Desktop Engineering Lead - Endpoint Security
$110k - $188kT. Rowe Price
Desktop Engineering Lead - Endpoint Security
Apply (
locations
Owings Mills, MD
time type
Full time
posted on
Posted 22 Days Ago
job requisition id
80979
At T. Rowe Price, we identify and actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.
We believe doing the right thing for our clients and our associates is good business . With a career at the firm, y ou can expect opportunities to create real impact at work and in your community. Y ou’ll enjoy resources to support your career path, a s well as compensation , benefits , and flexibility to enrich your life. Here, you’ll find a collaborative culture that respect s and valu e s differences and colleagues who share a spirit of generosity .
Join us for the opportunity to g row and make a difference in ways that matter to you .
Role Summary
We are seeking a Lead Desktop Engineer to own the technical direction, operational health, and security posture of our endpoint environment across approximately 14,000 managed devices. This role serves as the senior technical authority for endpoint engineering, operations, and security—ensuring consistent design, execution, and control ownership in a regulated enterprise environment.
The Desktop Engineering Lead will be accountable for endpoint compliance, vulnerability remediation, configuration standards, and high‑risk technical decision‑making. This role partners closely with Security, Infrastructure, Risk, and Audit teams to reduce operational risk, maintain audit readiness, and deliver a stable, secure end‑user computing platform.
Responsibilities
Endpoint Engineering & Platform Ownership:
Serve as the technical lead for endpoint engineering, operations, and security across ~14k devices, ensuring standardized design, implementation, and enforcement.
Own the endpoint management stack, including Intune, MECM (SCCM), Microsoft Defender, Entra ID, and related tooling.
Define and maintain endpoint architecture, configuration baselines, and OS lifecycle standards in alignment with security and regulatory requirements.
Security, Risk & Compliance:
Own endpoint health and compliance, including patching, OS upgrades, configuration baselines, device posture, and conditional access enforcement.
Own application control capabilities, including Windows Defender Application Control (WDAC), to enforce secure execution policies and reduce endpoint risk.
Provide decision authority for high‑risk endpoint changes (patching, policy updates, security remediations), minimizing the risk of misconfiguration or large‑scale impact.
Ensure timely remediation of vulnerabilities and adherence to firm‑defined SLAs, reducing exposure windows and maintaining audit readiness.
Enforce secure baseline configurations and compliance controls across all managed endpoints.
Operations & Vulnerability Management:
Partner with Security and Vulnerability Management teams to prioritize, plan, and execute endpoint remediation activities.
Ensure endpoint controls and processes are measurable, defensible, and auditable.
Act as the escalation point for complex or high‑impact endpoint incidents, driving root cause analysis and long‑term corrective actions.
Automation & Continuous Improvement:
Drive operational efficiency through automation, standardization, and reduction of manual processes.
Improve consistency, reliability, and scale of endpoint operations through policy‑driven management and modern endpoint practices.
Identify opportunities to modernize endpoint engineering practices and tooling while maintaining regulatory compliance.
Leadership & Collaboration:
Provide technical mentorship and leadership within the desktop/endpoint engineering team.
Collaborate with L1/L2 support, infrastructure, identity, security, and audit partners to ensure clear ownership and smooth execution.
Translate technical risk and trade‑offs into clear, actionable recommendations for leadership.
Qualifications
Required:
BS or MS degree (or equivalent experience) and 8+ years of experience in endpoint engineering, EUC, or desktop platform management within a large enterprise environment.
Deep hands‑on expertise with Intune, MECM (SCCM), Microsoft Defender, Entra ID, and Windows endpoint security controls.
Strong experience operating in regulated environments (financial services, healthcare, highly regulated enterprise).
Proven ownership of endpoint patching, vulnerability remediation, OS lifecycle, and compliance controls at scale.
Demonstrated experience serving as a technical decision authority for high‑risk or high‑impact changes.
Strong understanding of Zero Trust principles, device posture, and conditional access.
Excellent troubleshooting and root cause analysis skills for complex endpoint issues.
Preferred:
Experience supporting environments with 10k+ endpoints.
Familiarity with audit, risk, and compliance frameworks impacting endpoint controls.
Experience driving automation and standardization initiatives (PowerShell, policy‑as‑code, reporting, etc.).
Hands-on experience with Intune, MECM (SCCM), Microsoft Defender, Entra ID, and Windows endpoint management.
Strong communication skills with the ability to engage security, audit, and senior leadership audiences.
What This Role Is
Atrue accountability owner for endpoint health, compliance, and security.
A senior technical authority trusted to make risk‑based decisions.
A bridge between engineering, operations, and security.
What This Role Is Not
A ticket‑driven desktop support role.
A purely strategic role without hands‑on ownership.
A delegated or advisory‑only position without decision authority.
FINRA Requirements
FINRA licenses are not required and will not be supported for this role.
Work Flexibility
This role is eligible for hybrid work, with up to three days per week from home.
Base Salary Ranges
Please review the job posting for the location of this specific opportunity.
