Endpoint Administrator Associate
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
The L2 Senior Patch Management Engineer owns the end-to-end patch lifecycle for the end-user computing environment. Responsibilities include designing and maintaining patching baselines, automating patch workflows, resolving complex deployment failures, and acting as an escalation point for L1 analysts. The role also involves continuous improvement of patch tooling and processes., * Own the patch management lifecycle: assessment, testing, approval, deployment, validation, and reporting for all EUC endpoints.
-
Design and maintain software update groups, collections, and deployment rules in SCCM/MECM and Microsoft Intune.
-
Develop and maintain PowerShell / WMI scripts to automate patch compliance checks, remediation, and reporting.
-
Act as L2 escalation for patch deployment failures, application compatibility issues, and non-compliant device investigations.
-
Conduct patch testing in pilot/UAT rings before production rollout; document test results and obtain change approval.
-
Integrate Qualys / Tenable vulnerability scan data to drive patch prioritisation based on CVSS scores.
-
Define and enforce patching SLAs for Critical, High, Medium, and Low severity patches per security policy.
-
Maintain and improve the patch management runbook, SOPs, and exception handling process.
-
Collaborate with security operations (SOC) to address zero-day threats and emergency patch deployments.
-
Produce monthly patch compliance reports and trend analysis for management review.
-
Mentor and guide L1 analysts; review their tickets and provide technical feedback.
Requirements
-
Deep expertise in SCCM/MECM - software update point, ADRs, deployment rings, client health.
-
Hands-on experience with Microsoft Intune / Autopilot / Windows Update for Business.
-
Advanced PowerShell scripting for automation (compliance remediation, report extraction, deployment triggers).
-
Experience with vulnerability management tools: Qualys, Tenable Nessus, or Rapid7 InsightVM.
-
Knowledge of Windows OS lifecycle, patch Tuesday cycle, CBS, WUA, and WinSxS.
-
Familiarity with macOS patch management (Jamf Pro / Munki) is an advantage.
-
Understanding of BitLocker, Windows Defender, and endpoint security baselines (CIS / STIG).
-
Experience integrating patch workflows with ServiceNow ITSM and CMDB.
-
Working knowledge of Azure AD, Entra ID, and Conditional Access policies.
SOFT SKILLS & COMPETENCIES
-
Strong analytical and troubleshooting skills for complex patch failures.
-
Excellent documentation skills - able to produce clear SOPs, RCAs, and change records.
-
Effective communicator across technical and non-technical stakeholders.
-
Proactive mindset - identifies process gaps and proposes improvements.
-
Ability to manage concurrent workstreams under deadline pressure.
PREFERRED CERTIFICATIONS
-
Microsoft 365 Certified: Endpoint Administrator Associate (MD-102)
-
Microsoft Certified: Azure Administrator Associate (AZ-104)
-
CompTIA Security+ or CySA+
-
ITIL 4 Managing Professional (or Foundation)
-
Qualys Certified Specialist - Vulnerability Management
Benefits & conditions
A candidate’s pay within the range will depend on their skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters
Everything a Developer Needs to Know About MCP with Neo4j