WINDOWS CLIENT ENGINEER - HYBRID PITTSBURGH
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Sep 29, 2026
Overview
Location: Hybrid in Pittsburgh., PA (3 days onsite, 2 days remote)
Job Type: Full Time / Contract
Work Authorization: No Sponsorship
The A.C.Coy company has an immediate opening for a Microsoft Windows Client Engineer. Ideal candidates must have 3- 5 years of experience engineering and administering Microsoft Windows endpoints in an enterprise environment. Hands-on experience with Microsoft Intune and SCCM/Configuration Manager including application packaging and deployment is also required.
Responsibilities
Windows Client Engineer to manage and modernize the Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk. This is a hands-on engineering role: partner closely with the security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.
- Review outstanding vulnerabilities identified by Tenable Nessus / Tenable Security Center and own the endpoint-side remediation workflow from finding to closure
- Build, test, and deploy remediation packages and solutions using Intune and SCCM — application updates, patches, registry and configuration changes, and scripted fixes
- Author and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration items
- Package and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC)
- Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accurate
- Partner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positives
- Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs
- Maintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleet
- Support co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environment
- Document remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production
Qualifications
Education:
- Bachelor's degree - Required
Certifications:
- Microsoft MD - 102, SC - 200, or CompTIA Security+ - Preferred
Responsibilities:
- Experience engineering and administering Windows endpoints in an enterprise environment - 3-5 years
- Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment
- Strong PowerShell scripting skills for automation, detection, and remediation
- Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates)
- Familiarity with vulnerability management concepts and tooling — Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevant
- Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions
- Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD)
- Ability to test changes carefully and roll out fixes without disrupting end users
- Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX - Preferred
- Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration - Preferred
- Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs) - Preferred