$110,000.00 - $188,000.00 for the location of: Maryland, Colorado, Washington and remote workers$121,000.00 - $207,000.00 for the location of: Washington, D.C.$138,000.00 - $236,000.00 for the location of: New York, California
Placement within the range provided above is based on the individual’s relevant experience and skills for the role . Base salary is only one component of our total compensation package . Employees may be eligible for a discretionary bonus, which is determined upon company and individual performance.
Commitment to Diversity, Equity,andInclusion
At T. Rowe Price, our associates are our greatest asset. We thrive because our company culture is built on inclusion and because we sustain a work environment where associates can bring their best selves to work every day. The backgrounds, talents, and experiences of our global associates allow us to embrace new ideas and perspectives that move our business priorities forward and enable us to deliver strong client outcomes. Here, you can expect equal opportunity and fair and consistent treatment for all.
Benefits
We value your goals and needs, at work and in life. As an associate, you’ll be supported with resources , benefits , and work-life balance so you can thrive in ways that matter to you .
Featured employee benefits to enrich your life:
Competitive compensation
Annual bonus eligibility
A generous retirement plan
Hybrid work schedule
Health and wellness benefits, including online therapy
Paid time off for vacation, illness, medical appointments, and volunteering days
Family care resources, including fertility and adoption benefits
Learn more about our benefits. (
T. Rowe Price is an equal opportunity employer and values diversity of thought, gender, and race. We believe our continued success depends upon the equal treatment of all associates and applicants for employment without discrimination on the basis of race, religion, creed, color, national origin, sex, gender, age, mental or physical disability, marital status, sexual orientation, gender identity or expression, citizenship status, military or veteran status, pregnancy, or any other classification protected by country, federal, state, or local law.
Similar Jobs (1)
Lead Workplace Experience Engineer - Power Platform
locations
Owings Mills, MD
time type
Full time
posted on
Posted 22 Days Ago
About Us
T. Rowe Price is an asset management firm focused on delivering global investment management excellence and retirement services that investors can rely on–now, and over the long term.
Not ready to apply? Join our Talent Community ( !
Read More
- ...seeking an experienced IT professional to lead modernization and automation initiatives... ...end-user experiences, managing desktop services, and leading automation efforts... ...Computer Science, extensive experience in IT engineering, and a background in regulated industries...Suggested
- T. Rowe Price is actively seeking a Lead Desktop Engineer in Owings Mills, Maryland. This pivotal role centers on managing the security and operational compliance of around 14,000 endpoints within a regulated environment. As part of the endpoint engineering team, you will...Suggested
$159k - $272k
...Principal Desktop Engineer Apply ( locations Owings Mills, MD... ...leader responsible for both leading and actively contributing to... ...and operation of enterprise endpoint platforms. This role combines... ...are accountable for endpoint security posture, OS lifecycle compliance...SuggestedFull timeContract workLocal areaRemote work3 days per week$110k - $188k
...and make a difference in ways that matter to you.Role SummaryWe are seeking a Lead Desktop Engineer to own the technical direction, operational health, and security posture of our endpoint environment across approximately 14,000 managed devices. This role serves as the...SuggestedLocal areaRemote workWork from home3 days per week- ...with deeper AWS knowledge on services, security postures and network specific services such... ...Senior Technical Project Manager to lead and coordinate a team of infrastructure... ...with architecture, Information security, engineering, and operations teams including support...SuggestedContract work
$60 - $70 per hour
...Senior Infrastructure Engineer - Linux, Ansible Location: Owings... ...Enterprise grade Linux developer desktop pre-baked with tools and... ...Monitor and maintain Linux endpoints, enterprise software solutions... ...infrastructure, network, storage, and security teams to resolve issues,...Contract workWork visaShift work3 days per week- ...Asset Management Team - Desktop Operations This resource will be assisting in managing the lifecycle of client devices Requirements: ServiceNow is preferred Excel- spreadsheets for tracking purposes Inventory Operations experience Attention to detail...
$30 - $37 per hour
...About the Role: As an IT Desktop Technician at TAI Engineering, you will serve as the backbone of our daily... ...-level network configurations and security deployments to providing direct,... ...real impact on a variety of industry-leading projects. The ability to balance...Hourly payTemporary workWork at officeLocal areaRemote workHome officeMonday to FridayFlexible hours$98.9k - $148.3k
...is our commitment to missions. In rapidly changing global security environments, Northrop Grumman brings informed insights and... ...including coordination with network, software, and system engineers, PC desktop technicians, project managers, end users, and customer and...Full timeContract workRelocation packageFlexible hoursShift workWeekend work- HCLTech is seeking a Senior IT Field/Desktop Support Engineer in Towson, Maryland. The role involves providing hands-on IT support, troubleshooting desktop and mobile systems, and adhering to SLAs for incident resolution. Candidates should have a minimum of 7 years of...
