WINDOWS CLIENT ENGINEER - HYBRID PITTSBURGH

A.C. Coy • $85K — $100K *
US-AnywhereRemote in Pittsburgh, PA
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required.
  • 3-5 years experience in Windows endpoint engineering and administration in an enterprise environment.
  • Hands-on experience with Microsoft Intune and SCCM, including application packaging and deployment.
  • Strong PowerShell scripting skills for automation and remediation.
  • Familiarity with vulnerability management tools; Tenable experience preferred.

Responsibilities

  • Manage and modernize Windows endpoint estate using Intune and SCCM with a focus on vulnerability risk reduction.
  • Review and address vulnerabilities identified by Tenable, owning the remediation process from finding to closure.
  • Build and deploy remediation packages and solutions, including application updates and patches using Intune/SCCM.
  • Author and maintain remediation scripts, including detection logic for proactive remediations in Intune.
  • Package and deploy third-party application updates beyond standard Microsoft patching.
  • Collaborate with security teams to triage vulnerability findings and validate deployed fixes.
  • Maintain compliance reporting and track remediation progress against SLAs.

Benefits

  • Flexible hybrid work arrangement (3 days onsite, 2 days remote).
  • Collaborative and dynamic work environment.
  • Opportunity to work with the latest technology and tools.
  • Professional development opportunities.
Full Job Description
Overview

Location: Hybrid in Pittsburgh., PA (3 days onsite, 2 days remote)

Job Type: Full Time / Contract

Work Authorization: No Sponsorship

 

The A.C.Coy company has an immediate opening for a Microsoft Windows Client Engineer.  Ideal candidates must have 3- 5 years of experience engineering and administering Microsoft Windows endpoints in an enterprise environment.  Hands-on experience with Microsoft Intune and SCCM/Configuration Manager including application packaging and deployment is also required.  

Responsibilities

Windows Client Engineer to manage and modernize the Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk. This is a hands-on engineering role: partner closely with the security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.

  • Review outstanding vulnerabilities identified by Tenable Nessus / Tenable Security Center and own the endpoint-side remediation workflow from finding to closure
  • Build, test, and deploy remediation packages and solutions using Intune and SCCM — application updates, patches, registry and configuration changes, and scripted fixes
  • Author and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration items
  • Package and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC)
  • Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accurate
  • Partner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positives
  • Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs
  • Maintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleet
  • Support co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environment
  • Document remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production
Qualifications

Education:

  • Bachelor's degree - Required

Certifications:

  • Microsoft MD - 102, SC - 200, or CompTIA Security+ - Preferred

Responsibilities:

  • Experience engineering and administering Windows endpoints in an enterprise environment - 3-5 years
  • Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment
  • Strong PowerShell scripting skills for automation, detection, and remediation
  • Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates)
  • Familiarity with vulnerability management concepts and tooling — Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevant
  • Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions
  • Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD)
  • Ability to test changes carefully and roll out fixes without disrupting end users
  • Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX - Preferred 
  • Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration - Preferred
  • Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs) - Preferred

Similar Jobs

More Jobs at A.C. Coy

More Information Technology Jobs

Find similar WINDOWS CLIENT ENGINEER - HYBRID PITTSBURGH jobs: