WINDOWS CLIENT ENGINEER - HYBRID PITTSBURGH

A.C. Coy • $88K — $105K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required.
  • 3-5 years engineering and administering Windows endpoints in enterprise environments.
  • Hands-on experience with Microsoft Intune and SCCM, including application packaging and deployment.
  • Strong PowerShell scripting skills for automation and remediation.
  • Experience with Windows patch management systems (Windows Update for Business, WSUS, SCCM).
  • Familiarity with vulnerability management concepts, particularly with Tenable.
  • Solid understanding of Windows OS internals and Active Directory.

Responsibilities

  • Manage and modernize Windows endpoint estate using Intune and SCCM.
  • Review vulnerabilities from Tenable and lead remediation workflow from finding to closure.
  • Build, test, and deploy remediation packages and solutions for endpoints.
  • Author and maintain PowerShell scripts for proactive remediation in Intune and SCCM.
  • Package and deploy third-party application updates outside standard Microsoft patching.
  • Manage Windows Update policies for compliance and reporting accuracy.
  • Document remediation procedures to facilitate a consistent deployment process.

Benefits

  • Hybrid work model (3 days onsite, 2 days remote).
  • Engagement with cutting-edge security tools and methodologies.
  • Opportunity to work closely with a dedicated security team.
  • Support for professional development through certifications.
Full Job Description
Overview

Location: Hybrid in Pittsburgh., PA (3 days onsite, 2 days remote)

Job Type: Full Time / Contract

Work Authorization: No Sponsorship

The A.C.Coy company has an immediate opening for a Microsoft Windows Client Engineer. Ideal candidates must have 3- 5 years of experience engineering and administering Microsoft Windows endpoints in an enterprise environment. Hands-on experience with Microsoft Intune and SCCM/Configuration Manager including application packaging and deployment is also required.

Responsibilities

Windows Client Engineer to manage and modernize the Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk. This is a hands-on engineering role: partner closely with the security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.
  • Review outstanding vulnerabilities identified by Tenable Nessus / Tenable Security Center and own the endpoint-side remediation workflow from finding to closure
  • Build, test, and deploy remediation packages and solutions using Intune and SCCM - application updates, patches, registry and configuration changes, and scripted fixes
  • Author and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration items
  • Package and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC)
  • Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accurate
  • Partner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positives
  • Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs
  • Maintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleet
  • Support co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environment
  • Document remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production


Qualifications

Education:
  • Bachelor's degree - Required

Certifications:
  • Microsoft MD - 102, SC - 200, or CompTIA Security+ - Preferred

Responsibilities:
  • Experience engineering and administering Windows endpoints in an enterprise environment - 3-5 years
  • Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment
  • Strong PowerShell scripting skills for automation, detection, and remediation
  • Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates)
  • Familiarity with vulnerability management concepts and tooling - Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevant
  • Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions
  • Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD)
  • Ability to test changes carefully and roll out fixes without disrupting end users
  • Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX - Preferred
  • Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration - Preferred
  • Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs) - Preferred

Similar Jobs

More Jobs at A.C. Coy

More Information Technology Jobs

Find similar WINDOWS CLIENT ENGINEER - HYBRID PITTSBURGH jobs: