Principal Architect, IT Corporate Services

Remote, New York

Principal Architect, IT Corporate Services

  • Remote, New York
  • Full time
  • Opening on: Sep 14 2026
View favorites

The Principal Architect serves as the enterprise technology owner and principal architect for all endpoint computing and enterprise mobility services across Ascensus. This role is the senior technical authority for End User Computing, Endpoint Engineering, Modern Endpoint Management, and Enterprise Mobility Services and is responsible for defining and executing the enterprise endpoint strategy while maintaining ongoing operational ownership of the platforms, processes, standards, and technologies that support approximately 7,500 Windows, macOS, and mobile endpoints. The Principal Architect provides architectural leadership and technical governance for Microsoft Intune, Windows Autopilot, Apple Business Manager, Entra ID device registration, NinjaOne, Addigy, operating system standards, Group Policy, endpoint configuration baselines, device provisioning, software distribution, patching, application packaging, hardware and peripheral standards, endpoint lifecycle management, and enterprise mobility. The role leads through technical influence and coordination with internal teams and service providers and serves as the final technical escalation point for complex endpoint engineering issues. 

 

Section 2: Job Functions, Essential Duties and Responsibilities 

Endpoint Architecture and Strategy 

• Develop and execute the enterprise endpoint architecture strategy, standards, governance, and technology roadmaps for Windows, macOS, and mobile platforms. 

• Own Windows and macOS operating system standards, upgrade planning, feature adoption, and endpoint configuration baselines. 

• Lead endpoint technology planning and execution for acquisitions, divestitures, office openings and consolidations, migrations, and large-scale device refreshes. 

Modern Endpoint Management 

• Serve as technical owner for Microsoft Intune and the overall Modern Endpoint Management strategy, including architecture, design, implementation, governance, optimization, and operational ownership. 

• Own Windows Autopilot, Apple Business Manager, Entra ID device registration, NinjaOne, Addigy, and related endpoint management technologies. 

• Design and maintain endpoint enrollment, zero-touch provisioning, imaging, software distribution, patching, and device-management processes across supported platforms. 

• Drive adoption of cloud-based endpoint management and automation while ensuring solutions remain secure, scalable, supportable, and aligned with enterprise requirements. 

Endpoint Engineering and Configuration Management 

• Design, test, implement, and govern end-user Group Policies in Active Directory and establish consistent enterprise endpoint configuration standards. 

• Serve as the final technical escalation point for complex desktop engineering, application packaging, imaging, patching, Group Policy, software distribution, device enrollment, and endpoint-management issues. 

• Own application packaging and compatibility standards; coordinate testing and implementation activities performed by Desktop Support and service provider teams. 

• Provide technical direction to internal teams and service providers without direct supervisory responsibility. 

Enterprise Mobility Services 

• Establish and maintain the enterprise mobility strategy, standards, governance model, and technology roadmap for corporate mobile phones and tablets. 

• Serve as the primary technology and vendor owner for T-Mobile, including service planning, escalations, technology evaluation, rate-plan and device-standard input, and roadmap alignment in partnership with Procurement. 

• Define standards for mobile devices, operating systems, accessories, enrollment, eSIM, zero-touch provisioning, refresh, replacement, recovery, and retirement. 

• Partner with Cybersecurity and operational teams to align mobility services with security, compliance, risk, and business continuity requirements. 

Security and Risk Partnership 

• Coordinate with Cybersecurity to design and implement endpoint security controls through Group Policy, Intune, and operating system configurations. 

• Own BitLocker administration and governance while partnering with Cybersecurity on vulnerability remediation and Zero Trust initiatives. 

• Participate in major incidents and security incidents involving endpoints, providing technical leadership for investigation, containment, remediation, and recovery activities. 

• Contribute technical expertise to endpoint observability, compliance reporting, audit support, and operational metrics without serving as the primary owner of those functions. 

Hardware, Vendor, Asset Lifecycle, and Licensing 

• Lead evaluation, testing, selection, standardization, and lifecycle planning for enterprise laptops, desktops, mobile devices, peripherals, docking stations, and related end-user technologies. 

• Serve as the primary technology owner for strategic endpoint hardware vendors, including Dell, Apple, and other providers; participate in vendor evaluations and contract negotiations in partnership with Procurement. 

• Own the complete endpoint lifecycle, including deployment, refresh, recovery, secure disposition, and selection and oversight of asset recovery and eWaste vendors. 

• Manage licensing and technology governance for endpoint software such as Adobe Acrobat, Snagit, and other end-user applications. 

