Performs hands-on vulnerability remediation, patch deployment, and endpoint hardening for enterprise endpoints. Uses Microsoft System Center Configuration Manager, also known as Microsoft Endpoint Configuration Manager, and related endpoint tooling to deliver stable, compliant outcomes with measurable reporting.
ESSENTIAL FUNCTIONS:
Review Qualys Vulnerability Management findings for endpoints and translate into actionable remediation work, including prioritization, patch selection, and closure validation through rescans.
Define, test, package, and deploy operating system and application patches in SCCM controlled deployment rings and maintenance schedules.
Create new Software Update Groups (SUGs) each month for workstations and servers, segregated by OS and environment if needed (e.g., prod, dev, test).
Schedule and configure deployments for new SUGs, defining appropriate maintenance windows, user notifications, and reboot behavior.
Implement endpoint hardening standards including security baselines, policy configurations, encryption posture support, and reduction of risky endpoint configurations.
Troubleshoot patch failures and post-change endpoint issues; coordinate with Service Desk and Field Services for remediation and device recovery.
Produce and maintain metrics for patch compliance, vulnerability aging, remediation success rates, and repeat findings; support service level agreement reporting.
Maintain documentation and knowledge articles for repeatable endpoint remediation processes.
REQUIRED QUALIFICATIONS:
Three or more years of direct, hands-on endpoint patching experience using Microsoft System Center Configuration Manager or Microsoft Endpoint Configuration Manager in a production enterprise.
Demonstrated experience executing patch testing, staged rollouts, deployment troubleshooting, and compliance verification.
Hands-on experience using Qualys Vulnerability Management reporting for remediation validation and closure.
PREFERRED QUALIFICIATIONS:
Hospital information technology experience strongly preferred; broader healthcare experience preferred.
Certifications highly desirable: Microsoft endpoint certifications, CompTIA Security+, or equivalent.
WORK SCHEDULE EXPECTATIONS:
Participation in scheduled maintenance windows as required.
EDUCATION:
Associate degree or equivalent combination of education and experience.