Hub International logo
Hub International

784 open roles

Senior End Point Engineer

$130k to $155k

Chicago, ILFull-timePosted Aug 2, 2026

Against the Chicago typical range

Job description

Job Description ABOUT US At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference.

Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence. HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services.

With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions Responsibilities Platform Administration and Fleet Operations Own the day-to-day operation of Ninja. One across approximately 25,000 Windows endpoints on Lenovo standard hardware, covering HUB's 600-plus locations across the United States and Canada Maintain Ninja.

One agent health, version currency, policy assignments, and organization structure across the full fleet Manage the application catalog, application lifecycle, and deployment assignments, ensuring each application has exactly one primary owner across Ninja. One and Intune with no overlap Configure and maintain Autopilot orchestration and provisioning workflows within Ninja.

One Perform quarterly coexistence reviews with EUC, Sec. Ops, and the Tanium platform team to validate agent versions, policy exclusions, Zscaler bypass entries, and catalog ownership Resolve coexistence issues across the stack including Zscaler SSL bypass, Sentinel. One exclusion configuration, Tanium Threat Response exclusions, and Intune Management Extension conflicts Capability Expansion and Approval Program Own the technical documentation and capability justification for each of the six pending Ninja.

One capability approvals, working with Engineering leadership and Security Drive capability activation, policy build, and rollout for each approved module once cleared Build and maintain the application-layer patching program using Ninja. One's 200-plus application patch engine once the Automated Patch Management capability is approved Maintain a clean, properly structured Ninja.

One environment as the hard pre-requisite for production fleet rollout Scripting, Automation, and Runbooks Build and maintain a library of Ninja. One automation scripts in Power. Shell, covering routine maintenance, provisioning, remediation, and compliance enforcement Author and maintain monitoring policies and alert configurations that surface actionable signal without false-positive noise, in coordination with the Nexthink team Collaborate with the DEX team on Amplify remote actions that leverage Ninja.

One scripting and remote action capabilities as part of the L1 ticket deflection program Document all scripts, policies, and runbooks to SOC 2 standard, ensuring every automated action has an associated KB article before scale deployment Data Lake Integration Design, build, and maintain the Ninja. One extraction pipeline to HUB's Microsoft Fabric data lake using the Ninja.

One REST API v2 with OAuth 2.0 client-credentials (monitoring scope only), cursor-based pagination, and updated. After incremental filters Coordinate on entity resolution, joining Ninja. One records to Nexthink records via hardware serial number, hostname, and logged-on user UPN to build the unified golden device record Monitor pipeline health, handle API version changes, implement backoff on rate limits, and maintain extraction schema documentation Maintain monitoring-scope-only credential posture with secrets managed in Azure Key Vault and following SOC 2 credential rotation standards CMDB and Service.

Now Integration Own the Ninja. One to Service. Now CMDB bidirectional sync, ensuring device state, software inventory, and operational changes flow automatically between platforms Resolve CMDB drift and data quality issues in coordination with the Service. Now platform team Maintain IAM compliance on device deletion rights and role-based access controls within the Ninja.

One console Governance, Compliance, and Documentation Maintain Ninja. One documentation to SOC 2 audit standard including access controls, change records, policy history, and exception tracking Support quarterly and annual coexistence audits including end-to-end installation walkthroughs, exclusion accuracy verification, and tabletop troubleshooting exercises Participate in the patching governance RACI contributing EUC endpoint perspective on patch ring design, advancement criteria, and compliance reporting Requirements Four or more years of hands-on experience administering Ninja.

One or a comparable enterprise RMM platform such as Datto RMM, N-able, or Kaseya at scale Deep experience with Ninja. One specifically — policy configuration, monitoring and alerting, scripting and automation, application catalog management, and console administration Strong Power. Shell scripting including production automation, error handling, logging, and integration with external APIs Working knowledge of the Windows endpoint security and management stack with hands-on experience across at least two of the following: Microsoft Intune, Sentinel.

One, Zscaler, Tanium, or equivalent platform Experience with REST API integration including OAuth 2.0 client-credentials flows, cursor-based pagination, incremental filters, and webhook handling Understanding of enterprise patch management principles including ring-based deployment, compliance reporting, and controlled rollback Ability to operate in an enterprise governance environment including change management, RACI-aligned accountability, and audit-facing documentation Nice to Have Direct experience configuring Ninja.

One coexistence with Zscaler ZIA and ZCC including SSL inspection bypass policy and domain allowlisting Experience with the Ninja. One to Service. Now CMDB integration or bidirectional sync from any RMM to a CMDB platform Familiarity with Microsoft Fabric, Azure Data Lake Storage Gen2, or Fabric Data Factory for building REST-based data pipelines Experience operating within a SOC 2 Type II audit framework including evidence collection, access control documentation, and control testing Familiarity with Nexthink Infinity or a comparable DEX platform Experience with Lenovo enterprise hardware and Windows Autopilot provisioning workflows Ninja.

One certification or documented advanced platform training Familiarity with Microsoft Defender for Endpoint and dual-agent management alongside a contracted EDR platform Teamwork and Collaboration Communicate technical concepts clearly to both technical and non-technical stakeholders including Engineering leadership and Security reviewers Work cross-functionally with the EUC, DEX, Sec.

Ops, Tanium, and Service. Now teams to maintain platform boundaries and deliver shared goals Participate actively in team rituals — sprint readouts, retrospectives, and planning sessions — and contribute to a culture of continuous improvement Share knowledge through documentation, internal KB articles, and peer mentoring, holding the standard that every automation ships with a runbook Give and receive constructive feedback in technical design discussions and coexistence reviews Adapt to shifting priorities and support teammates during high-pressure incidents or capability rollouts Unified asset and experience view used for proactive remediation and executive reporting JOIN OUR TEAM Do you believe in the power of innovation, collaboration, and transformation?

Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International , you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.

The expected salary range for this position is $ 130,000 to $155,000 and will be impacted by factors such as the successful candidate’s skills, experience and working location, as well as the specific position’s business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays.

In addition, eligible annual bonuses, equity and commissions may be available for some positions. Department Information Technology Required Experience: 5-7 years of relevant experience Required Travel: Negligible Required Education: Bachelor's degree (4-year degree) HUB International Limited is an equal opportunity employer that does not discriminate on the basis of race/ethnicity, national origin, religion, age, color, sex, sexual orientation, gender identity, disability or veteran's status, or any other characteristic protected by local, state or federal laws, rules or regulations.

E-Verify Program We endeavor to make this website accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the recruiting team HUBRecruiting@hubinternational.com . This contact information is for accommodation requests only; do not use this contact information to inquire about the status of applications.

Description copied from Hub International's careers page. Read the full posting before you apply.

More jobs at Hub International

See all openings at Hub International

More jobs in Chicago

See all jobs in Chicago