Staff Endpoint Security Engineer & Endpoint Platform Lead

Jose Luis Lopez

Securing global fleets, end to end.

I build, secure, and scale enterprise endpoint platforms, currently a global fleet of more than 150,000 devices across macOS, Windows, iOS, and Android. I work at the implementation layer: hardening baselines shipped as version-controlled configuration, device posture wired into Entra ID conditional access as a trust gate, and automation that replaces manual device operations.

13
Years in enterprise mobility and endpoint
150K+
Devices across macOS, Windows, iOS, Android
100K
Endpoints migrated, zero disruption
About

The person who owns the hard endpoint problem

Across thirteen years I have built, secured, and scaled enterprise endpoint platforms. Today I lead endpoint platform engineering for a global fleet of over 150,000 devices, with ownership across Microsoft Intune, Jamf Pro, Entra ID conditional access, device compliance, host hardening, vulnerability remediation, automation, and incident response.

I lead a team of eleven engineers across Apple and enterprise mobility services, setting technical direction while staying hands-on in the code and the consoles, close enough to write the policy, harden the host, and lead the room when something breaks at scale. I bring people along rather than dictating to them, and I would rather grow an engineer than escalate past one.

I am known for turning complex endpoint, identity, and Zero Trust requirements into practical platform standards that reduce risk, improve compliance visibility, and keep the user experience clean.

Security, Risk, Infrastructure, and business teams trust me to own difficult endpoint problems from strategy through execution. I size controls to real risk, prove outcomes rather than effort, and measure what I ship.

I treat AI as part of the toolchain, not a novelty. Claude, Copilot, and ChatGPT are a daily part of how my team generates and refactors scripts, reviews code, triages logs, and keeps documentation current, and I set the norms for how AI-generated code gets reviewed before it merges.

At a glance

Based inFort Lauderdale, FL
AvailabilityOpen to USA Remote
Leads11 engineers
FocusEndpoint & Identity
Also buildingPermitOps.ai
CertifiedAWS Cloud Practitioner
Experience

Where I have done the work

2023 — Present
GE Aerospace · Miami, FL
Endpoint Security Engineer / Endpoint Platform Lead
GE Aerospace

Technical lead for enterprise endpoint platforms serving a global fleet of more than 150,000 devices. Lead a team of eleven engineers across Apple and enterprise mobility services, owning engineering direction across device management, identity integration, conditional access, hardening, automation, and escalation while staying hands-on in the code and the consoles.

  • Corporate separation (~100,000 endpoints). Technical lead for the endpoint workstream of a Fortune 500 separation, standing up a greenfield Intune, Jamf Pro, and Entra ID environment and migrating macOS, Windows, iOS, and Android devices over a six-to-eight-month window with no unplanned service disruption. Owned tenant-to-tenant migration design, Apple Business Manager token and ADE re-assignment, Autopilot re-registration, and the rebuild of compliance and conditional access policy from zero.
  • Team leadership. Lead a team of eleven engineers across Apple and enterprise mobility services, covering hiring, mentorship, design and code review, and ownership of the standards the team builds against.
  • Conditional access as a device trust gate. Designed and operate the Entra ID conditional access policy set that admits only encrypted, patched, and policy-compliant devices to corporate resources, each staged through report-only mode and progressive user rings before enforcement, with break-glass and exclusion handling documented.
  • Hardening baselines as code. Authored macOS and Windows hardening baselines mapped to CIS Level 1 and the macOS Security Compliance Project, delivered as version-controlled .mobileconfig profiles and Intune settings-catalog policies, with a documented exception path and automated drift detection.
  • Custom compliance signals. Built Intune compliance policies plus custom detection scripts in PowerShell and shell that evaluate FileVault and BitLocker state, OS build, patch age, and configuration posture, then publish results back to Entra ID as the signals conditional access decisions rely on.
  • Jamf posture instrumentation. Wrote Jamf Pro extension attributes and smart group logic to expose posture data Jamf does not report natively, including patch age, security agent health, and profile drift, enabling automatically scoped remediation instead of manual triage.
  • Cross-platform inventory reconciliation. Built PowerShell tooling against the Microsoft Graph and Jamf Pro APIs that reconciles device records across Intune, Jamf, and Entra ID on a schedule, auto-remediating stale, duplicate, and orphaned objects and retiring a standing manual cleanup process.
  • Self-healing endpoints. Authored Intune remediation packages, paired detection and remediation scripts that correct common misconfigurations before they ever generate a helpdesk ticket.
  • CI/CD for endpoint configuration. Moved policy, scripts, and packages into Azure DevOps Repos under Git with branch policies and PR review, and built YAML pipelines that validate changes, deploy to a pilot ring, and promote to production, replacing untracked console edits with an auditable release process.
  • Vulnerability remediation pipeline. Designed the fleet remediation workflow that joins exposure data against device inventory and business-impact tiers to generate prioritized patch rings, driving critical patches to roughly 80 percent fleet coverage within five days with closed-loop verification.
  • Application and agent delivery. Own packaging and release for business applications and security tooling across Intune and Jamf, covering Win32 and PSADT packaging, macOS pkg signing and notarization validation, phased ring assignment, required versus available scoping, and tested rollback paths.
  • Major incident escalation. Senior escalation engineer for endpoint major incidents. Lead root-cause analysis across identity, network, and platform boundaries and convert findings into permanent policy changes and detections rather than one-off fixes.
  • Platform KPIs. Define and track endpoint platform metrics jointly with Security and Risk, using the data to right-size controls against real user impact and to evidence compliance posture over time.
2018 — 2023
General Electric · Miami, FL
Mobility & Endpoint Enterprise Engineer
General Electric (Corporate)

