A.C.Coy logo

WINDOWS CLIENT ENGINEER - HYBRID PITTSBURGH

Hiring from
United States
Work type
Hybrid
Posted
Sep 29, 2026
Is this job info correct?

Overview

Location: Hybrid in Pittsburgh., PA (3 days onsite, 2 days remote)

Job Type: Full Time / Contract

Work Authorization: No Sponsorship

The A.C.Coy company has an immediate opening for a Microsoft Windows Client Engineer. Ideal candidates must have 3- 5 years of experience engineering and administering Microsoft Windows endpoints in an enterprise environment. Hands-on experience with Microsoft Intune and SCCM/Configuration Manager including application packaging and deployment is also required.

Responsibilities

Windows Client Engineer to manage and modernize the Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk. This is a hands-on engineering role: partner closely with the security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.

  • Review outstanding vulnerabilities identified by Tenable Nessus / Tenable Security Center and own the endpoint-side remediation workflow from finding to closure
  • Build, test, and deploy remediation packages and solutions using Intune and SCCM — application updates, patches, registry and configuration changes, and scripted fixes
  • Author and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration items
  • Package and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC)
  • Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accurate
  • Partner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positives
  • Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs
  • Maintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleet
  • Support co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environment
  • Document remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production

Qualifications

Education:

  • Bachelor's degree - Required

Certifications:

  • Microsoft MD - 102, SC - 200, or CompTIA Security+ - Preferred

Responsibilities:

  • Experience engineering and administering Windows endpoints in an enterprise environment - 3-5 years
  • Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment
  • Strong PowerShell scripting skills for automation, detection, and remediation
  • Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates)
  • Familiarity with vulnerability management concepts and tooling — Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevant
  • Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions
  • Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD)
  • Ability to test changes carefully and roll out fixes without disrupting end users
  • Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX - Preferred
  • Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration - Preferred
  • Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs) - Preferred

Similar jobs

Apply for this job