Workplace Engineer Subject Matter Expert

Detachering
Delen

Over de opdracht

Vacature Workplace Engineer Subject Matter Expert

In het kort: Je gaat als workplace engineer veilige moderne werkplekken ontwerpen, bouwen, testen en uitrollen, MDM en Microsoft endpointbeheer configureren en kennis overdragen aan interne teams binnen een academische omgeving. Informatie over de inhoud van de functie (in English) Description for this hiring position The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. TU/e has identified four strategic focus areas within its Digital Safety Program. The Digital Safety Program aims to significantly strengthen the university’s cyber resilience, governance, identity & data security, endpoint security and overall control framework, while maintaining the open and collaborative nature of an academic institution. To support this transformation, TU/e is looking for a highly experienced Workplace Engineer Subject Matter Expert to technically design, build, test and support the rollout of the Secure Modern Workplace initiative within the scope of the Digital Safety Program. Secure Modern Workplace The Secure Modern Workplace project will define, design and implement a future-ready workplace model for TU/e. The project must balance strong central security standards with the specific needs of faculties, researchers, local IT-teams and specialized academic environments. A key objective is to co-create new workplace types with the faculties, including the standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace. The project also includes the rollout of Mobile Device Management and the use of Microsoft capabilities such as Intune, Autopilot, Company Portal, Entra ID, Conditional Access, device compliance and Microsoft Defender for Endpoint. Role Profile – Workplace Engineer Subject Matter Expert The Workplace Engineer SME is responsible for translating the workplace solution design into working technical configurations, builds and rollout-ready workplace types. The role works closely with the Project Manager Secure Modern Workplace, the Program Architect, LIS workplace management, security specialists, local IT and faculty representatives. The objective is to create controlled, automated and service-oriented workplace building blocks that reduce unmanaged risk, improve user experience, enable MDM adoption and lower operational support effort through standardization, automation and clear support boundaries. Key responsibilities include – Translate the approved solution design and architecture principles into technical workplace configurations and reusable service building blocks. – Design, build and validate the standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace concepts. – Configure and support the rollout of MDM and Microsoft endpoint management capabilities, including Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint. – Work with faculties, researchers and local IT teams to validate technical requirements, test workplace types and adapt implementation options where justified. – Support pilots and rollout waves, including technical troubleshooting, acceptance testing, user migration support and feedback processing. – Document configuration choices, support boundaries, exception logic and operational procedures for handover to the beheer/support teams. – Provide knowledge transfer, coaching and practical training to internal engineers and operational teams to enable sustainable in-house ownership. – Ensure continuous alignment with the Project Manager Secure Modern Workplace, Program Architect, security baselines, IAM, application packaging and service management processes. The ideal candidate has extensive hands-on experience as a senior workplace engineer or endpoint management specialist in complex modern workplace, MDM, cybersecurity and service transition environments. The role requires the ability to build and configure technical solutions, while also communicating clearly with architects, project management, faculties, researchers and support teams. The department and organization TU/e consists of various departments and faculties where education and research are conducted, supported by several central services. The candidate will work within the Digital Safety Program, primarily with LIS workplace management, end-user services, architecture, security operations, service management and local IT teams. A substantial part of the assignment is to work directly with the Project Manager Secure Modern Workplace, the Program Architect, faculty stakeholders, researchers and local IT teams to translate requirements into technical workplace builds, validate implementation choices and support a smooth transition into the new Secure Modern Workplace support model. The candidate reports to the Project Manager Secure Modern Workplace. Description of the work and Key Deliverables – Approved Technical Work Plan and Build Backlog: A clear technical delivery plan covering build activities, configuration work, testing, dependencies, risks, rollout support and handover milestones, aligned with the project plan. – Solution Design Translation: A practical translation of the solution design and architecture principles into technical workplace configurations, policies, profiles, baselines and implementation choices. – Standard Secure Workplace Build: A configured and validated standard secure workplace, including device management, security baseline, user experience, application access, Autopilot provisioning and operational support model. – Research Workplace Build: A configured and validated research workplace, including device management, security baseline, user experience, application access, Autopilot provisioning and operational support model. – Linux and MacOS Workplace Build: A configured and validated Linux & MacOs, including device management, security baseline, user experience, application access, Autopilot provisioning and operational support model. – BYOD and MDM Configuration: A technical design and configuration approach for BYOD access, mobile device management, device compliance, enrolment, remote wipe, application access and privacy-sensitive operating principles. – Microsoft Endpoint Management Configuration: Configured use of Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint within the target workplace model. – Application Deployment and Packaging Support: Technical support for application packaging, scripting, Company Portal publication and light rationalisation of the application landscape. – Security Baseline and Compliance Implementation: Implementation of minimum management and security baselines covering device compliance, local admin approach, patching, endpoint protection, vulnerability visibility, logging and monitoring. – IAM and Conditional Access Technical Alignment: Technical alignment with IAM, device identity, user identity, RBAC/ABAC principles, conditional access and privileged access requirements. – Pilot Build, Test and Evaluation: A completed pilot build with selected faculties or user groups, including test results, lessons learned, refined configurations and recommendations for wider rollout. – Rollout Support for Workplace Types: Hands-on technical support during rollout waves, including user migration support, troubleshooting, issue resolution and stabilization activities. – Service Building Blocks and Technical Documentation: Technical input for service building blocks, service catalogue descriptions, configuration standards, support levels, responsibilities and operational procedures. – Operational Handover and In-Service Transition: A structured handover to beheer/support teams, including documentation, runbooks, known issues, monitoring/reporting routines, support boundaries and acceptance criteria. – Knowledge Transfer to Internal Teams: Active knowledge transfer and practical training for internal engineers, support teams and workplace management staff, enabling sustainable operation after the assignment. – Architecture and Program Alignment: Continuous alignment with the Program Architect, Project Manager Secure Modern Workplace and wider Digital Safety dependencies such as IAM, security operations, application packaging and service management. Key Competencies – Senior Workplace Engineering: Extensive hands-on experience with modern workplace engineering, endpoint configuration, device lifecycle management, automation, deployment, remote management and support model redesign. – Microsoft Technology Expertise – Azure fundamentals – Azure Administrator Associate – Azure Solutions Architect Expert – Identity & Access Administrator Associate – MDM, MAM and BYOD Understanding: Understands MDM/MAM concepts, enrolment, device compliance, remote wipe, privacy considerations and the balance between secure access and user flexibility. – Windows, Linux and MacOS Workplace Knowledge: Able to understand and translate requirements for standard secure, research (OT), Linux, MacOS and BYOD workplace types into practical technical designs and implementation options. – Solution Design and Architecture Translation: Able to understand solution designs and enterprise architecture principles and translate them into buildable configurations, technical standards and rollout-ready solutions. – Security Baseline and Endpoint Protection: Understands endpoint hardening, local admin reduction, patching, device compliance, vulnerability visibility, logging, monitoring and risk-based exception handling. – Service Design and Service Building Blocks: Able to translate technical configurations into reusable service building blocks, service catalogue elements, responsibilities, support boundaries and operating model choices. – Testing, Piloting and Rollout Support: Able to define test scenarios, validate technical readiness, support pilots, solve rollout issues and stabilize workplace types before handover to operations. – Knowledge Transfer and In-Service Handover: Strong ability to document, explain and transfer technical knowledge to internal engineers and beheer/support teams, including runbooks, configuration logic and support procedures. – Faculty Co-Creation and Stakeholder Sensitivity: Comfortable working with faculties, researchers and local IT teams to validate technical needs and implementation options in a decentralized and autonomous academic environment. – Collaboration with Project and Architecture Teams: Works effectively with the Project Manager Secure Modern Workplace, Program Architect, security specialists, IAM, application packaging and service management teams. – Pragmatism and Delivery Focus: Balances security, architecture and service objectives with operational feasibility, capacity constraints and the realities of research and faculty environments. – Communication Skills: Communicates complex workplace, security and endpoint management topics in clear, accessible language for both technical and non-technical audiences. – Agile way of working: Experience with scaled agile and Lean working. – Other: Fluent in English mandatory; Dutch required language for speaking. Work location is Eindhoven (minimal 3 days).