- Model Based Systems Engineering Lead Towson, MD(Onsite) Fulltime Required Qualifications Bachelor's or master's degree in systems engineering, Engineering (Mechanical/Electrical/Software), Computer Science, or related discipline INCOSE, OMG, or equivalent certifications...Full time
- ...Knowledge of different probes (Ex. CDM, apache, others...) • Knowledge of how to adjust alerting thresholds • Apply / remove security patches on Solaris 10 and 11 • Apply / remove patches on Linux (Red Hat) • knowledge of Solaris Ops Center a plus • Thoroughly...
- ...Desktop Systems Administrator I - Exempt End Client T-Rowe Price Location Owings Mills, MD Visa – H1B The Desktop Systems Administrator... ...infrastructure Previous application packaging, preference is with MSI based packages Microsoft Certified Systems Engineer preferred...Work experience placementH1bWork at office
- System Administrator Location – Owings Mills, Maryland (Hybrid – 2 days in a week onsite and 3 days remote) 6-7+ years of experience Team supports and administers UIM platform and other windows/Linux platforms. Management and administration and monitoring...Remote work2 days per week
- Systems Administrator The main function of a Systems Administrator is to be responsible for system administration of core systems as well as monitoring and repair of high performance computing systems. Ensures consistent and reliable operation including enterprise servers...
- ...ePMO Human Resources Planning, Control, And Reporting by identifying, planning, developing, testing, implementing, maintaining, and securing Project Portfolio Management system (PPM) solutions. Facilitate and coordinate building, document, and review of system, and data...Work experience placement
- Production Support Analyst Location: Owings Mills, MD. Duration: Contract Rate: Doe Citizen and GC Preferred | C2C available Required Skills: ~ Bachelors in Computer Science, Information Systems/Technology, Business, or equivalent work experience ~3 to 5+ ...Contract workWork experience placement
- ...effectiveness of business units in performing their essential functions. The PSA also: Participates in re-platforming and re-engineering efforts essential to ongoing system support, staying abreast of business and technological changes. Documents requirements due to...
- Towson University is seeking a Systems Administrator to support desktop and server services within the Solutions Engineering group. Responsibilities include troubleshooting complex issues, mentoring staff, and maintaining services like encryption and software deployment...Casual work
$85.9k - $129.7k
A leading aerospace firm in Hunt Valley is looking for a Systems Administrator to support classified information systems. The role involves... ...support, administer systems, and ensure compliance with security regulations. This position is on-site with occasional travel, offering...- ...inquiries, budget management, and supporting PMO on projects related to Mainframe or Cloud technologies, and web services/middleware security. 5+ years of Project Management experience supporting application or web services architecture Excellent communication skills...
- ...advisor for wireless communications, data, and security, is seeking an experienced Technical Project Manager to lead and manage a large-scale, high-impact public... ...project execution. Partner closely with engineering, field service, and operations teams to ensure...Contract workFor contractorsLocal areaRemote work
- ...business. Excellent onboarding and industry‑leading learning culture will set you up for a... ...and distributing system patches to endpoint nodes using BigFix software. About If you... ...implementation, and documenting various security mitigations, fixes and patches with a sense...
- Certified Salesforce Admin Colorado Springs, CO or Owings Mills, MD 6 + Months Onsite Day 1: Hybrid Model: 2 - 3 Days Onsite! This person will need to sit onsite at either Colorado Springs or Owings Mills, under the hybrid model. Top skills: Strong Salesforce ...
$77.5k - $82.5k
...part of the Solutions Engineering (SE) group and is responsible... ...of enterprise desktop and server services.... ...to maintain reliable, secure, and well?documented technology... ...selected desktop and endpoint services, bridging... ...as the technical lead for select Solutions Engineering...Work at officeRemote work2 days per week- ...or educational background (Python, PowerShell, Unix shell, etc.) + ability to write basic SQL statements; solid knowledge of SFTP (secure file transfer protocol). Ability to write basic Splunk queries and investigate application issues through Splunk logs preferred. Cloud...
- Technical Business Analyst Location: Owings Mills MD Duration: 12 Months+ Rate: DOE Interview: Zoom call with Manager + 2 members from his team US citizens and those authorized to work in the U.S are encouraged to apply. We are unable to sponsor at this ...
- ...conversion techniques. Produces and distributes monthly, quarterly, and annual reports, etc. Prepares ad-hoc analysis as requested. Leads and/or participates in department projects as assigned. Researches questions related to report information and calculations....Work experience placement
- ...will be expected to operate, improve, and secure the Corporate IT environment and the... ...product offerings. This includes macOS endpoints, Windows and Linux servers and services,... ...been committed to hiring the industry’s leading professionals, and presenting exciting career...Permanent employmentContract workWork at officeRemote work
- ...Linux Systems Engineer Locations: Owings Mills, MD 21117 OR Baltimore, MD 21202 OR Philadelphia, PA 19103 OR New York, NY 10003 OR... ...support our growing development community on a Linux Developer Desktop offering. Primary skills: Fluent in Linux / Active Directory and...For contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Desktop Engineering Lead - Endpoint Security. Be the first to apply!


