About Allogene:
Allogene Therapeutics, with headquarters in South San Francisco, is a clinical-stage biotechnology company pioneering the development of allogeneic chimeric antigen receptor T cell (AlloCAR T) products for cancer and autoimmune disease. Led by a management team with significant experience in cell therapy, Allogene is developing a pipeline of “off-the-shelf” CAR T cell product candidates with the goal of delivering readily available cell therapy on-demand, more reliably, and at greater scale to more patients.
About the role:
We are seeking an experienced Desktop Engineer to manage and support the organization’s endpoint and workplace technology environment across Windows and macOS devices. This role owns day-to-day endpoint operations and helps ensure corporate laptops and desktops remain secure, compliant, patched, reliable, and productive within a Microsoft-centric environment.
The successful candidate will combine strong endpoint engineering skills with a hands-on, customer-focused support approach. This role is a tier 3 escalation.
The role can be based remote or can be based onsite at the South San Francisco offices.
Responsibilities:
Endpoint Management and Configuration
- Administer and maintain enterprise desktop management platforms for Windows and macOS devices without dependency on a single technology or vendor.
- Develop, implement, and maintain device standards, security baselines, configuration profiles, compliance policies, and enrollment settings.
- Manage the complete endpoint lifecycle, including procurement coordination, enrollment, provisioning, deployment, refresh, reassignment, and secure retirement.
- Monitor endpoint health and compliance, investigate configuration drift, and remediate devices that fall outside established standards.
- Automate repeatable deployment and configuration activities using appropriate scripting and administration methods.
Software Deployment and Application Management
- Packaging, testing, deployment, maintenance, and removal of windows/third party applications across supported endpoint platforms. Experience with Microsoft Intune, JAMF, and Automox are considered an additional qualification.
- Maintain standard application catalogs and self-service delivery capabilities where appropriate.
- Coordinate application upgrades, compatibility testing, licensing considerations, and rollout communications.
- Troubleshoot failed installations, application conflicts, performance issues, and deployment errors.
Patch and Vulnerability Management
- Plan and execute operating system, browser, firmware, driver, and third-party application patching based on defined maintenance schedules and risk priorities.
- Monitor patch deployment success, investigate failures, and drive remediation of noncompliant or vulnerable endpoints.
- Coordinate urgent security updates and out-of-band maintenance in partnership with Information Security and Infrastructure teams.
Endpoint Security and Compliance
- Implement and maintain endpoint security settings, including encryption, host firewall, local privilege controls, device restrictions, authentication-related configurations, and approved security baselines.
- Partner with Information Security to investigate endpoint alerts, remediate vulnerabilities, support incident response, and reduce endpoint risk.
- Apply configuration and software changes through documented testing, approval, deployment, validation, and rollback practices.
Microsoft 365 and Identity-Integrated Workplace Support
- Configure and support Microsoft 365 settings that affect endpoint access, productivity, collaboration, device compliance, and the end-user experience.
- Troubleshoot endpoint integration with cloud identity, authentication, productivity applications, collaboration services, email, file access, and device compliance controls.
- Support user onboarding and offboarding activities, including device readiness, application access, licensing coordination, profile configuration, and secure device return.
- Work with Security and Infrastructure teams on access policies, authentication requirements, device trust, and other identity-integrated controls.
New Hire Onboarding Support
- Partner with Human Resources, hiring managers, and the Service Desk to ensure new hire technology needs are identified, ordered, and ready before the employee start date.
- Prepare, image, enroll, and configure new hire laptops, desktops, peripherals, and mobile devices to established standards, security baselines, and role-based requirements.
- Provision accounts, licensing, group membership, application access, email, file access, and collaboration tools in coordination with Security and Infrastructure teams.
- Automate onboarding wherever technically feasible, including zero-touch device provisioning and enrollment, automated account, group, and license assignment, scripted application and configuration delivery, and self-service setup, so that manual steps are the exception rather than the standard.
- Deliver new hire technology orientation, including device setup, multifactor authentication enrollment, and self-service support resources, etc.
- Provide day-one and first-week support for new hires, resolve setup issues promptly, and verify device compliance and enrollment after deployment.
- Maintain onboarding checklists, build documentation, automation scripts, and standard device configurations, and continuously reduce manual effort and handoffs as tooling and business needs change.
Onsite Hardware, Network, and Workplace Support
- Be readily available to provide onsite support at the South San Francisco or Newark, California offices as business needs require.
- Diagnose and resolve laptop, desktop, monitor, peripheral, printer, and other hardware or software issues requiring physical access.