Eisen

Uitvoeringsvoorwaarde arbeidsrelatie
De aard en organisatorische inbedding van deze opdracht maken dat niet iedere contractvorm passend is; voor deze opdracht wordt daarom uitgegaan van uitvoering via detachering.
OverheidZZP sluit geen specifieke contractvorm of categorie opdrachtnemers op voorhand uit. Wel geldt dat iedere opdracht moet kunnen worden uitgevoerd op een wijze die in overeenstemming is met de toepasselijke wet- en regelgeving, waaronder de regels omtrent de kwalificatie van arbeidsrelaties en de Wet DBA.
De geschiktheid van een opdracht voor een bepaalde contractvorm wordt beoordeeld aan de hand van de beoogde feitelijke uitvoering van de werkzaamheden en niet uitsluitend op basis van de gekozen juridische constructie. Daardoor kan het voorkomen dat een opdracht zich, gelet op de aard, inrichting of organisatorische inbedding van de werkzaamheden, niet leent voor alle contractvormen.
Inschrijvers dienen desgevraagd aannemelijk te maken op welke wijze zij de opdracht zullen uitvoeren en hoe daarbij wordt voldaan aan de toepasselijke wet- en regelgeving. Indien onvoldoende aannemelijk wordt gemaakt dat de opdracht binnen de voorgestelde constructie rechtmatig kan worden uitgevoerd, kan een inschrijving buiten beschouwing worden gelaten.

– De aangeboden kandidaat voldoet minimaal aan de kwalificaties en competenties zoals opgegeven in het functieprofiel (1.3). – Fluent in English mandatory; Dutch required language for speaking. – Work location is Eindhoven (minimal 3 days).

