Windows Client Engineer responsible for enterprise endpoint management, vulnerability remediation, patching, application deployment, and Windows security hardening using Intune, SCCM, and PowerShell. Job Requirements Bachelor's degree or higher. 3-5 years of experience engineering and administering Windows endpoints in an enterprise environment. Proficiency with Microsoft Windows client and server operating systems. Hands-on experience with Microsoft Intune and SCCM/Configuration Manager. Experience with application packaging and deployment. Strong PowerShell scripting experience for automation, detection, and remediation. Experience with Windows patch management using Windows Update for Business, WSUS, SCCM software updates, or equivalent tools. Experience investigating and remediating endpoint vulnerabilities. Knowledge of vulnerability management concepts and tools. Understanding of CVEs, CVSS scoring, and vulnerability remediation processes. Knowledge of Windows OS internals, Active Directory, Group Policy, and Entra ID/Azure AD. Experience testing and deploying endpoint changes in production environments. Experience maintaining endpoint configuration baselines and compliance policies. Preferred Skills Experience with Tenable.io, Nessus, or Tenable Security Center. Experience with Qualys, Rapid7, or comparable vulnerability management platforms. Experience with PSADT, PatchMyPC, MSI, or MSIX application packaging. Experience with Microsoft Defender for Endpoint and Threat & Vulnerability Management. Knowledge of CIS Benchmarks and
DISA STIG
security hardening frameworks. Experience with Intune proactive remediations and SCCM configuration items. Experience with co-management, device onboarding, conditional access, and endpoint compliance policies. Microsoft MD-102 certification. Microsoft SC-200 certification. CompTIA Security+ certification. Job Responsibilities Review endpoint vulnerabilities identified through vulnerability scanning platforms and manage remediation through closure. Investigate vulnerability findings and determine appropriate endpoint remediation actions. Build, test, and deploy remediation packages using Intune and SCCM. Deploy application updates, patches, registry changes, configuration changes, and scripted fixes. Develop and maintain PowerShell scripts for vulnerability detection and remediation. Configure Intune proactive remediations and SCCM configuration items. Package and deploy third-party application updates. Manage Windows Update policies through Windows Update for Business, WSUS, SCCM, or related platforms. Monitor and validate endpoint patch compliance. Verify that deployed remediations resolve identified vulnerabilities. Investigate and document false-positive vulnerability findings. Track remediation progress, patch coverage, compliance levels, and outstanding vulnerabilities against defined SLAs. Maintain Windows endpoint configuration baselines and security hardening standards. Support Intune and SCCM co-management, device onboarding, compliance policies, and conditional access. Document remediation procedures, deployment processes, and endpoint configuration standards. Test remediation packages and configuration changes before production deployment.
Pay Details:
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable: The California Fair Chance Act Los Angeles City Fair Chance Ordinance Los Angeles County Fair Chance Ordinance for
Employers San Francisco Fair Chance Ordinance Massachusetts Candidates Only:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.