G

SCCM Intune Engineer (Night Shift)

Gemological Institute of America
NewPosted today

LOCATION

GIA Services Private Limited · Onsite

EXPERIENCE

7+ Years

TYPE

FullTime

SALARY

Negotiable

SKILLS REQUIRED

PowerShellPatch ManagementLinux System AdministrationIdentity and Access Management

Job description

Overview

The SCCM / Intune Engineer oversees endpoint management platforms that build, configure, secure and patch the Windows estate. The role owns enterprise patch management and compliance across end-user devices and Windows servers, administers Microsoft Configuration Manager and Microsoft Intune across the co-management boundary, and operates an assigned night shift reporting to the Manager IT Infrastructure.

What you'll do

  • Manage the software update infrastructure end to end, including Software Update Point, WSUS, database maintenance, update classifications and products, synchronization health, Windows Update for Business and Windows Autopatch policy where used.
  • Run the full monthly patch cycle for workstations and Windows servers, including update groups, automatic deployment rules, pilot and production rings, deadlines, deferrals, user notifications, maintenance windows, reboot orchestration and ordering for clustered, dependent and business-critical servers.
  • Manage third-party application patching alongside Microsoft updates.
  • Report endpoint and server patch compliance against agreed targets to IT leadership, information security and audit, documenting risk acceptance and remediation dates for exceptions.
  • Investigate and remediate devices and servers that fail to patch, including client health, content, bandwidth, disk space and reboot-pending causes.
  • Perform and document structured pre-deployment and post-deployment validation for every cycle.
  • Administer Microsoft Configuration Manager, including site systems, distribution points, boundary groups, collections, client settings, client health remediation, console security roles, and site database and SQL maintenance.
  • Administer Microsoft Intune, including enrolment methods, device configuration profiles, compliance policies, endpoint security policies, filters and scope tags.
  • Manage co-management configuration and workload migration from Configuration Manager to Intune with a documented target state.
  • Maintain platform currency and health, including version upgrades, hotfixes, content distribution health, and Configuration Manager backup and recovery.
  • Monitor and report estate health, enrolment coverage and policy application, and act on devices that fall out of management.
  • Coordinate shared Intune tenant configuration with Apple and M365 platform engineers.
  • Package, test and deploy applications and updates through Configuration Manager and Intune, including Win32 app packaging, detection rules, requirements, dependencies, supersedence and uninstall behavior.
  • Deliver applications through required push deployments and self-service Software Center and Company Portal deployments.
  • Maintain the application catalogue, including license-restricted assignment, retirement of superseded packages and removal of software no longer entitled.
  • Establish and maintain packaging standards for silent installation, correct detection, clean supersedence, reliable uninstallation and documentation.
  • Coordinate deployments with application owners, including pilot rings, regional-business-hours scheduling, communication and rollback.
  • Investigate deployment failures to root cause across client, content, detection, dependency and network layers.
  • Build and maintain operating system images, task sequences and Windows Autopilot deployment profiles, maintaining parity between imaging and cloud provisioning paths.
  • Maintain driver packages and firmware update management across supported hardware models, including model introduction and retirement.
  • Manage Windows feature updates and version currency through servicing rings, deadlines, deferrals and upgrade readiness assessment.
  • Maintain provisioning integrations including domain and Entra join, BitLocker enablement and recovery key escrow, and Windows LAPS where deployed.
  • Follow and enforce change control, including Change Advisory Board submission, tested rollback and coordination of deployment windows with affected business teams.
  • Maintain configuration and security baselines, including CIS-aligned hardening where adopted, and remediate baseline drift.
  • Remediate endpoint and server findings from the enterprise vulnerability management program through verified closure with documented exceptions.
  • Maintain endpoint security agent coverage and health, including Microsoft Defender for Endpoint onboarding, attack surface reduction rules and exclusion governance.
  • Maintain the device compliance signal on which conditional access depends.
  • Support internal and external audit with documented evidence of patch compliance, baseline configuration and exception governance.
  • Support devices and servers during the assigned shift and provide coverage across time zones.
  • Manage content distribution to remote and bandwidth-constrained sites, including distribution point placement, boundary groups, peer cache, BranchCache, Delivery Optimization, bandwidth throttling and scheduling.
  • Schedule patch and application deployment windows to local business hours.
  • Complete and verify documented shift handovers covering running deployments, patch cycle status, open failures and pending actions.
  • Coordinate with IT contacts and the service desk on deployment communications, failures and device-level escalations.
  • Develop PowerShell automation for administration, reporting, remediation scripts and Intune proactive remediations.
  • Build and publish scheduled reporting on patch compliance, enrolment coverage, deployment success, baseline conformance and application inventory.
  • Provide second- and third-level support for complex endpoint management issues and troubleshoot through root cause.
  • Author and maintain runbooks, packaging standards and technical documentation, and provide technical guidance and mentoring to less experienced engineers.

