Enterprise Patch Management and Compliance – Endpoints and Servers
•Manages the software update infrastructure end to end, including the Software Update Point, WSUS and database maintenance, update classifications and products, synchronization health, and Windows Update for Business and Windows Autopatch policy where used.
•Run the full monthly patch cycle for the workstation estate, including software update groups, automatic deployment rules, pilot and production deployment rings, deadlines, deferrals and user notification behavior.
•Run patching for the Windows server estate, including server collections, agreed maintenance windows, reboot orchestration and ordering for clustered, dependent and business-critical servers, in coordination with the application teams.
•Manage third-party application patching alongside Microsoft updates, so that the compliance position covers the software that is actually exploited rather than only the operating system.
•Report patch compliance for endpoints and servers against agreed targets on a defined cadence to IT leadership, information security and audit, and hold every exception with documented risk acceptance and an agreed remediation date.
•Investigate and remediate devices and servers that fail to patch, including client health, content, bandwidth, disk space and reboot-pending causes, rather than allowing a persistent non-compliant tail to accumulate.
•Perform structured pre-deployment and post-deployment validation for every cycle and document the outcome.
Endpoint Management Platform Operations – Configuration Manager and Intune
•Administer Microsoft Configuration Manager, including site systems, distribution points, boundary groups, collections, client settings, client health remediation, console security roles, and site database and SQL maintenance.
•Administer Microsoft Intune, including enrolment methods, device configuration profiles, compliance policies, endpoint security policies, filters and scope tags.
•Manage the co-management configuration, including workload sliders, and manage the migration of workloads from Configuration Manager to Intune deliberately rather than opportunistically, with a documented target state.
•Maintain platform currency and health for both platforms, including version upgrades, hotfixes, content distribution health and backup and recovery of the Configuration Manager site.
•Monitor and report estate health, enrolment coverage and policy application, and act on devices that fall out of management before they become invisible.
•Coordinate shared Intune tenant configuration with the Apple and M365 platform engineers, so that policy scoped by one team does not conflict with another.
Application Packaging, Push and Pull Deployment
•Package, test and deploy applications and updates through Configuration Manager and Intune, including Win32 app packaging, detection rules, requirements, dependencies, supersedence, and uninstall behavior.
•Deliver applications by push, as required deployments targeted at collections or groups with scheduling, deadlines and phased rings, and by pull, as self-service made available through Software Center and Company Portal.
•Maintain the application catalogue, including license-restricted assignment, retirement of superseded packages and removal of software no longer entitled.
•Establish and maintain packaging standards so that packages install silently, detect correctly, supersede cleanly, uninstall reliably and are documented.
•Coordinate deployment with application owners, including pilot rings, scheduling around regional business hours, communication and rollback.
•Investigate deployment failures to root cause across client, content, detection, dependency and network layers, and remediate rather than re-target.
OS Deployment, Imaging, Autopilot and Hardware Lifecycle
•Build and maintain operating system images, task sequences and Windows Autopilot deployment profiles, and maintain parity between the imaging and cloud provisioning paths so a device is the same however it was built.
•Maintain driver packages and firmware update management across the supported hardware models and manage model introduction and retirement with the endpoint and procurement teams.
•Manage Windows feature update and version currency, including servicing rings, deadlines, deferrals and upgrade readiness assessment, so that the estate stays on supported builds.
•Maintain provisioning integrations including domain and Entra join, BitLocker enablement and recovery key escrow, and Windows LAPS where deployed.
•Follow and enforce change control for deployment activity, including Change Advisory Board submission, tested rollback and coordination of deployment windows with affected business teams.
Security Baselines, Vulnerability Remediation and Endpoint Security
•Maintain configuration and security baselines, including CIS-aligned hardening where adopted, and detect and remediate drift from baseline across the managed estate.
•Remediate endpoint and server findings raised by the enterprise vulnerability management program, tracking items through to verified closure with documented exceptions.
•Maintain endpoint security agent coverage and health in partnership with information security, including Microsoft Defender for Endpoint onboarding, attack surface reduction rules and exclusion governance.
•Maintain the device compliance signal that conditional access depends on, so that access decisions are made on verified state rather than assumption.
•Support internal and external audit with documented evidence of patch compliance, baseline configuration and exception governance.
Content Distribution, Regional Coverage and Shift Support
•Support devices and servers working the assigned shift and providing coverage across time zones.
•Manage content distribution to remote and bandwidth-constrained sites, including distribution point placement, boundary groups, peer cache, BranchCache and Delivery Optimization, and bandwidth throttling and scheduling.
•Schedule patch and application deployment windows to local business hours, so that a deployment does not land in the middle of a working day in another time zone.
•Complete a documented handover at the end of each shift covering running deployments, patch cycle status, open failures and pending actions, and verify the handover received at shift start.
•Coordinate with IT contacts and the service desk on deployment communications, failures and device-level escalations.
Automation, Reporting, Support and Documentation
•Develop PowerShell automation for recurring administration, reporting, remediation scripts and Intune proactive remediations, treating repeated manual work as a defect.
•Build and publish scheduled reporting on patch compliance for endpoints and servers, enrolment coverage, deployment success, baseline conformance and application inventory.
•Act as second and third level support for complex endpoint management issues, troubleshooting through to root cause.
•Author and maintain runbooks, packaging standards and technical documentation, and provide technical guidance and mentoring to less experienced engineers.
JOB COMPETENCIES (Skills & Abilities)
•Technical depth: Advanced, practical Microsoft Configuration Manager and Microsoft Intune administration across the co-management boundary, including site systems, client health, collections, policy and content.
•Patch management command: Manages a monthly cycle across workstations and servers, including update groups, automatic deployment rules, rings, deadlines, maintenance windows and reboot orchestration for clustered and dependent systems.
