Senior Cybersecurity Patch and Endpoint Management Engineer

Job description

Senior Cybersecurity Patch & Endpoint Management Engineer

Position Overview

The Senior Cybersecurity Patch & Endpoint Management Engineer serves as the technical subject matter expert for enterprise patch management, endpoint engineering, vulnerability remediation, identity security, compliance enforcement, and cybersecurity automation across client, server, cloud, and hybrid environments.

This role supports a complex enterprise environment consisting of approximately 3,000 managed endpoints, including Windows workstations, Windows and Linux servers, Azure-hosted systems, virtual desktop infrastructure (VDI), mobile devices, and hybrid cloud workloads.

The ideal candidate will possess deep expertise across Microsoft Entra ID, Microsoft Defender XDR, CrowdStrike Falcon, Public Key Infrastructure (PKI), Windows Autopilot, Microsoft Intune, Azure Update Manager, Patch My PC, Kusto Query Language (KQL), PowerShell automation, and enterprise vulnerability management programs.

This position plays a critical role in strengthening organizational security posture by driving security compliance, reducing cyber risk, automating remediation processes, and ensuring adherence to cybersecurity standards, regulatory requirements, and vulnerability management objectives across the enterprise.

Primary Responsibilities

Enterprise Patch Management & Vulnerability Remediation

Serve as the enterprise owner for patch management and vulnerability remediation programs.

Responsibilities include:

Developing and maintaining patching strategies across:

Windows Server

Linux Server

Windows Client

macOS and iOS

Android

Citrix and VMware Horizon virtual desktops

Azure Virtual Machines

Azure Arc-managed systems

Microsoft 365 services

Third-party applications

Managing and optimizing:

Azure Update Manager

Microsoft 365 update channels

Patch My PC

Microsoft Intune Update Rings

Microsoft Configuration Manager (where applicable)

Establishing patch deployment rings, pilot groups, production deployments, rollback strategies, and emergency remediation procedures.

Leading remediation efforts for critical and actively exploited vulnerabilities.

Developing automated workflows for:

Vulnerability identification

Risk prioritization

Patch deployment

Validation testing

Compliance reporting

Partnering with Security Operations teams to ensure remediation objectives and service levels are achieved.

Building executive dashboards that provide visibility into patch compliance, risk exposure, and remediation progress.

Microsoft Entra ID (Expert Level)

Serve as the technical authority for Microsoft Entra ID, identity security, authentication services, identity governance, privileged access management, and Zero Trust identity architecture.

Responsibilities

Design and maintain enterprise identity architectures.

Implement and support:

Conditional Access

Identity Protection

Access Reviews

Entitlement Management

Identity Governance

Authentication Methods

Manage hybrid identity integrations.

Support SAML, OAuth, OpenID Connect, SCIM, and federation-based authentication solutions.

Conduct identity security assessments and remediation activities.

Develop and maintain Zero Trust identity architectures.

Support secure integrations between enterprise SaaS applications and Microsoft Entra ID.

CrowdStrike Falcon Vulnerability Management (Expert Level)

Serve as the technical lead for enterprise vulnerability management, providing strategic oversight and operational leadership for risk reduction initiatives.

Responsibilities

Administer and optimize CrowdStrike Falcon and Falcon Spotlight across workstation, server, cloud, and hybrid environments.

Own vulnerability identification, prioritization, remediation coordination, validation, and reporting processes.

Develop enterprise vulnerability management procedures aligned with cybersecurity policies, risk frameworks, and compliance requirements.

Analyze vulnerability intelligence, exploitability data, threat intelligence, and business impact to prioritize remediation efforts.

Collaborate with Security, Infrastructure, Service Desk, and Operations teams to remediate critical vulnerabilities.

Establish remediation SLAs, metrics, and reporting.

Develop executive dashboards highlighting vulnerability trends, remediation progress, compliance posture, and organizational risk.

Lead mitigation efforts for high-risk vulnerabilities when patching is not immediately feasible.

Integrate vulnerability intelligence with Microsoft Defender, Intune, Azure, patching platforms, SIEM solutions, and security operations workflows.

Support audits, compliance assessments, penetration testing activities, and security reviews.

Develop automated remediation solutions utilizing PowerShell, Microsoft Graph, Azure Automation, APIs, and related technologies.

Monitor emerging threats, active exploit campaigns, and zero-day vulnerabilities.

Advance vulnerability management governance aligned to NIST, CIS Controls, Zero Trust principles, and industry best practices.

Endpoint Engineering & Microsoft Intune (Expert Level)

Serve as the technical authority for modern endpoint management, endpoint security, device lifecycle management, and Microsoft Intune administration.

Responsibilities

Design, implement, and support Microsoft Intune across Windows, macOS, iOS/iPadOS, Android, and hybrid-managed devices.

Architect and manage MDM, MAM, and modern endpoint management solutions.

Develop configuration profiles, compliance policies, security baselines, administrative templates, endpoint privilege management policies, and application protection policies.

Design and support Windows Autopilot deployment solutions.

Manage the complete device lifecycle, including enrollment, provisioning, configuration, software deployment, monitoring, retirement, and decommissioning.

Integrate Intune with Microsoft Entra ID, Microsoft Defender XDR, Conditional Access, and related Microsoft technologies.

Implement endpoint security controls aligned with Zero Trust principles and cybersecurity requirements.

Configure and manage Windows Update for Business, feature updates, quality updates, driver updates, and expedited security updates.

Develop proactive remediation solutions utilizing PowerShell, Microsoft Graph API, and Intune Remediations.

