Why Work for Frontier Airlines?
At Frontier, we believe the skies should be for everyone. We deliver on this promise through our commitment to Low Fares Done Right. This is more than our tagline - it’s our driving philosophy. Every member of Team Frontier has an important role to play in bringing this vision to life. Our successful business model allows travelers to take advantage of our fast-growing route network while our bundled and unbundled pricing options allow our customers to personalize their travel experience and only pay for the services they need – saving them money along the way.
What We Stand For
Low Fares Done Right is our mission and we strive to bring it to life every day. Our ‘Done Right’ promise means delivering not only affordable prices, but making travel
friendly and easy for our customers. To do this, we put a great deal of
care into every decision and action we take. We must be efficient with the use of our resources and make smart decisions about how we run our business. We must also innovate and be
pioneers - we’re not afraid to try new things. While our business requires us to fly high in the air, we also consider ourselves
down-to-earth in our approach, creating a warm and friendly experience that truly demonstrates Rocky Mountain Hospitality.
Work Perks
At Frontier, we like to think we’re creating something very special for our team members. Work is why we’re here, but the perks are nice too:
- Flight benefits for you and your family to fly on Frontier Airlines
- Buddy passes for your friends so they can experience what makes us so great
- Discounts throughout the travel industry on hotels, car rentals, cruises and vacation packages
- Discounts on cell phone plans, movie tickets, restaurants, luggage and over 2,000 other vendors
- Enjoy a ‘Dress for your Day’ business casual environment
- Flexible work schedules that support work/life balance
- Total Rewards program including a competitive base salary, short term incentives, long-term incentives, paid holidays, 401(k) plan, vacation/sick time and medical/dental/vision insurance that begins the 1st of the month following your hire date.
- We play our part to make a difference. The HOPE League, Frontier Airlines’ non-profit organization, is dedicated to providing employees financial assistance during catastrophic hardship
Who We Are
Frontier Airlines is a leading ultra-low cost carrier headquartered in Denver, Colorado. With a mission to deliver Low Fares Done Right, the company provides affordable, convenient and accessible air travel throughout the U.S., Caribbean, Mexico and Latin America. Frontier’s highly fuel-efficient, all-Airbus fleet is among the youngest and most modern of any carrier within the U.S. That, combined with the airline’s many weight-saving initiatives and focus on operational efficiencies, makes Frontier America’s Greenest Airline.* Each Frontier Airlines plane tail features a special animal with a unique name and backstory. Many of the featured species are endangered or threatened, part of the airline’s commitment to underscore and raise awareness for their plight. Frontier serves approximately 100 destinations throughout North America and operates 500-plus daily flights, on average. The airline employs more than 7,000 team members and has crew bases in more than a dozen U.S. cities. Frontier Airlines., Inc., is a subsidiary of Frontier Group Holdings, Inc. (NASDAQ: ULCC).
- Frontier is the most fuel-efficient of all major U.S. carriers when measured by ASMs per fuel gallon consumed.
What Will You Be Doing?
The Lead Endpoint, Identity & Microsoft 365 Administrator is responsible for the architecture, engineering, security, administration, and continuous improvement of the enterprise endpoint, identity, and Microsoft 365 ecosystems. This role provides technical leadership for endpoint management, identity services, collaboration platforms, and cybersecurity initiatives that support a secure, resilient, and compliant hybrid (Cloud & On-prem) technology environment.
The position serves as the subject matter expert for endpoint device management, Microsoft 365 administration, Entra ID (Azure AD), identity governance, authentication technologies, device security, and endpoint security architecture. Additionally, the role is responsible for identifying, recommending, and implementing cybersecurity best practices that strengthen the organization’s overall security posture and reduce operational risk.
The Lead Engineer partners closely with Cybersecurity, Infrastructure, Service Desk, Cloud Engineering, and business stakeholders to ensure enterprise technologies align with security standards, regulatory requirements, and business objectives.
This role is responsible for administering Active Directory, Microsoft Entra ID, Microsoft Intune, ManageEngine Endpoint Central, Zscaler ZIA/ZPA, Microsoft 365, and Exchange Online. The successful candidate will support user identity lifecycle processes, endpoint enrollment and compliance, device patching, application deployment, secure internet and private application access, mail administration, and Microsoft 365 services.
