Windows Engineer (Client/Endpoint) - Local Applicants Only
A.C.Coy Company
APPLICANTS MUST BE LOCAL TO PITTSBURGH, PA No 3rd Parties/Sub Vendos Location: Hybrid in Pittsburgh., PA (3 days onsite, 2 days remote) Job Type: 1 year Contract Work Authorization: U.S. Citizen or Green Card Holders Only Overview: The A.C.Coy company has...
Job description
Responsibilities:
The Windows Client Engineer will manage and modernize the Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk. This is a hands-on engineering role: partner closely with the security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.
Review outstanding vulnerabilities identified by Tenable Nessus / Tenable Security Center and own the endpoint-side remediation workflow from finding to closureBuild, test, and deploy remediation packages and solutions using Intune and SCCM — application updates, patches, registry and configuration changes, and scripted fixesAuthor and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration itemsPackage and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC)Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accuratePartner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positivesTrack remediation progress and report on compliance, patch coverage, and outstanding risk against SLAsMaintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleetSupport co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environmentDocument remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production
Education:
Bachelor's degree - Required
Certifications:
Microsoft MD - 102, SC - 200, or CompTIA Security+ - Preferred
Responsibilities:
Experience engineering and administering Windows endpoints in an enterprise environment - 3-5 yearsHands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deploymentStrong PowerShell scripting skills for automation, detection, and remediationExperience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates)Familiarity with vulnerability management concepts and tooling — Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevantUnderstanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actionsSolid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD)Ability to test changes carefully and roll out fixes without disrupting end usersExperience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX - PreferredExposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration - PreferredKnowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs) - Preferred