Locatie
Zuid-Holland
Uren per week
32
Maximum tarief
In overleg
Looptijd
07-10-2026 t/m 07-04-2027
Dienstverband
Detachering
Status
Open
Sluit over 6 dagen
Organisatie logo

Omschrijving

The Eindhoven University of Technology (TU/e) is looking for a Workplace Engineer Subject Matter Expert to technically design, build, test and support the rollout of the Secure Modern Workplace initiative within the scope of the Digital Safety Program.

The Secure Modern Workplace project will define, design and implement a future-ready workplace model for TU/e. The project must balance strong central security standards with the specific needs of faculties, researchers, local IT-teams and specialized academic environments. A key objective is to co-create new workplace types with the faculties, including the standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace. The project also includes the rollout of Mobile Device Management and the use of Microsoft capabilities such as Intune, Autopilot, Company Portal, Entra ID, Conditional Access, device compliance and Microsoft Defender for Endpoint.

Role and Responsibilities

The Workplace Engineer SME is responsible for translating the workplace solution design into working technical configurations, builds and rollout-ready workplace types. The role works closely with the Project Manager Secure Modern Workplace, the Program Architect, LIS workplace management, security specialists, local IT and faculty representatives. The objective is to create controlled, automated and service-oriented workplace building blocks that reduce unmanaged risk, improve user experience, enable MDM adoption and lower operational support effort through standardization, automation and clear support boundaries.

  • Translate the approved solution design and architecture principles into technical workplace configurations and reusable service building blocks.
  • Design, build and validate the standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace concepts.
  • Configure and support the rollout of MDM and Microsoft endpoint management capabilities, including Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint.
  • Work with faculties, researchers and local IT teams to validate technical requirements, test workplace types and adapt implementation options where justified.
  • Support pilots and rollout waves, including technical troubleshooting, acceptance testing, user migration support and feedback processing.
  • Document configuration choices, support boundaries, exception logic and operational procedures for handover to the beheer/support teams.
  • Provide knowledge transfer, coaching and practical training to internal engineers and operational teams to enable sustainable in-house ownership.
  • Ensure continuous alignment with the Project Manager Secure Modern Workplace, Program Architect, security baselines, IAM, application packaging and service management processes.

Key Deliverables

  • Approved Technical Work Plan and Build Backlog: A clear technical delivery plan covering build activities, configuration work, testing, dependencies, risks, rollout support and handover milestones, aligned with the project plan.
  • Solution Design Translation: A practical translation of the solution design and architecture principles into technical workplace configurations, policies, profiles, baselines and implementation choices.
  • Standard Secure Workplace Build: A configured and validated standard secure workplace, including device management, security baseline, user experience, application access, Autopilot provisioning and operational support model.
  • Research Workplace Build: A configured and validated research workplace, including device management, security baseline, user experience, application access, Autopilot provisioning and operational support model.
  • Linux and MacOS Workplace Build: A configured and validated Linux & MacOs, including device management, security baseline, user experience, application access, Autopilot provisioning and operational support model.
  • BYOD and MDM Configuration: A technical design and configuration approach for BYOD access, mobile device management, device compliance, enrolment, remote wipe, application access and privacy-sensitive operating principles.
  • Microsoft Endpoint Management Configuration: Configured use of Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint within the target workplace model.
  • Application Deployment and Packaging Support: Technical support for application packaging, scripting, Company Portal publication and light rationalisation of the application landscape.
  • Security Baseline and Compliance Implementation: Implementation of minimum management and security baselines covering device compliance, local admin approach, patching, endpoint protection, vulnerability visibility, logging and monitoring.
  • IAM and Conditional Access Technical Alignment: Technical alignment with IAM, device identity, user identity, RBAC/ABAC principles, conditional access and privileged access requirements.
  • Pilot Build, Test and Evaluation: A completed pilot build with selected faculties or user groups, including test results, lessons learned, refined configurations and recommendations for wider rollout.
  • Rollout Support for Workplace Types: Hands-on technical support during rollout waves, including user migration support, troubleshooting, issue resolution and stabilization activities.
  • Service Building Blocks and Technical Documentation: Technical input for service building blocks, service catalogue descriptions, configuration standards, support levels, responsibilities and operational procedures.
  • Operational Handover and In-Service Transition: A structured handover to beheer/support teams, including documentation, runbooks, known issues, monitoring/reporting routines, support boundaries and acceptance criteria.
  • Knowledge Transfer to Internal Teams: Active knowledge transfer and practical training for internal engineers, support teams and workplace management staff, enabling sustainable operation after the assignment.
  • Architecture and Program Alignment: Continuous alignment with the Program Architect, Project Manager Secure Modern Workplace and wider Digital Safety dependencies such as IAM, security operations, application packaging and service management.

Department and Context

TU/e consists of various departments and faculties where education and research are conducted, supported by several central services. The candidate will work within the Digital Safety Program, primarily with LIS workplace management, end-user services, architecture, security operations, service management and local IT teams. A substantial part of the assignment is to work directly with the Project Manager Secure Modern Workplace, the Program Architect, faculty stakeholders, researchers and local IT teams to translate requirements into technical workplace builds, validate implementation choices and support a smooth transition into the new Secure Modern Workplace support model. The candidate reports to the Project Manager Secure Modern Workplace.

Eisen

  • Extensive hands-on experience with modern workplace engineering, endpoint configuration, device lifecycle management, automation, deployment, remote management and support model redesign
  • Azure fundamentals
  • Azure Administrator Associate
  • Azure Solutions Architect Expert
  • Identity & Access Administrator Associate
  • Understands MDM/MAM concepts, enrolment, device compliance, remote wipe, privacy considerations and the balance between secure access and user flexibility
  • Able to understand and translate requirements for standard secure, research (OT), Linux, MacOS and BYOD workplace types into practical technical designs and implementation options
  • Able to understand solution designs and enterprise architecture principles and translate them into buildable configurations, technical standards and rollout-ready solutions
  • Understands endpoint hardening, local admin reduction, patching, device compliance, vulnerability visibility, logging, monitoring and risk-based exception handling
  • Able to translate technical configurations into reusable service building blocks, service catalogue elements, responsibilities, support boundaries and operating model choices
  • Able to define test scenarios, validate technical readiness, support pilots, solve rollout issues and stabilize workplace types before handover to operations
  • Strong ability to document, explain and transfer technical knowledge to internal engineers and beheer/support teams, including runbooks, configuration logic and support procedures
  • Comfortable working with faculties, researchers and local IT teams to validate technical needs and implementation options in a decentralized and autonomous academic environment
  • Works effectively with the Project Manager Secure Modern Workplace, Program Architect, security specialists, IAM, application packaging and service management teams
  • Balances security, architecture and service objectives with operational feasibility, capacity constraints and the realities of research and faculty environments
  • Communicates complex workplace, security and endpoint management topics in clear, accessible language for both technical and non-technical audiences
  • Experience with scaled agile and Lean working
  • Fluent in English mandatory; Dutch required language for speaking

Over de organisatie

Meer weten over deze organisatie? Lees wie ze zijn en welke opdrachten ze momenteel aanbieden.

Sluit over 6 dagen

Is deze opdracht iets voor jou?

Past jouw ambitie, kennis en talent bij deze opdracht? Schrijf in via de knop.

Vragen over de opdracht?

Neem contact op met onze opdracht adviseur via WhatsApp, of via een van de kanalen hieronder.

Neem contact op
Ja, inschrijven

Word je enthousiast van deze opdracht? Laat het ons weten!

Bij een geschikte match stelt TenTalent je graag voor! We lezen graag hoe jouw CV aansluit bij deze opdracht.

Marge TenTalent

Onze marge voor de dienstverlening is €2,50 van het afgesproken uurtarief.

Professionele ondersteuning

Als ervaren recruitment partner nemen wij het volledige selectie- en administratieve proces voor onze rekening. Jij kunt je volledig concentreren op je vakgebied, terwijl wij zorgen voor optimale matchmaking en professionele begeleiding gedurende de hele opdracht.

Slimme job alerts

Blijf automatisch op de hoogte van relevante opdrachten door onze gerichte e-mail notificaties. Onze slimme matching zorgt ervoor dat je alleen opdrachten ontvangt die aansluiten bij jouw expertise, ervaring en voorkeuren.

1
Contactgegevens
2
Tarief & CV
€ –

incl. €2,50 marge TenTalent

Voer een geldig uurtarief in (alleen cijfers, bijvoorbeeld 85).

Bezig met uploaden...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.
3
Bevestiging

Bedankt voor je inschrijving!

We hebben je gegevens en CV ontvangen. Bij een geschikte match nemen we spoedig contact met je op.

Verzenden mislukt. Probeer het later opnieuw.