This position requires strong troubleshooting skills, security awareness, documentation discipline, and the ability to collaborate effectively with infrastructure, cybersecurity, networking, and service desk teams.
Essential Functions
- Identity Administration: Manage and support Active Directory and Microsoft Entra ID objects, including users, groups, service accounts, organizational units, attributes, and identity lifecycle processes.
- Secure Access: Administer and support Conditional Access, Multi-Factor Authentication (MFA), and related identity security controls aligned to zero trust and company security standards.
- Endpoint Management: Configure, deploy, and maintain endpoint management capabilities using Microsoft Intune and related MDM/MAM platforms.
- Device Enrollment and Compliance: Manage endpoint enrollment, provisioning, compliance policies, configuration profiles, and device lifecycle processes for Windows, mobile, and other supported platforms.
- Endpoint Security: Experience configuring and supporting Defender for Endpoint.
- Endpoint Patching: Manage device patching, software updates, and remediation activities using ManageEngine Endpoint Central and Microsoft endpoint management tools.
- Application Deployment: Package, deploy, update, and troubleshoot applications across managed endpoints using Intune, ManageEngine Endpoint Central, and other approved tools.
- Zscaler Administration: Support Zscaler ZIA/ZPA access policies, client connector deployment, secure internet access, and private application access troubleshooting.
- Microsoft 365 Administration: Administer Microsoft 365 services, including licensing, collaboration services, service health monitoring, and user support.
- Exchange Online Administration: Support mailbox administration, mail flow, distribution groups, shared mailboxes, permissions, and troubleshooting of Exchange Online issues.
- Troubleshooting and Support: Provide advanced technical support for identity, endpoint, secure access, mail, and Microsoft 365 service issues while minimizing business disruption.
- Security Management: Implement and maintain endpoint and identity security controls to protect users, devices, applications, and data from threats and vulnerabilities.
- Automation and Scripting: Use PowerShell and other approved automation methods to improve administration, reporting, remediation, and operational efficiency.
- Documentation: Maintain comprehensive documentation of identity, endpoint, access, Microsoft 365, Exchange Online, and operational procedures.
- Collaboration: Work closely with infrastructure, cybersecurity, networking, service desk, and business teams to align platform administration with organizational goals.
- Training and Knowledge Sharing: Provide guidance and support to IT teams and end users on endpoint, identity, secure access, and Microsoft 365 best practices.
- Travel requirements: 25% in support of projects.
- Other duties as assigned.
- Other Functions
- Maintain accurate records for endpoint configurations, identity objects, access policies, mail administration, and Microsoft 365 service changes
- Adhere to documented Change Management processes to protect the integrity of the production environment
- Manage ticket loads and ensure response time SLAs are met for identity, endpoint, access, Microsoft 365, and Exchange Online support requests
- Develop and maintain procedures that support consistent, secure, and process-driven resolution of operational issues
Qualifications
- Education: Bachelor’s degree in Computer Science, Information Technology, or related field or equivalent combination of education and experience required.
- Technical Experience: At least 7 years of experience in enterprise endpoint management, identity administration, Microsoft 365 administration, or related infrastructure operations.
- Hybrid Identity Experience: Hands-on experience supporting hybrid identity environments using Active Directory and Microsoft Entra ID.
- Endpoint Management Experience: Experience configuring and supporting Microsoft Intune, endpoint compliance, device enrollment, application deployment, and patch management.
- Endpoint Tooling: Experience with ManageEngine Endpoint Central or similar endpoint patching and device management platforms strongly preferred.
- Secure Access Platforms: Experience supporting Zscaler ZIA/ZPA, client connectors, secure internet access, and private application access preferred.
- Microsoft 365 and Exchange Online: Experience administering Microsoft 365 services and Exchange Online, including mailbox management, mail flow, permissions, and collaboration services.
- Automation: PowerShell scripting experience for administration, reporting, troubleshooting, and process automation strongly preferred.
- Certifications: Relevant certifications such as Microsoft Certified: Endpoint Administrator Associate, Microsoft 365 Certified Administrator, Microsoft Certified: Identity and Access Administrator Associate, JAMF Certified Admin, or similar are a plus.
- Problem-Solving: Excellent troubleshooting and problem-solving skills.
