Senior Cybersecurity Patch & Endpoint Management Engineer
Position Overview
The Senior Cybersecurity Patch & Endpoint Management Engineer serves as the technical subject matter expert for enterprise patch management, endpoint engineering, vulnerability remediation, identity security, compliance enforcement, and cybersecurity automation across client, server, cloud, and hybrid environments.
This role supports a complex enterprise environment consisting of approximately 3,000 managed endpoints, including Windows workstations, Windows and Linux servers, Azure-hosted systems, virtual desktop infrastructure (VDI), mobile devices, and hybrid cloud workloads.
The ideal candidate will possess deep expertise across Microsoft Entra ID, Microsoft Defender XDR, CrowdStrike Falcon, Public Key Infrastructure (PKI), Windows Autopilot, Microsoft Intune, Azure Update Manager, Patch My PC, Kusto Query Language (KQL), PowerShell automation, and enterprise vulnerability management programs.
This position plays a critical role in strengthening organizational security posture by driving security compliance, reducing cyber risk, automating remediation processes, and ensuring adherence to cybersecurity standards, regulatory requirements, and vulnerability management objectives across the enterprise.
Primary Responsibilities
Enterprise Patch Management & Vulnerability Remediation
Serve as the enterprise owner for patch management and vulnerability remediation programs.
Responsibilities include:
Developing and maintaining patching strategies across:
Windows Server
Linux Server
Windows Client
macOS and iOS
Android
Citrix and VMware Horizon virtual desktops
Azure Virtual Machines
Azure Arc-managed systems
Microsoft 365 services
Third-party applications
Managing and optimizing:
Azure Update Manager
Microsoft 365 update channels
Patch My PC
Microsoft Intune Update Rings
Microsoft Configuration Manager (where applicable)
Establishing patch deployment rings, pilot groups, production deployments, rollback strategies, and emergency remediation procedures.
Leading remediation efforts for critical and actively exploited vulnerabilities.
Developing automated workflows for:
Vulnerability identification
Risk prioritization
Patch deployment
Validation testing
Compliance reporting
Partnering with Security Operations teams to ensure remediation objectives and service levels are achieved.
Building executive dashboards that provide visibility into patch compliance, risk exposure, and remediation progress.
Microsoft Entra ID (Expert Level)
Serve as the technical authority for Microsoft Entra ID, identity security, authentication services, identity governance, privileged access management, and Zero Trust identity architecture.
Responsibilities
Design and maintain enterprise identity architectures.
Implement and support:
Conditional Access
Identity Protection
Access Reviews
Entitlement Management
Identity Governance
Authentication Methods
Manage hybrid identity integrations.
Support SAML, OAuth, OpenID Connect, SCIM, and federation-based authentication solutions.
Conduct identity security assessments and remediation activities.
Develop and maintain Zero Trust identity architectures.
Support secure integrations between enterprise SaaS applications and Microsoft Entra ID.
CrowdStrike Falcon Vulnerability Management (Expert Level)
Serve as the technical lead for enterprise vulnerability management, providing strategic oversight and operational leadership for risk reduction initiatives.
Responsibilities
Administer and optimize CrowdStrike Falcon and Falcon Spotlight across workstation, server, cloud, and hybrid environments.
Own vulnerability identification, prioritization, remediation coordination, validation, and reporting processes.
Develop enterprise vulnerability management procedures aligned with cybersecurity policies, risk frameworks, and compliance requirements.
Analyze vulnerability intelligence, exploitability data, threat intelligence, and business impact to prioritize remediation efforts.
Collaborate with Security, Infrastructure, Service Desk, and Operations teams to remediate critical vulnerabilities.
Establish remediation SLAs, metrics, and reporting.
Develop executive dashboards highlighting vulnerability trends, remediation progress, compliance posture, and organizational risk.
Lead mitigation efforts for high-risk vulnerabilities when patching is not immediately feasible.
Integrate vulnerability intelligence with Microsoft Defender, Intune, Azure, patching platforms, SIEM solutions, and security operations workflows.
Support audits, compliance assessments, penetration testing activities, and security reviews.
Develop automated remediation solutions utilizing PowerShell, Microsoft Graph, Azure Automation, APIs, and related technologies.
Monitor emerging threats, active exploit campaigns, and zero-day vulnerabilities.
Advance vulnerability management governance aligned to NIST, CIS Controls, Zero Trust principles, and industry best practices.
Endpoint Engineering & Microsoft Intune (Expert Level)
Serve as the technical authority for modern endpoint management, endpoint security, device lifecycle management, and Microsoft Intune administration.
Responsibilities
Design, implement, and support Microsoft Intune across Windows, macOS, iOS/iPadOS, Android, and hybrid-managed devices.
Architect and manage MDM, MAM, and modern endpoint management solutions.
Develop configuration profiles, compliance policies, security baselines, administrative templates, endpoint privilege management policies, and application protection policies.
Design and support Windows Autopilot deployment solutions.
Manage the complete device lifecycle, including enrollment, provisioning, configuration, software deployment, monitoring, retirement, and decommissioning.
Integrate Intune with Microsoft Entra ID, Microsoft Defender XDR, Conditional Access, and related Microsoft technologies.
Implement endpoint security controls aligned with Zero Trust principles and cybersecurity requirements.
