Position: SCCM Administration
Location: Taylor, TX (Hybrid, 2 days a Week)
Duration: 2 years of Contract (W2 Only)
We're looking for an experienced SCCM (Security Center Configuration Manager) Administrator to manage our endpoint infrastructure — spanning SCCM, Group Policy, Microsoft Intune, and third-party patch management tooling (Patch My PC). You'll own day-to-day administration of our Configuration Manager environment, drive governance and cleanup of our GPO landscape, and lead application deployment and co-management efforts through Intune. This role suits someone who's comfortable owning complex, multi-system environments and bringing order to them.
What You'll Do
SCCM
· Administer, deploy, and maintain SCCM infrastructure supporting software distribution, patch management, and endpoint security
· Build and maintain packages, applications, collections, and deployments
· Manage client health — troubleshooting agent issues, re-installs, and discovery/push methods
· Administer Software Update Point (SUP)/WSUS, including sync troubleshooting and Automatic Deployment Rule (ADR) management
· Own monthly Patch Tuesday cadence, including third-party patching via Patch My PC
· Manage Distribution Points and content distribution, monitoring for failures and DP health
· Configure and maintain boundaries/boundary groups for correct client site assignment and content routing
· Support OS Deployment (OSD) — task sequences for imaging/re-imaging and driver package management
· Use CMPivot for real-time device queries and rapid troubleshooting
· Configure maintenance windows and client settings
· Monitor system health and troubleshoot issues to ensure optimal performance
· Develop reports on deployment status, patch compliance, and hardware inventory
Group Policy
· Design, implement, and manage GPOs enforcing security baselines and configuration standards across the domain
· Inventory existing GPOs, map each to its business/technical purpose, and consolidate overlapping or deprecated policies into standardized baselines (Core, Security, Browsers, Office, Remote Access)
· Diagnose and resolve policy conflicts, replication issues, and slow processing using RSoP, GPResult, and Event Viewer
· Optimize GPO performance (link order, enforcement, WMI filters, item-level targeting)
· Establish governance and change control — test OU, approval workflow, rollback plans — and maintain documentation for audit and knowledge transfer
Intune
· Enroll and configure workstations for co-management between SCCM and Intune, including Windows Autopilot deployment
· Package, deploy, and monitor applications; manage Company Portal experience and troubleshoot enrollment issues
· Maintain compliance and configuration policies, including BitLocker management and app protection (MAM) policies
· Coordinate with Conditional Access policies to ensure compliance status supports access requirements
Cross-Functional
· Partner with other IT teams to integrate SCCM, GPO, Intune, and patch management tooling with broader infrastructure
· Enforce security best practices across all platforms
· Serve as a technical resource for other IT staff on SCCM/GPO/Intune matters
· Support software licensing and compliance reporting using SCCM inventory data as needed
· Keep current with platform updates and industry best practices
Required Qualifications
· Bachelor’s degree in Computer Information Systems, Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
· 5+ years administering SCCM in an enterprise environment
· Hands-on experience designing and troubleshooting GPOs in a multi-domain/multi-OU AD environment, including diagnosing conflicts and performance issues via RSoP, GPResult, and Event Viewer
· Strong knowledge of Windows Server, Active Directory, and core networking concepts
· PowerShell scripting experience, particularly for GPO management and reporting
· SQL Server proficiency for SCCM reporting and troubleshooting
· Experience with SQL Server Always On Availability Groups in a multi-server SCCM environment
· Experience building and customizing SSRS reports for SCCM beyond out-of-box reporting
· Hands-on Intune experience: co-management enrollment, application deployment, and Company Portal support
· Experience with PKI infrastructure and certificate management
· Experience with third-party patch management tools (Patch My PC or similar)
· Proficiency using CMTrace to sort through SCCM client/server logs, Windows Event Logs, IIS logs, and Patch My PC logs, with working knowledge of which specific logs to reference based on the issue (e.g., client install, policy, content, patching) to diagnose and resolve issues
· Strong troubleshooting, communication, and collaboration skills; able to work independently
Preferred Qualifications
· GPMC experience for modeling, testing, and auditing policy changes pre-deployment
· Configuration Manager Task Sequences and OSD imaging experience
· Power BI
· Windows Autopilot
· Virtualization (Hyper-V/VMware)
· ITIL framework familiarity