
Kymera is a clinical-stage biotechnology company pioneering the field of targeted protein degradation (TPD) to develop medicines that address critical health problems and have the potential to dramatically improve patients’ lives. Kymera is deploying TPD to address disease targets and pathways inaccessible with conventional therapeutics. Having advanced the first degrader into the clinic for immunological diseases, Kymera is focused on building an industry-leading pipeline of oral small molecule degraders to provide a new generation of convenient, highly effective therapies for patients with these conditions. Founded in 2016, Kymera has been recognized as one of Boston’s top workplaces for the past several years. For more information about our science, pipeline and people, please visit www.kymeratx.com or follow us on X (formerly Twitter) or LinkedIn.
PIONEER: We are courageous, resilient and rigorous in our mission to improve patients’ lives through our revolutionary degrader medicines.
COLLABORATE: We value trust + transparency from everyone. Our goals are shared, our decisions data-driven and our camaraderie genuine.
BELONG: We recognize our differences, inviting curiosity and inclusivity, so that our people are valued, seen, and heard.
Kymera Therapeutics is seeking a Senior Infrastructure & Systems Engineer to serve as a technical peer and force multiplier for the Senior Director of Infrastructure & Operations. This role provides technical leadership for the organization's endpoint computing platform and broader infrastructure within a hybrid Microsoft ecosystem, serving as the senior engineering resource responsible for designing, implementing, securing, and optimizing endpoint management technologies while acting as the highest level of technical escalation for complex infrastructure issues.
The successful candidate will drive the evolution of Kymera's modern workplace by leveraging Microsoft Intune, Microsoft 365, Entra ID, Windows client engineering, automation, and cloud technologies to deliver secure, scalable, and highly available endpoint services. This position partners closely with Infrastructure, Cybersecurity, Identity, and Enterprise Applications teams to modernize endpoint architecture, improve operational maturity, and implement engineering best practices across the organization.
Architect, implement, and maintain enterprise endpoint management solutions using Microsoft Intune and Company Portal
Design and maintain application deployment strategies utilizing Win32 packaging, Microsoft Store integration, Microsoft 365 Apps, and PowerShell automation
Develop and maintain configuration profiles, compliance policies, security baselines, remediation scripts, and update rings
Engineer and optimize Windows Autopilot deployments including Enrollment Status Page (ESP) configurations, provisioning workflows, Windows Hello for Business, and lifecycle management
Develop standards for endpoint configuration, provisioning, and device governance
Lead initiatives to modernize endpoint management through cloud-native technologies
Support macOS and iPadOS devices in an enterprise MDM context alongside Windows. A key opportunity within this role is to establish and mature Apple device management practices including MDM enrollment, compliance policies, and lifecycle management
Serve as L3 escalation point for the deskside support team, building on prior work rather than re-diagnosing from scratch
Engineer and support Windows 11 enterprise platforms with a focus on performance, reliability, and security
Perform deep operating system analysis including boot performance, driver architecture, Windows servicing, registry, profile management, and application compatibility
Analyze Windows internals using Event Viewer, Performance Monitor, ProcMon, Reliability Monitor, ETW traces, and Windows diagnostic tools
Lead root cause analysis of recurring endpoint issues and implement permanent engineering solutions
Evaluate new Microsoft technologies and recommend improvements to the enterprise endpoint platform
Advanced Active Directory and Entra ID administration in a hybrid environment including Azure AD Connect, conditional access, hybrid join states, and Privileged Identity Management
Okta and Microsoft Entra ID administration including SSO integrations, enterprise application registrations, user provisioning, MFA policy management, and agent health monitoring across a hybrid identity environment
Troubleshoot complex authentication, synchronization, token, Kerberos, and hybrid identity issues spanning on-premises Active Directory, Entra ID, and Okta
Support identity lifecycle processes for users, devices, and service accounts
Partner with Infrastructure and Security teams to strengthen identity governance and Zero Trust initiatives
Advanced PowerShell scripting and Microsoft Graph API proficiency are core requirements. The environment relies heavily on custom automation across identity, endpoint management, and operational workflows. The candidate must be able to read, maintain, extend, and build complex scripts and Graph API integrations from scratch including Azure Automation runbooks and scheduled operational tasks.