Automation and Continuous Improvement 

• Develop and maintain PowerShell and other scripting solutions for endpoint provisioning, administration, software deployment, patching, remediation, and operational automation. 

• Advance automation and standardization to reduce manual effort and improve the reliability, scalability, and consistency of endpoint operations. 

• Evaluate emerging endpoint and mobility technologies, lead pilots, and recommend solutions that improve security, supportability, productivity, and associate experience. 

 

Supervision   

• No direct supervisory responsibilities are required in this position. 

• Provides enterprise-wide technical leadership and architectural guidance for End User Computing, Endpoint Engineering, Modern Endpoint Management, and Enterprise Mobility Services. 

• Leads through technical influence and coordination with Desktop Support, Service Desk, Infrastructure, Cybersecurity, Procurement, and third-party service providers. 

• Serves as technology owner for endpoint management platforms, enterprise mobility services, hardware standards, endpoint lifecycle services, software licensing, and strategic vendor relationships. 

 

Section 3:  Experience, Skills, Knowledge Requirements  

• Education: Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent relevant experience. A master’s degree is preferred. 

• Extensive Experience: At least 10 years of progressive information technology experience, including substantial experience in endpoint architecture, desktop engineering, endpoint management, or End User Computing technical leadership. 

• Large-Scale Endpoint Expertise: Demonstrated experience supporting large enterprise environments across Windows, macOS, and mobile platforms, including endpoint standards, operating system lifecycle management, configuration baselines, application packaging, software distribution, patching, imaging, and provisioning. 

• Modern Endpoint Management: Deep hands-on knowledge of Microsoft Intune, Windows Autopilot, Apple Business Manager, Entra ID device registration, Group Policy, BitLocker, and endpoint management platforms such as NinjaOne and Addigy. 

• Scripting and Automation: Strong PowerShell scripting skills are required. Experience using APIs and other automation frameworks to improve endpoint provisioning, deployment, management, remediation, and operational efficiency is preferred. 

• Enterprise Mobility: Experience establishing mobile device standards, managing carrier and vendor relationships, and governing mobile enrollment, provisioning, lifecycle, and support technologies. 

• Vendor and Lifecycle Management: Experience serving as a technology owner for strategic vendors and managing hardware standards, refresh programs, software licensing, asset recovery, secure disposition, and eWaste services in partnership with Procurement and operational teams. 

• Security Partnership: Experience implementing endpoint security controls and partnering with Cybersecurity on vulnerability remediation, encryption, security incidents, audits, and Zero Trust initiatives. 

• Leadership and Communication: Excellent organization, analytical, decision-making, communication, and interpersonal skills. Demonstrated ability to influence technical direction, coordinate across teams and service providers, and explain complex concepts to technical and business stakeholders. 

• Certifications: Relevant endpoint administration and management certifications are preferred but not required, including Microsoft endpoint or Microsoft 365 certifications, Apple device management certifications, ITIL, NinjaOne, Addigy, or comparable credentials. 

• Availability: Ability to participate in scheduled non-business-hour implementation and maintenance activities and in major incident or security incident response when required. 

Be aware of employment fraud. All email communications from Ascensus or its hiring managers originate from @ascensus.com or @futureplan.com email addresses. We will never ask you for payment or require you to purchase any equipment. If you are suspicious or unsure about validity of a job posting, we strongly encourage you to apply directly through our website.

For all virtual remote positions, in order to ensure associates can effectively perform their job duties with no distractions, we require an uninterrupted virtual work space and there is also an expectation of family care being in place during business hours. Additionally, there is an internet work speed requirement of 25 MBps or better for individual use. If more than one person is utilizing the same internet connection in the same household or building, then a stronger connection is required. If you are unsure of your internet speed, please check with your service provider. Note: For call center roles specifically, it is a requirement to either hardwire your equipment directly to the internet router or ensure your workstation is in close proximity to the router. Please ensure that you are able to meet these expectations before applying. No associate is permitted to work at a location outside the United States for any length of time, except for approved business travel on a limited basis. Exempt Associates traveling outside the United States on personal travel or while on PTO may work on a limited basis (e.g., occasionally checking and responding to business-critical emails or dialing into business-critical meetings) from their personal devices but not from a company-provided computer.

Ascensus provides equal employment opportunities to all associates and applicants for employment without regard to ancestry, race, color, religion, sex, (including pregnancy, childbirth, breastfeeding and/or related medical conditions), gender, gender identity, gender expression, national origin, age, physical or mental disability, medical condition (including cancer and genetic characteristics), marital status, military or veteran status, genetic information, sexual orientation, criminal conviction record or any other protected category in accordance with applicable federal, state, or local laws (“Protected Status”).