- Communication: Strong verbal and written communication skills.
- Team Player: Ability to work effectively in a team-oriented environment and collaborate with infrastructure, cybersecurity, networking, and service desk teams.
Knowledge, Skills And Abilities
- Identity Platforms: Strong understanding of Active Directory and Microsoft Entra ID administration, including users, groups, service accounts, synchronization concepts, and hybrid identity operations.
- Conditional Access and MFA: Knowledge of Conditional Access, Multi-Factor Authentication, identity protection, and secure access best practices.
- Endpoint Management: Advanced skills in configuring and managing Microsoft Intune, endpoint enrollment, compliance policies, configuration profiles, and application policies.
- Endpoint Patching: Proficiency with ManageEngine Endpoint Central or similar tools for patch deployment, software updates, endpoint inventory, and remediation.
- Operating Systems: Knowledge of desktop and mobile operating systems such as Windows, iOS, Android, and macOS.
- Zscaler: Knowledge of Zscaler ZIA/ZPA, client connector behavior, secure internet access, private application access, and policy troubleshooting.
- Microsoft 365: Ability to administer Microsoft 365 services, licensing, collaboration features, service health, and user support processes.
- Exchange Online: Knowledge of mailbox administration, mail flow, shared mailboxes, distribution groups, permissions, and Exchange Online troubleshooting.
- Security Best Practices: Familiarity with zero trust principles, endpoint security, identity security, and secure configuration standards.
- Networking: Basic knowledge of networking principles and how they relate to endpoint connectivity, cloud services, VPN-less access, and secure web access.
- Compliance Standards: Understanding of compliance standards and regulations related to endpoint, identity, and access management.
- PowerShell: Ability to use PowerShell for administration, automation, reporting, troubleshooting, and operational support.
- Troubleshooting: Strong troubleshooting skills to diagnose and resolve identity, endpoint, secure access, Microsoft 365, and Exchange Online issues.
- Policy Development: Ability to develop, implement, and maintain endpoint, identity, access, and application policies.
- Software Deployment: Proficiency in deploying software, updates, and patches through Intune, ManageEngine Endpoint Central, or similar platforms.
- Documentation: Excellent documentation skills to maintain detailed records of configurations, policies, procedures, and support processes.
- Communication: Strong verbal and written communication skills for effective collaboration and user support.
- Training: Ability to train and support end users and IT teams on endpoint, identity, secure access, and Microsoft 365 best practices.
- Analytical Thinking: Ability to analyze complex technical issues and develop effective solutions.
- Attention to Detail: High attention to detail to ensure accurate configuration and compliance with policies.
- Adaptability: Ability to adapt to new technologies and changing environments.
- Team Collaboration: Strong ability to work collaboratively with infrastructure, cybersecurity, networking, service desk, and other departments.
- Time Management: Effective time management skills to prioritize tasks and meet deadlines.
- Customer Service: Ability to provide excellent customer service and support to end users.
Equipment Operated
Standard office equipment, including PC, copier, fax machine, printer
Work Environment
Typical office environment, adequately heated and cooled
Physical Effort
Generally, not required.
Supervision Received
General Supervision: The incumbent performs a variety of routine work within established policies and procedures and receives detailed instructions on new projects and assignments.
Salary Range: $110,114-$150,000 - Please note: this role will close on or before 9/30/26.
Positions Supervised
None
Workplace Policies
Disclaimer: The above statements are intended only to describe the general nature and level of work required of the referenced position; they are not intended to be an exhaustive list of all responsibilities, duties, and skills required of individuals in this position. Please be advised that duties and expectations of this position may be subject to change.
Frontier Airlines, Inc. is an equal opportunity employer and, as such, is committed to providing equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, national origin, age, marital status, veteran status, sexual orientation, gender identity or expression, disability status, pregnancy, genetic information, citizenship status or any other basis protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Frontier Airlines is a Zero Tolerance Drug-Free Workplace. All prospective DOT safety-sensitive employees are subject to pre-employment testing for the following drugs and their metabolites: Marijuana, Cocaine, Amphetamines, Opioids and Phencyclidine (PCP). Further, any DOT safety-sensitive job applicant who is found to have tested positive on any required drug or alcohol test at a former employer will be considered ineligible for employment with Frontier.
Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.