Support environments consisting of approximately 3,000 managed endpoints while maintaining high levels of security, availability, and operational efficiency.

Windows Autopilot (Expert Level)

Serve as the technical authority for Windows Autopilot, modern device provisioning, zero-touch deployment, endpoint onboarding, and lifecycle management.

Responsibilities

Design and maintain Windows Autopilot deployment strategies.

Support:

User-Driven Deployments

Pre-Provisioning

Self-Deploying Mode

Hybrid Entra Join

Microsoft Entra Join

Manage device registration, hardware hash imports, deployment profiles, dynamic group assignments, and enrollment status page configurations.

Develop zero-touch deployment strategies for remote and distributed workforces.

Automate:

Device Enrollment

Application Deployment

Security Baseline Enforcement

Compliance Policy Assignment

Certificate Deployment

Endpoint Security Configuration

Support large-scale device refreshes, deployment modernization efforts, and merger and acquisition integrations.

Establish KPIs around deployment success, onboarding efficiency, compliance attainment, and reduction of manual deployment activities.

Compliance, Security & Risk Management

Partner with Security, Risk, Audit, and Compliance teams.

Support compliance requirements aligned to:

NIST

CIS Controls

Zero Trust Framework

Internal Security Standards

Develop remediation plans for audit findings.

Maintain compliance reporting and evidence collection.

Support risk reduction initiatives and continuous security improvement programs.

Advanced Automation & Scripting (Expert Level)

Serve as the technical authority for enterprise automation, scripting, configuration management, and remediation engineering.

Technical Expertise

PowerShell

PowerShell Desired State Configuration (DSC)

Microsoft Graph API

Microsoft Graph PowerShell SDK

Azure Automation

Azure Logic Apps

Azure Functions

REST APIs

JSON Integrations

Microsoft Intune Remediations

Responsibilities

Automate patch deployment workflows across endpoints, servers, cloud workloads, and third-party applications.

Develop automated vulnerability remediation processes.

Automate device onboarding, provisioning, configuration, and lifecycle management.

Create compliance validation and remediation scripts.

Develop enterprise reporting for:

Patch Compliance

Vulnerability Exposure

Device Health

Security Posture

Certificate Status

Integrate Microsoft, security, ITSM, and monitoring platforms through APIs and automation.

Build reusable automation frameworks that improve operational efficiency and reduce manual intervention.

Maintain enterprise standards for secure scripting, source control, testing, documentation, and change management.

Advanced Analytics & KQL

Develop advanced analytics and reporting solutions using Kusto Query Language (KQL) supporting:

Microsoft Defender

Microsoft Sentinel

Microsoft Entra ID

Azure Log Analytics

Security Operations

Deliver:

Threat Analytics

Security Reporting

Compliance Reporting

Vulnerability Trending

Executive Dashboards

Required Qualifications

7+ years of experience in cybersecurity, infrastructure engineering, endpoint engineering, or systems engineering.

5+ years leading enterprise patch management and vulnerability remediation initiatives.

Experience supporting environments with 3,000+ managed endpoints.

Expert-level Microsoft Intune administration and engineering.

Expert-level Microsoft Entra ID administration and identity governance.

Expert-level Microsoft Defender XDR administration.

Advanced CrowdStrike Falcon administration experience.

Advanced PKI and certificate services administration.

Advanced PowerShell automation and scripting experience.

Experience supporting cloud, hybrid, and on-premises environments.

Strong understanding of cybersecurity frameworks and security controls.

Strong communication and executive presentation skills.

Preferred Certifications

Microsoft Certified Cybersecurity Architect Expert

Microsoft Certified Identity and Access Administrator Associate

Microsoft Certified Security Operations Analyst Associate

Microsoft Certified Endpoint Administrator Associate

Microsoft Certified Azure Administrator Associate

Microsoft Certified Azure Security Engineer Associate

CompTIA Security+

CrowdStrike Falcon Certification

ITIL Foundation

Success Measures

Success in this role will be measured by:

Maintaining 95%+ patch compliance across enterprise endpoints.

Reducing critical vulnerability remediation timelines.

Increasing automated remediation rates.

Improving Microsoft Secure Score and exposure metrics.

Reducing endpoint-related security incidents.

Maintaining audit and compliance readiness.

Strengthening overall endpoint security posture.

Improving deployment success rates for Microsoft and third-party updates.

Reducing operational effort through automation.

Lowering enterprise cyber risk through proactive remediation.

Ideal Candidate

The ideal candidate is a cybersecurity-focused engineering leader who combines deep expertise in enterprise patch management, vulnerability remediation, identity security, endpoint engineering, PKI, automation, compliance, and cloud technologies.

This individual is equally comfortable leading enterprise security initiatives, developing advanced PowerShell automation, building KQL-based analytics and reporting solutions, architecting secure identity frameworks, administering Microsoft and CrowdStrike security platforms, and driving risk-focused remediation programs across a large-scale enterprise environment.

Most importantly, this person consistently looks for opportunities to reduce risk, automate operations, improve compliance, strengthen security posture, and simplify enterprise technology management.

Job details

Job type Contract

Location ATL, GA

Reference JOB-5470

Apply now

"*" indicates required fields

Step 1 of 3

Accepted file types: pdf, doc, docx, txt, Max. file size: 4 MB.
If hired, will you now or in the future require sponsorship for employment visa status (e.g., H-1B visa)?
Employment with Tier4 Group and our clients may be contingent upon successfully passing a background check, in compliance with applicable laws. Do you consent to a background check if offered employment?
Are you legally authorized to work in the United States?*