Wensen

LET OP: Op basis van de wensen van onze opdrachtgever wordt bepaald of je eventueel wordt uitgenodigd voor een selectiegesprek. Het is dus noodzakelijk dat je ook op de wensen een sterke match hebt.

– Geen wensen

Overige informatie

Optie tot verlenging: Ja, tot maximale looptijd van 2 jaar, daarna eventueel nogmaals met wederzijds goedvinden Gespreksdatum: 02/10/2026 tussen 10.00-16.00 uur

Procedure

De sluitingsdatum van deze opdracht is de harde deadline van onze opdrachtgever.

  • Om je krachtig voor te kunnen dragen hebben wij minimaal één werkdag nodig om samen met jou alle bescheiden in orde te maken.
  • Wanneer je interesse hebt in deze opdracht en overtuigd bent van een sterke match, reageer dan direct!
  • Naast een actueel en op de opdracht gericht CV zullen wij altijd vragen om een bondige persoonlijke motivatiebrief (inclusief een toelichting per functie-eis en -wens) en een indicatief uurtarief/maandloon.

Op basis van deze informatie kunnen wij voor je aan de slag! We nemen contact met je op om alle verdere details goed door te nemen en duidelijke afspraken met je te maken voor we je daadwerkelijk voorstellen.

Reageer nu op

Workplace Engineer Subject Matter Expert

Let op: Gewenste contractvorm voor deze opdracht is detachering


Wij staan voor je klaar!

(ma - vr 09:00 - 17:00)

Vraag over de opdracht? Wij ontvangen graag je vraag per mail via [email protected]

Bureau/partner?

Je kunt dan alleen voorstellen na aanmelding en toelating als partner via onderstaande pagina.

Hulp met je stukken?

Leer hier hoe je een goede motivatiebrief schrijft (als ZZP-er) in het publieke domein!

Leer hier hoe je je CV herschrijft naar de opdracht (als ZZP-er) in het publieke domein!

Leer hier hoe je je competenties verwerkt in je CV, motivatiebrief en gesprek!

Veelgestelde vragen

Wij kennen de meeste opdrachtgevers goed en weten waar zij op letten in een selectieproces. Die ervaring gebruiken we bij elke aanbieding: we toetsen je CV en geven gerichte tips over je CV, motivatie, (concurrerend) uurtarief en presentatie. Ook wanneer je op gesprek mag helpen wij je met de voorbereiding. Zo vergroten we samen je slagingskans!

Reageren is altijd vrijblijvend (no cure no pay) en nog niet definitief. Na jouw reactie nemen we altijd eerst contact met je op, en pas als jij helemaal akkoord bent met de financiële en praktische uitgangspunten dragen wij je formeel voor bij de opdrachtgever. We werken met een eerlijke, marktconforme fee bovenop jouw uurtarief, verwerkt in het tarief richting de opdrachtgever. Samen stemmen we altijd af welk uurtarief jij wilt ontvangen en verkennen we of de opdracht goed aansluit bij jouw ambities en kwaliteiten.

Bij OverheidZZP vind je opdrachten die via verschillende contractvormen kunnen worden uitgevoerd, waaronder ZZP en detachering. Per opdracht wordt beoordeeld welke contractvorm(en) passend zijn, afhankelijk van de aard van de werkzaamheden, de organisatorische inbedding en de wijze waarop de opdracht feitelijk wordt uitgevoerd. Je herkent de voorkeur of uitgangspunten voor een opdracht aan het label bovenaan de vacature: ZZP (of detachering) of Detachering . Staat bij een opdracht uitsluitend ‘Detachering’? Dan is op basis van de kenmerken van die specifieke opdracht gekozen voor uitvoering via detachering. Dit betekent niet dat bepaalde groepen opdrachtnemers op voorhand worden uitgesloten, maar dat de opdracht zich gelet op de beoogde uitvoering niet leent voor alle contractvormen. Lees hier meer over de uitvoeringsvoorwaarde arbeidsrelatie en detachering.

De eisen die bij een opdracht staan vermeld zijn knock-out criteria: je moet hier 100% aantoonbaar aan voldoen om in aanmerking te komen. Wensen zijn geen harde vereisten, maar het is wel aanbevolen om aan zoveel mogelijk wensen te voldoen om kansrijk te zijn in de selectie. Reageer alleen als je zeker weet dat je aan alle eisen en de meest essentiële wensen voldoet.

Gebruik de eerste pagina van je CV of een deel van je motivatiebrief voor een heldere onderbouwing van jouw match. Neem alle eisen en wensen uit de opdracht over en beschrijf steeds kort hoe je hieraan voldoet. Dit maakt de aansluiting op de opdracht direct inzichtelijk en helpt de opdrachtgever in het begrijpen van jouw aanbieding. Je kunt hiervoor dit format gebruiken.

Relevante opdrachten

Interesse, en overtuigd van een sterke match?

Mogen wij je helpen met zoeken?

Wij helpen je graag met het vinden van een passende opdracht in het publieke domein! Interim of detachering? Neem contact met ons op dan gaan wij vrijblijvend persoonlijk voor je op zoek!