Configure and manage Windows Update for Business, feature updates, quality updates, driver updates, and expedited security updates.
Develop proactive remediation solutions utilizing PowerShell, Microsoft Graph API, and Intune Remediations.
Support environments consisting of approximately 3,000 managed endpoints while maintaining high levels of security, availability, and operational efficiency.
Windows Autopilot (Expert Level)
Serve as the technical authority for Windows Autopilot, modern device provisioning, zero-touch deployment, endpoint onboarding, and lifecycle management.
Responsibilities
Design and maintain Windows Autopilot deployment strategies.
Support:
User-Driven Deployments
Pre-Provisioning
Self-Deploying Mode
Hybrid Entra Join
Microsoft Entra Join
Manage device registration, hardware hash imports, deployment profiles, dynamic group assignments, and enrollment status page configurations.
Develop zero-touch deployment strategies for remote and distributed workforces.
Automate:
Device Enrollment
Application Deployment
Security Baseline Enforcement
Compliance Policy Assignment
Certificate Deployment
Endpoint Security Configuration
Support large-scale device refreshes, deployment modernization efforts, and merger and acquisition integrations.
Establish KPIs around deployment success, onboarding efficiency, compliance attainment, and reduction of manual deployment activities.
Compliance, Security & Risk Management
Partner with Security, Risk, Audit, and Compliance teams.
Support compliance requirements aligned to:
NIST
CIS Controls
Zero Trust Framework
Internal Security Standards
Develop remediation plans for audit findings.
Maintain compliance reporting and evidence collection.
Support risk reduction initiatives and continuous security improvement programs.
Advanced Automation & Scripting (Expert Level)
Serve as the technical authority for enterprise automation, scripting, configuration management, and remediation engineering.
Technical Expertise
PowerShell
PowerShell Desired State Configuration (DSC)
Microsoft Graph API
Microsoft Graph PowerShell SDK
Azure Automation
Azure Logic Apps
Azure Functions
REST APIs
JSON Integrations
Microsoft Intune Remediations
Responsibilities
Automate patch deployment workflows across endpoints, servers, cloud workloads, and third-party applications.
Develop automated vulnerability remediation processes.
Automate device onboarding, provisioning, configuration, and lifecycle management.
Create compliance validation and remediation scripts.
Develop enterprise reporting for:
Patch Compliance
Vulnerability Exposure
Device Health
Security Posture
Certificate Status
Integrate Microsoft, security, ITSM, and monitoring platforms through APIs and automation.
Build reusable automation frameworks that improve operational efficiency and reduce manual intervention.
Maintain enterprise standards for secure scripting, source control, testing, documentation, and change management.
Advanced Analytics & KQL
Develop advanced analytics and reporting solutions using Kusto Query Language (KQL) supporting:
Microsoft Defender
Microsoft Sentinel
Microsoft Entra ID
Azure Log Analytics
Security Operations
Deliver:
Threat Analytics
Security Reporting
Compliance Reporting
Vulnerability Trending
Executive Dashboards
Required Qualifications
7+ years of experience in cybersecurity, infrastructure engineering, endpoint engineering, or systems engineering.
5+ years leading enterprise patch management and vulnerability remediation initiatives.
Experience supporting environments with 3,000+ managed endpoints.
Expert-level Microsoft Intune administration and engineering.
Expert-level Microsoft Entra ID administration and identity governance.
Expert-level Microsoft Defender XDR administration.
Advanced CrowdStrike Falcon administration experience.
Advanced PKI and certificate services administration.
Advanced PowerShell automation and scripting experience.
Experience supporting cloud, hybrid, and on-premises environments.
Strong understanding of cybersecurity frameworks and security controls.
Strong communication and executive presentation skills.
Preferred Certifications
Microsoft Certified Cybersecurity Architect Expert
Microsoft Certified Identity and Access Administrator Associate
Microsoft Certified Security Operations Analyst Associate
Microsoft Certified Endpoint Administrator Associate
Microsoft Certified Azure Administrator Associate
Microsoft Certified Azure Security Engineer Associate
CompTIA Security+
CrowdStrike Falcon Certification
ITIL Foundation
Success Measures
Success in this role will be measured by:
Maintaining 95%+ patch compliance across enterprise endpoints.
Reducing critical vulnerability remediation timelines.
Increasing automated remediation rates.
Improving Microsoft Secure Score and exposure metrics.
Reducing endpoint-related security incidents.
Maintaining audit and compliance readiness.
Strengthening overall endpoint security posture.
Improving deployment success rates for Microsoft and third-party updates.
Reducing operational effort through automation.
Lowering enterprise cyber risk through proactive remediation.
Ideal Candidate
The ideal candidate is a cybersecurity-focused engineering leader who combines deep expertise in enterprise patch management, vulnerability remediation, identity security, endpoint engineering, PKI, automation, compliance, and cloud technologies.
This individual is equally comfortable leading enterprise security initiatives, developing advanced PowerShell automation, building KQL-based analytics and reporting solutions, architecting secure identity frameworks, administering Microsoft and CrowdStrike security platforms, and driving risk-focused remediation programs across a large-scale enterprise environment.
Most importantly, this person consistently looks for opportunities to reduce risk, automate operations, improve compliance, strengthen security posture, and simplify enterprise technology management.

