection design and query creation.
  • Windows imaging modernization (e.g., Autopilot, zero-touch provisioning, DISM when needed).
  • Familiarity with software packaging technologies (EXE, MSI, MSIX, INTUNEWIN).
  • Experience with third-party patching platforms (e.g., Patch My PC).
  • Strong PowerShell automation expertise and familiarity with Git-based workflows.
  • Experience with vulnerability management tools and endpoint telemetry/observability platforms.
  • Experience supporting local AI/LLM developer tooling (e.g., Claude Code, Ollama, LM Studio) and GPU-accelerated workstations.
  • Microsoft certifications related to Endpoint, Azure, or Security.

  

 

Why Choose Fitch:  

  

  • Hybrid Work Environment: 2 to 3 days a week in office required based on your line of business and location  
  • A Culture of Learning & Mobility: Dedicated trainings, leadership development and mentorship programs designed to ensure that your time at Fitch will be a continuous learning opportunity 
  • Investing in Your Future: Retirement planning, financial wellness and tuition reimbursement programs that empower you to achieve your short and long-term goals 
  • Promoting Health & Wellness: Comprehensive healthcare offerings that prioritize a healthy body & mind 
  • Supportive Parenting Policies: Family-first policies, including a generous global parental leave plan, designed to help you balance career and family life effectively 
  • Dedication to Giving Back: Paid volunteer days and support for community engagement initiatives 

  

  

At Fitch, AI is embedded in how we work every day—supporting smarter decision-making, streamlining workflows, and enabling new ways to create value for our business and clients. Intelligent solutions are increasingly part of our day-to-day operations, helping teams work more efficiently and think differently as we continue to evolve. We’re looking for colleagues who are comfortable operating in an AI-enabled environment—or who are curious, adaptable, and eager to build their AI literacy over time. We value professionals who embrace technology as part of continuous learning and who are committed to using it thoughtfully to enhance how work gets done. 

 

 

Fitch is committed to providing global securities markets with objective, timely, independent and forward-looking credit opinions. To protect Fitch’s credibility and reputation, our employees must take every precaution to avoid conflicts of interests or any appearance of a conflict of interest. Should you be successful in the recruitment process at Fitch Ratings you will be asked to declare any securities holdings and other potential conflicts prior to commencing employment. If you, or your immediate family, have any holdings that may conflict with your work responsibilities, you may be asked to divest yourself of them before beginning work.  

  

 

Fitch is proud to be an Equal Opportunity and Affirmative Action Employer. We evaluate qualified applicants without regard to race, color, national origin, religion, sex, sexual orientation, gender identity, disability, protected veteran status, and other statuses protected by law.  

 

#LI-HYBRID #LI-KC1

Apply now »