Windows Client Engineer responsible for enterprise endpoint management, vulnerability remediation, patching, application deployment, and Windows security hardening using Intune, SCCM, and PowerShell.

Job Requirements

  • Bachelor’s degree or higher.

  • 3–5 years of experience engineering and administering Windows endpoints in an enterprise environment.

  • Proficiency with Microsoft Windows client and server operating systems.

  • Hands-on experience with Microsoft Intune and SCCM/Configuration Manager.

  • Experience with application packaging and deployment.

  • Strong PowerShell scripting experience for automation, detection, and remediation.

  • Experience with Windows patch management using Windows Update for Business, WSUS, SCCM software updates, or equivalent tools.

  • Experience investigating and remediating endpoint vulnerabilities.

  • Knowledge of vulnerability management concepts and tools.

  • Understanding of CVEs, CVSS scoring, and vulnerability remediation processes.

  • Knowledge of Windows OS internals, Active Directory, Group Policy, and Entra ID/Azure AD.

  • Experience testing and deploying endpoint changes in production environments.

  • Experience maintaining endpoint configuration baselines and compliance policies.

Preferred Skills

  • Experience with Tenable.io, Nessus, or Tenable Security Center.

  • Experience with Qualys, Rapid7, or comparable vulnerability management platforms.

  • Experience with PSADT, PatchMyPC, MSI, or MSIX application packaging.

  • Experience with Microsoft Defender for Endpoint and Threat & Vulnerability Management.

  • Knowledge of CIS Benchmarks and DISA STIG security hardening frameworks.

  • Experience with Intune proactive remediations and SCCM configuration items.

  • Experience with co-management, device onboarding, conditional access, and endpoint compliance policies.

  • Microsoft MD-102 certification.

  • Microsoft SC-200 certification.

  • CompTIA Security+ certification.

Job Responsibilities

  • Review endpoint vulnerabilities identified through vulnerability scanning platforms and manage remediation through closure.

  • Investigate vulnerability findings and determine appropriate endpoint remediation actions.

  • Build, test, and deploy remediation packages using Intune and SCCM.

  • Deploy application updates, patches, registry changes, configuration changes, and scripted fixes.

  • Develop and maintain PowerShell scripts for vulnerability detection and remediation.

  • Configure Intune proactive remediations and SCCM configuration items.

  • Package and deploy third-party application updates.

  • Manage Windows Update policies through Windows Update for Business, WSUS, SCCM, or related platforms.

  • Monitor and validate endpoint patch compliance.

  • Verify that deployed remediations resolve identified vulnerabilities.

  • Investigate and document false-positive vulnerability findings.

  • Track remediation progress, patch coverage, compliance levels, and outstanding vulnerabilities against defined SLAs.

  • Maintain Windows endpoint configuration baselines and security hardening standards.

  • Support Intune and SCCM co-management, device onboarding, compliance policies, and conditional access.

  • Document remediation procedures, deployment processes, and endpoint configuration standards.

  • Test remediation packages and configuration changes before production deployment.



Pay Details: $45.00 to $52.00 per hour

Benefit offerings available for our associates include medical, dental, vision, life insurance, short-term disability, additional voluntary benefits, EAP program, commuter benefits and a 401K plan. Our benefit offerings provide employees the flexibility to choose the type of coverage that meets their individual needs. In addition, our associates may be eligible for paid leave including Paid Sick Leave or any other paid leave required by Federal, State, or local law, as well as Holiday pay where applicable.

Equal Opportunity Employer/Veterans/Disabled

Military connected talent encouraged to apply

To read our Candidate Privacy Information Statement, which explains how we will use your information, please

The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
  • The California Fair Chance Act
  • Los Angeles City Fair Chance Ordinance
  • Los Angeles County Fair Chance Ordinance for Employers
  • San Francisco Fair Chance Ordinance


Massachusetts Candidates Only: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Equal Opportunity Employer/Veterans/Disabled
The Company will consider qualified applicants with arrest and conviction records.

  • Flex your reach.

    When you work with us, you gain access to our expansive network of top companies that are searching for engineering and technical talent just like you.

  • Leverage our reputation.

    Sometimes it's not about what you know, but who you know. And when you know us, you're getting your foot in the right doors, shaking the right hands, and landing in the right spots.

  • Let us go to bat for you.

    We'll make sure your resume, interview techniques, and technical training and certification are in line to shine with your next potential employer. We know what they're looking for, and we know how to help you stand out.