- Troubleshoot user connectivity issues involving wired and wireless networks, VPN access, DNS, DHCP, TCP/IP, and local office infrastructure.
- Support conference rooms, audiovisual equipment, collaboration spaces, and other workplace technology.
- Coordinate with Network, Infrastructure, Facilities, Security, and external service providers during office projects, technology deployments, outages, and incidents.
- Provide responsive support for executives, critical business operations, and time-sensitive onsite issues.
- Experiences with Boiotech industries, handling lab equipment's is considered an additional qualification
Service Desk Escalation and Surge Support
- Serve as a Tier 3 escalation resource for complex endpoint, application, hardware, identity, and connectivity issues.
- Assist the Service Desk during periods of increased support volume, employee onboarding, device refreshes, office events, outages, or major technology changes.
- Communicate clearly with end users, set expectations, document troubleshooting activity, and ensure appropriate follow-through and closure.
- Identify recurring issues and convert them into standard fixes, knowledge articles, automation, or preventive controls.
Projects, Vendors, and Continuous Improvement
- Lead or contribute to endpoint modernization, security, lifecycle, patching, and workplace technology projects.
- Participate in vendor evaluations, endpoint management RFPs, Statements of Work, implementation planning, service transitions, and ongoing provider oversight.
- Collaborate with managed service providers and technology partners while retaining internal ownership of standards, approvals, quality, and outcomes.
- Develop and maintain technical documentation, standard operating procedures, support guides, configuration records, and operational runbooks.
- Recommend improvements that strengthen security, reliability, automation, supportability, and the end-user experience.
- Perform other responsibilities as assigned based on individual skills and experience; because the team is small, this role will be expected to assist with networking, security, and server administration as needed.
Requirements:
- Five or more years of experience in desktop engineering, endpoint administration, or enterprise end-user computing support.
- Hands-on experience managing Windows and macOS devices in a Microsoft-centric enterprise environment.
- Experience with modern desktop management platforms for device enrollment, configuration, compliance, software deployment, inventory, and remote administration.
- Experience with operating system and third-party application patch management, vulnerability remediation, and deployment troubleshooting.
- Experience configuring and supporting Microsoft 365 settings and endpoint integrations with cloud identity and collaboration services.
- Strong troubleshooting skills across endpoint operating systems, applications, hardware, authentication, and network connectivity.
- Ability and willingness to be readily available onsite in South San Francisco or Newark, California, as needed.
- Strong customer service, documentation, communication, prioritization, and cross-functional collaboration skills.
Preferred Qualifications:
- Working knowledge of networking fundamentals, including TCP/IP, DNS, DHCP, Wi-Fi, VPN, routing, switching, and systematic network troubleshooting.
- Experience supporting security baselines, encryption, device compliance, conditional access concepts, least privilege, and zero trust initiatives.
- Experience with PowerShell, shell scripting, or other automation methods used in endpoint administration.
- Experience supporting conference room technology, audiovisual systems, printers, and hybrid meeting environments.
- Experience in a regulated environment and familiarity with formal change management, audit evidence, and documented operational controls.
- Relevant industry or platform certifications are helpful but not required.
Core Competencies:
- Endpoint lifecycle management and desktop engineering
- Windows and macOS administration
- Software packaging, deployment, and application lifecycle management
- Configuration, compliance, patch, and vulnerability management
- Microsoft 365 and identity-integrated endpoint support
- Hardware, network, and workplace technology troubleshooting
- Automation, documentation, and process improvement
This position supports a remote or hybrid workplace. Occasional after-hours work may be required for planned maintenance, urgent patching, major deployments, or critical incidents. Candidates must be authorized to work in the U.S. This is a 6 month contract opportunity with the possibility of extension or contract-to-hire.
We offer a chance to work with talented people in a collaborative environment and provide a top-notch compensation. The expected hourly range for this role is $55 to $65 per hour. Actual pay will be determined based on experience, qualifications, geographic location, business needs, and other job-related factors permitted by law.
As an equal opportunity employer, Allogene is committed to a diverse workforce. Employment decisions regarding recruitment and selection will be made without discrimination based on race, color, religion, national origin, gender, age, sexual orientation, physical or mental disability, genetic information or characteristic, gender identity and expression, veteran status, or other non-job-related characteristics or other prohibited grounds specified in applicable federal, state and local laws. We also embrace differences in experience and background, and welcome diversity of opinions and thought with active recruitment and internships designed to create a stronger and better Allogene that is focused on developing life-changing products for patients.
#LI-remote #LI-TF1