What you'll need

  • Bachelor’s degree in computer science, Information Technology, Engineering or a closely related field, or equivalent professional experience.
  • 7+ years of experience in endpoint engineering or systems administration, with substantial hands-on responsibility for enterprise endpoint management platforms.
  • Demonstrated hands-on administration of Microsoft Configuration Manager, including SCCM, MECM, MACM or current naming, site systems, distribution points, boundary groups, collections, client health and site maintenance.
  • Demonstrated hands-on administration of Microsoft Intune, including enrolment, device configuration profiles, compliance policies, endpoint security policies and Windows Autopilot.
  • Demonstrated experience operating co-management, including workload transition from Configuration Manager to Intune.
  • Demonstrated ownership of an enterprise workstation patch management cycle, including update groups, automatic deployment rules, rings, deadlines and compliance reporting.
  • Demonstrated ownership of Windows server patching, including maintenance windows, reboot orchestration for clustered or dependent systems, and coordination with server and application owners.
  • Demonstrated experience administering software update infrastructure, including Software Update Point and WSUS health and maintenance, and Windows Update for Business or Windows Autopatch policy.
  • Demonstrated experience with third-party application patching alongside Microsoft updates.
  • Demonstrated Win32 and MSI application packaging capability, including detection rules, requirements, dependencies, supersedence and uninstall behavior.
  • Demonstrated experience delivering applications as required push deployments and as self-service through Software Center or Company Portal.
  • Demonstrated experience with operating system deployment, including task sequences, image maintenance, driver packages and Windows Autopilot provisioning.
  • Demonstrated experience with Windows feature update and servicing management, including rings, deadlines and upgrade readiness.
  • Demonstrated experience maintaining configuration and security baselines, including CIS-aligned hardening and drift remediation.
  • Demonstrated experience remediating endpoint and server findings from an enterprise vulnerability management program, with documented exceptions.
  • Experience with Microsoft Defender for Endpoint onboarding, agent health and exclusion governance, and with the device compliance signal used by conditional access.
  • Experience supporting a distributed estate across multiple time zones and region-aware deployment scheduling.
  • Strong PowerShell scripting ability, including Intune proactive remediations and Configuration Manager reporting.
  • Working knowledge of Active Directory, Entra ID, Group Policy and certificate services as they affect endpoint management.
  • Experience operating within a formal change management process, including Change Advisory Board submission, rollback planning and post-implementation review.
  • Experience working within a shift-based infrastructure team, including structured handover of running deployments and open failures.
  • Professional proficiency in spoken and written English, sufficient to coordinate with global IT teams and regional contacts and communicate with senior stakeholders.

Nice to have

  • Experience with BitLocker enablement and recovery key escrow, and with Windows LAPS or equivalent local administrator password management.
  • Certification such as Microsoft 365 Certified: Endpoint Administrator Associate (MD-102), or an equivalent Configuration Manager or Intune credential

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

SCCM Intune Engineer (Night Shift)