SCCM / Intune / Windows Administrator (L3)
Indexed description
- Please note, this role is not able to offer visa transfer or sponsorship now or in the future**
This role will be responsible for maintaining endpoint health, software deployment services, device lifecycle management, compliance enforcement, vulnerability remediation, and advanced troubleshooting within a large-scale enterprise environment.
In this role, you will
Endpoint Management & Modern Device Administration
- Administer, maintain, and optimize Microsoft Intune and SCCM/MECM environments for enterprise endpoint management.
- Manage device enrollment, provisioning, imaging, deployment, and lifecycle activities across Windows endpoints.
- Implement and support Windows Autopilot and modern device management solutions.
- Configure compliance policies, configuration profiles, device restrictions, and endpoint governance standards.
- Manage co-management environments integrating SCCM and Intune.
- Monitor endpoint posture and ensure adherence to organizational technology standards.
- Package, test, deploy, and support enterprise applications using SCCM and Intune.
- Manage deployment of operating system patches, cumulative updates, feature updates, and third-party software patches.
- Monitor software distribution performance and deployment success metrics.
- Perform patch compliance reporting and remediation activities.
- Ensure endpoint systems remain compliant with security and operational standards.
- Coordinate patching schedules and maintenance windows with business and infrastructure teams.
- Support and administer Windows 10 and Windows 11 enterprise environments.
- Manage OS migrations, feature upgrades, image maintenance, and deployment strategies.
- Troubleshoot Windows operating system issues related to performance, reliability, and user experience.
- Administer Active Directory integration and Group Policy configurations.
- Maintain Windows security baselines and hardening standards.
- Support endpoint performance optimization initiatives and system lifecycle planning.
- Implement and maintain endpoint security controls aligned with enterprise security policies.
- Support Microsoft Defender for Endpoint, BitLocker encryption, and endpoint protection technologies.
- Conduct vulnerability assessments and coordinate remediation activities.
- Partner with cybersecurity teams to address security findings and policy compliance gaps.
- Ensure regulatory, audit, and organizational compliance requirements are met.
- Support Zero Trust and endpoint security initiatives.
- Diagnose and resolve complex SCCM client, Intune enrollment, software deployment, and endpoint configuration issues.
- Support enterprise endpoint infrastructure including management points, distribution points, software update points, and related services.
- Perform root cause analysis (RCA) for recurring incidents and service disruptions.
- Act as an L3 escalation point for critical endpoint management issues.
- Collaborate with server, network, cloud, and security teams to ensure seamless endpoint operations.
- Maintain system stability and improve endpoint service availability.
- Develop, maintain, and enhance PowerShell scripts for automation and operational efficiency.
- Automate routine administration, health checks, reporting, and remediation activities.
- Build operational dashboards and executive reporting metrics.
- Monitor endpoint health, deployment performance, compliance status, and service quality metrics.
- Identify opportunities to reduce manual effort through process automation and standardization.
- Maintain runbooks, standard operating procedures (SOPs), and technical documentation.
- Support audit activities and compliance reviews.
- Participate in Incident, Change, Problem, Release, and Configuration Management processes.
- Ensure all activities comply with ITIL and organizational governance standards.
- Maintain accurate records for system configurations, deployments, and operational changes.
- Microsoft Endpoint Configuration Manager (SCCM/MECM)
- Microsoft Intune
- Microsoft Endpoint Manager
- Windows Autopilot
- Co-Management Architecture
- Device Enrollment & Lifecycle Management
- Windows 10 Administration
- Windows 11 Administration
- Active Directory
- Group Policy Administration
- Windows Security Hardening
- Endpoint Configuration Management
- Microsoft Defender for Endpoint
- BitLocker Administration
- Endpoint Protection Policies
- Vulnerability Management
- Security Baselines
- Compliance Reporting
- PowerShell Scripting
- Windows Automation Frameworks
- Task Automation
- Operational Reporting Automation
- ServiceNow or other Enterprise ITSM Platforms
- Incident Management
- Change Management
- Problem Management
- Release Management
- Root Cause Analysis (RCA)
- SLA Management
- 8+ years of experience supporting enterprise Windows environments.
- Strong hands-on expertise in SCCM/MECM administration and Microsoft Intune.
- Experience managing enterprise endpoint deployments, patching, and compliance programs.
- Experience supporting large-scale Windows migration and modernization projects.
- Knowledge of ITIL Service Management practices.
- Experience working within managed services and SLA-driven environments.
- Proven experience supporting enterprise endpoint security initiatives.
- Medical/Dental/Vision/Life Insurance
- Paid holidays plus Paid Time Off
- 401(k) plan and contributions
- Long-term/Short-term Disability
- Paid Parental Leave
- Employee Stock Purchase Plan
We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply, even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
“Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search