•Compliance rigor: Treats the patch cycle as a commitment rather than a best effort, pursues the non-compliant tail to cause, and governs exceptions with documented risk acceptance rather than letting them accumulate.
•Server patching judgement: Understands that a server is not a workstation — sequences reboots, respects clustering and dependencies, and agrees windows with application owners rather than applying a default schedule.
•Packaging discipline: Builds application packages that install silently, detect correctly, supersede cleanly and uninstall reliably, and holds others to the same standard.
•Deployment judgement: Uses pilot rings, phased rollout and deadlines deliberately, and knows when a deployment should be paused rather than pushed.
•Push and pull balance: Decides what is mandated and what is offered, so that self-service reduces support demand without weakening compliance on the software that matters.
•Security orientation: Applies configuration and security baselines consistently, remediates endpoint and server vulnerabilities within compliance timelines, and partners with information security on agent coverage and exclusions.
•Delivery capability: Plans content distribution, bandwidth and deployment timing for other time zones and supports users and servers outside the local working day.
•Automation mindset: Proficiency with PowerShell to automate administration, reporting and remediation, treating repeated manual work as a defect.
•Reporting discipline: Produces patch and compliance reporting on a fixed cadence that leadership, security and audit can rely on, without manual assembly each month.
•Operational discipline: Runbook-driven execution, adherence to change control, and structured validation before and after every deployment and patch cycle.
•Problem solving: Strong analytical skills with proven ability to identify root causes across client, policy, content, network, imaging and update layers.
•Change absorption: Tracks Microsoft’s endpoint management release and deprecation cadence and plans for it ahead of enforcement rather than after it.
•Handover discipline: Transfers ownership of running deployments, patch cycle status and open failures explicitly at shift boundaries.
•Documentation and knowledge transfer: Clear, maintainable runbooks and packaging documentation that reduce single-person dependency across shifts.
•Communication: Excellent written and verbal communication in English, including the ability to explain a deployment failure, a forced reboot or a compliance requirement to non-technical stakeholders.
•Accountability and autonomy: Owns the endpoint management platforms end to end and makes sound technical decisions with limited information.
•Leadership and mentoring: Provides guidance and technical leadership to less experienced engineers without holding formal authority.
MINIMUM QUALIFICATIONS (Knowledge & Experience)
•Bachelor’s degree in computer science, Information Technology, Engineering or a closely related field, or equivalent professional experience. (Required)
•7+ years of experience in endpoint engineering or systems administration, with substantial hands-on responsibility for enterprise endpoint management platforms. (Required)
•Demonstrated hands-on administration of Microsoft Configuration Manager, in any of its SCCM, MECM, MACM or current naming, including site systems, distribution points, boundary groups, collections, client health and site maintenance. (Required)
•Demonstrated hands-on administration of Microsoft Intune, including enrolment, device configuration profiles, compliance policies, endpoint security policies and Windows Autopilot. (Required)
•Demonstrated experience operating co-management, including workload transition from Configuration Manager to Intune. (Required)
•Demonstrated ownership of an enterprise patch management cycle for the workstation estate, including update groups, automatic deployment rules, rings, deadlines and compliance reporting. (Required)
•Demonstrated ownership of Windows server patching, including maintenance windows, reboot orchestration for clustered or dependent systems, and coordination with server and application owners. (Required)
•Demonstrated experience administering the software update infrastructure, including Software Update Point and WSUS health and maintenance, and Windows Update for Business or Windows Autopatch policy. (Required)
•Demonstrated experience with third-party application patching alongside Microsoft updates. (Required)
•Demonstrated Win32 and MSI application packaging capability, including detection rules, requirements, dependencies, supersedence and uninstall behavior. (Required)
•Demonstrated experience delivering applications both as required push deployments and as self-service through Software Center or Company Portal. (Required)
•Demonstrated experience with operating system deployment, including task sequences, image maintenance, driver packages and Windows Autopilot provisioning. (Required)
•Demonstrated experience with Windows feature update and servicing management, including rings, deadlines and upgrade readiness. (Required)
•Demonstrated experience maintaining configuration and security baselines, including CIS-aligned hardening and drift remediation. (Required)
•Demonstrated experience remediating endpoint and server findings from an enterprise vulnerability management program, with documented exceptions. (Required)
•Experience with Microsoft Defender for Endpoint onboarding, agent health and exclusion governance, and with the device compliance signal used by conditional access. (Required)
•Experience supporting a distributed estate across multiple time zones and region-aware deployment scheduling. (Required)
•Experience with BitLocker enablement and recovery key escrow, and with Windows LAPS or equivalent local administrator password management. (Preferred)
•Strong PowerShell scripting ability, including Intune proactive remediations and Configuration Manager reporting. (Required)
•Working knowledge of Active Directory, Entra ID, Group Policy and certificate services as they affect endpoint management. (Required)
•Experience operating within a formal change management process, including Change Advisory Board submission, rollback planning and post-implementation review. (Required)
•Experience working within a shift-based infrastructure team, including structured handover of running deployments and open failures. (Required)
•Professional proficiency in spoken and written English, sufficient to coordinate with global IT teams and regional contacts and to communicate with senior stakeholders. (Required)
•Certification such as Microsoft 365 Certified: Endpoint Administrator Associate (MD-102), or an equivalent Configuration Manager or Intune credential. (Preferred)
•ITIL 4 Foundation, or equivalent demonstrated knowledge of incident, change and problem practice. (Preferred)
Disclaimer: This job description indicates in general terms, the type and level of work performed as well as the typical responsibilities of employees in this classification and it may be changed by management at any time. Other duties may also apply. Nothing in this job description changes the at-will employment relationship existing between the Company and its employees.