K

Solution Architect – Devices / Endpoint Migration (Tenant-to-Tenant)

Kyndryl · Bangalore

8–16 yrs experienceRemoteFlexTimePosted 2 days ago
Apply now →

Job description

**Who We Are** At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world's leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people---Kyndryls---that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive. **The Role** **The Role:** You will be the **Devices discipline Solution Architect** for a large-scale, global **Microsoft 365 tenant-to-tenant consolidation** programme, operating in an industrialised **migration factory model (24x7 delivery across shifts)** . Your job is in providing technical leadership for **the end-to-end device migration execution** , ensuring it is delivered consistently across high volume waves with minimal disruption to end users. This role is for a genuine **migration specialist** : someone who has delivered multiple endpoint migrations (not just run Intune). You will set the migration patterns, guardrails, runbooks, validation gates, exception handling and escalation paths for the factory execution teams. You will work closely with regional Scale technical leadership and Governance to ensure devices can be migrated repeatably, safely and at pace. **Key Responsibilities:** * Own the **target state endpoint architecture** for the consolidated tenant (join model, identity/device trust, Intune/Autopilot posture, compliance strategy, app delivery strategy). * Define the **tenant-to-tenant device migration approach** including sequencing of: identity readiness → device readiness → policy/app alignment → cutover → stabilisation. * Establish factory-ready **runbooks and quality gates** for every major device migration activity (pre-checks, enrolment, policy assignment, app deployment, validation, rollback). * Specify and operationalise use of migration tooling (e.g., **PowerSyncPro** or equivalent), including configuration patterns, telemetry, dashboards and failure triage. * Define **device cohort segmentation** strategies (VIPs, executives, kiosks, shared devices, remote-only, high-risk apps, high-privilege users) and tailored migration patterns for each. * Lead architecture decisions for **Autopilot strategy** , device provisioning, re-enrolment paths, device compliance re-baselining and post-move support. * Define the **security/compliance impact model** (Conditional Access dependencies, compliance policies, device certificates, Defender integration, privileged access constraints). * Create and govern the **exception framework** (what exceptions are allowed, evidence required, approval process, technical debt management). * Act as final escalation point for device migration failures and systemic issues; drive root-cause elimination into improved standards/runbooks. * Ensure evidence capture is "audit-grade" for each wave: readiness evidence, validation packs, known-issue logs, acceptance sign-offs. **Who You Are** **Must‑Have:** * Proven delivery of tenant-to-tenant endpoint migration at enterprise scale (Intune Windows), must be demonstrated with outcomes, not theory. * Deep hands-on expertise in Microsoft Intune, Windows endpoint management, policy design, configuration profiles, compliance, app deployment and troubleshooting. * Strong understanding of Microsoft Entra ID device identity, device registration/join states, device trust and Conditional Access device-based controls. * Experience designing and running industrialised migration: runbooks, gates, telemetry-driven execution, shift handovers and repeatable "factory" patterns. * Strong PowerShell/Graph troubleshooting mindset (bulk checks, readiness reporting, remediation scripting). * Experience managing complex device estates (multi-region, multiple personas, varied network conditions, legacy constraints, heavy endpoint security tooling). * Comfortable operating under pressure during cutover windows; able to lead war rooms and make safe, fast decisions. **Good‑to‑Have:** * Experience with **PowerSyncPro** specifically (or comparable endpoint migration tooling) including operational constraints and troubleshooting patterns. * Knowledge of Defender for Endpoint integration, certificate-based auth scenarios, device-based access restrictions and endpoint DLP considerations. * Experience with Windows 11 transition alongside tenant consolidation. **Interpersonal \& Consulting Skills:** * "Direction-setter" behaviour: can set standards, defend them with evidence and get adoption across teams. * Calm under pressure; can lead escalation without drama and keep teams focused on outcomes. * Strong stakeholder translation: can explain device risk/impact in business language without hand-waving. * High quality bar: refuses unsafe shortcuts, insists on evidence and repeatability. * Coaches engineers and senior SMEs: builds capability, doesn't hoard knowledge. * Operates as one-team across onshore/offshore and across identity/security/app stakeholders. **Shift / Working Pattern Notes:** * This role operates within a **three‑shift 24x7 Factory model** . The specific rota will be confirmed, but **shift handovers are mandatory** and performance is measured on shift outcomes. Peak cutover windows may require schedule flexibility. **Being You** The "Kyn" in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don't meet every requirement, we encourage you to apply. We believe in growth, and we're excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging --- being