Built and governed global endpoint and mobility platforms across multiple GE business units.

  • Enterprise Intune governance model. Defined the policy naming, scoping, ring, and compliance-baseline standards adopted across multiple GE business units, the same model that later survived the separation into GE Aerospace.
  • Compliance visibility. Built the reporting path that turned raw device state into fleet-wide posture metrics for Security and Risk, replacing per-team spreadsheet pulls with a single source of truth.
  • Control alignment with audit. Partnered with Information Security and Risk to translate enterprise audit requirements into enforceable device controls, and to right-size controls where the audit language and the technical reality diverged.
  • Lifecycle standardization. Consolidated enrollment-through-retirement processes that had diverged by region into one documented baseline used by both support and engineering.
  • Risk-managed release. Reviewed and approved endpoint platform changes through change advisory, defining rollback criteria and blast-radius limits for each release.
2013 — 2018
BlackBerry Limited · Sunrise, FL
Enterprise Analyst — Mobility Platforms & Incident Leadership
BlackBerry Limited

Led global escalation operations for enterprise mobility and secure communication platforms serving financial and government clients.

  • Global escalation authority. Senior technical escalation point for enterprise mobility and secure communication platforms serving financial and government customers, owning root cause on infrastructure performance and platform stability incidents.
  • MTTR reduction. Cut mean time to resolution by roughly 25 percent by building structured escalation playbooks, diagnostic runbooks, and log-analysis procedures adopted across the global support organization.
  • Customer architecture advisory. Advised enterprise customers on platform resilience, capacity, and operational stability for production deployments under load.
Projects

What I build outside the day job

Live SaaS · Founder

PermitOps.ai

Permit intelligence for South Florida contractors
24
Permit types
3
Cities covered
Live
In production

A live platform that helps contractors navigate building permits across Fort Lauderdale, Miami, and Tampa. It centers on local depth and rejection prevention, turning jurisdiction specific rules into clear, actionable guidance.

I designed and built the whole thing: data schema, application logic, payments, email automation, and analytics, shipping it end to end as a solo founder.

Notion Softr Stripe Brevo Zapier GA4
Visit PermitOps.ai

Personal Portfolio

This site. A single page, hand built, no framework, with a serif display face, dark mode, and a grid texture. Hosted on a static deploy.

HTMLCSSVanilla JS
Live

Endpoint Automation Toolkit

PowerShell and Bash automation built against the Microsoft Graph and Jamf Pro APIs for provisioning, hardening, inventory reconciliation, and compliance reporting, version controlled and released through Azure DevOps as configuration as code.

PowerShellBashGraph APIAzure DevOps
In production
Capabilities

Core competencies

Languages & APIs

PowerShellBash / zshMicrosoft Graph APIJamf Pro APIREST / JSONYAMLXML / plistPester

Endpoint & MDM

Microsoft IntuneJamf ProMobileIron / IvantiApple Business ManagerAndroid EnterpriseAutopilotADE

Identity & Zero Trust

Microsoft Entra IDConditional access designDevice complianceDevice trust & postureRisk-based accessIdentity Protection

Security Engineering

CIS BenchmarksmacOS Security Compliance ProjectFileVault & BitLockerPatch & configuration complianceDrift detectionHost hardening baselines

Endpoint Security Tooling

EDRDLPSecure browserSecurity agent healthAttack surface reductionVulnerability remediation

Delivery & Tooling

Azure DevOps Repos & PipelinesGit branching & PR reviewCI/CD for endpoint config.mobileconfig authoringWin32 / PSADT packagingpkg signing & notarization

AI-Assisted Engineering

Claude & Claude CodeChatGPT / OpenAI APIGitHub CopilotMicrosoft 365 CopilotGoogle GeminiAI code review standards

Leadership

Team lead, eleven engineersHiring & mentorshipDesign & code reviewMajor incident commandKPI definitionStakeholder alignment

Cloud

AWS Cloud PractitionerAzure DevOpsHybrid infrastructure
Credentials

Education and certifications

B.S. Computer Science and Technology

Undergraduate degree program
Ongoing, expected 2028

AWS Certified Cloud Practitioner

Amazon Web Services
Issued March 2025
Contact

Let's build something secure.

Whether it is a staff level endpoint security role, a hard platform problem, or a conversation about what I am building, I would be glad to hear from you.