Administer and maintain Power Automate flows integrated with SharePoint, Azure Automation, and identity systems
Troubleshoot flow failures, manage connections, and improve existing automation reliability
Build reusable automation solutions that improve operational efficiency and reduce manual effort
Create reporting dashboards and health monitoring scripts for endpoint compliance and operational metrics
Advanced Exchange Online administration including mail flow rules, connectors, transport policies, message tracing, and the ability to diagnose and resolve complex email delivery issues
Advanced SharePoint Online administration including site lifecycle management, permissions, governance, and the ability to research and resolve complex issues independently
Microsoft Teams administration
Troubleshoot cross-service Microsoft 365 issues involving authentication, licensing, permissions, and collaboration services
Engineer endpoint security controls in partnership with the cybersecurity team including Microsoft Defender for Endpoint, Attack Surface Reduction, BitLocker, Windows Firewall, and endpoint hardening standards
Perform initial triage of endpoint and infrastructure security alerts before escalation
Support vulnerability management, compliance reporting, and endpoint security assessments
Participate in incident response activities involving endpoint compromise or identity-related threats
Establish standards for enterprise hardware lifecycle management
Coordinate OEM warranty services, vendor escalations, and hardware replacement programs
Utilize enterprise diagnostic tools to distinguish hardware, firmware, and operating system issues
Evaluate new endpoint hardware platforms for enterprise deployment
Author and maintain technical documentation, runbooks, engineering standards, and operational SOPs
Mentor junior engineers and deskside support staff while promoting engineering best practices
Lead root cause analysis efforts and post-incident reviews for critical endpoint issues
Drive continuous service improvement through automation, standardization, and operational maturity
In addition to core responsibilities, this role contributes across a broad infrastructure stack in collaboration with the wider infrastructure team. While endpoint management and identity remain the primary focus, the successful candidate will bring familiarity with the following areas and engage with them as part of day-to-day operations.
Participate in Azure environment administration including resource groups, virtual networks, and storage accounts
Manage and maintain Azure Automation runbooks supporting identity and operational workflows
Contribute to Azure infrastructure initiatives in collaboration with the broader infrastructure team
Assist with Cisco Meraki network administration including switch configuration, VLAN management, and wireless access point management
Troubleshoot DNS, DHCP, VPN, and Wi-Fi connectivity issues affecting endpoints and users
Support network infrastructure projects including hardware refresh and new site deployments
Familiarity with Palo Alto next-generation firewalls is a plus
Participate in VMware ESXi environment administration including VM deployment, configuration, and health monitoring
Assist with Windows Server administration including domain controllers, utility servers, and application servers
Contribute to server patching, lifecycle management, and disaster recovery validation
Assist with NetApp ONTAP storage administration as needed including volume management and cluster health
Support cloud file storage migration and ongoing management
5 to 7 years of hands-on experience specifically in an enterprise infrastructure or systems engineering role, not general IT support. This person needs to contribute immediately without significant onboarding or training.
Advanced Intune administration including Win32 app packaging, compliance policies, configuration profiles, remediation scripts, and Autopilot provisioning
Advanced Active Directory and Entra ID administration in a hybrid environment including Azure AD Connect, conditional access, hybrid join states, and Privileged Identity Management
Okta and Microsoft Entra ID administration including SSO integrations, enterprise application registrations, user provisioning, and MFA policy management
Advanced PowerShell scripting and Microsoft Graph API proficiency
Advanced Exchange Online administration including mail flow rules, connectors, transport policies, and message tracing
Advanced SharePoint Online administration including site lifecycle, permissions, and governance
Microsoft Teams administration
Experience supporting Apple devices including macOS and iPadOS in an enterprise environment
Deep understanding of Windows client architecture, troubleshooting, and enterprise lifecycle management
Strong knowledge of enterprise networking concepts including DNS, DHCP, VPN, and Wi-Fi
Strong troubleshooting instincts across identity, endpoints, and connectivity
Familiarity with enterprise ITSM platforms for ticket management and documentation
Ability to work independently across multiple concurrent workstreams
Strong written and verbal communication skills
Azure administration including resource groups, virtual networks, storage accounts, and Azure Automation runbook management
Cisco Meraki network administration including switches, VLANs, and wireless access points
Palo Alto firewall familiarity
VMware ESXi and vSphere administration
NetApp ONTAP familiarity
Power Automate and Power Apps experience building and maintaining enterprise flows integrated with SharePoint and Azure Automation
Experience with hybrid Active Directory to Entra ID migration
Zoom platform administration including user management, licensing, meeting policies, and Zoom Rooms
Experience with Microsoft Defender for Endpoint and Microsoft Defender XDR
Experience with Windows Update for Business, Windows Autopatch, and enterprise servicing strategies
Backup and disaster recovery platform experience
Apple Business Manager and enterprise Apple MDM platform experience such as Jamf or Kandji
Exposure to regulated industry environments including biotech, pharma, or life sciences
Operates with a high degree of independence and ownership
Comfortable managing multiple concurrent workstreams without losing depth on any of them
Brings methodical, structured thinking to ambiguous technical problems
Understands enterprise systems as interconnected platforms rather than isolated technologies
Communicates clearly across technical and non-technical audiences
Committed to reducing single points of failure through documentation and automation
Ready to contribute immediately
Originally posted by Kymera Therapeutics. View original posting
BioCareerAI is an independent job platform and is not affiliated with or endorsed by Kymera Therapeutics.
