About this role
Key Responsibilities
Endpoint Management & Administration
• Administer endpoint management platforms including Microsoft Intune, Windows Update for Business, RMM tools, and endpoint security solutions.
• Manage device enrollment, compliance policies, software deployment, and endpoint standards.
• Maintain workstation lifecycle processes including provisioning, deployment, refresh, and retirement.
• Support endpoint configuration baselines, security policies, and hardening initiatives.
Patch Management
• Own patch management processes for Windows servers and workstations.
• Coordinate testing, deployment, validation, and reporting of operating system and application updates.
• Monitor patch compliance against defined SLAs.
• Schedule and execute maintenance windows with minimal business disruption.
• Support emergency and out-of-band patching for critical vulnerabilities.
Vulnerability Management
• Monitor vulnerability scanning platforms and remediation dashboards.
• Triage vulnerabilities based on severity, exploitability, and business risk.
• Coordinate remediation activities with infrastructure, networking, application owners, and vendors.
• Track remediation progress and maintain exception documentation.
• Produce vulnerability and remediation metrics for leadership and compliance reporting.
RMM & Monitoring
• Administer Remote Monitoring and Management (RMM) platforms.
• Develop monitoring standards and alerting thresholds.
• Investigate recurring alerts and eliminate noise through automation and process improvements.
• Create automated remediation workflows where appropriate.
• Monitor endpoint health, software inventory, disk utilization, service status, and system performance.
Security Operations Support
• Assist with endpoint security tools including Microsoft Defender, SentinelOne, FortiClient, and related technologies.
• Investigate endpoint security alerts and coordinate escalation when required.
• Support audits, compliance initiatives, and security assessments.
• Maintain endpoint security baselines and enforce remediation activities.
Asset & CMDB Management
• Maintain accurate endpoint inventory and asset records.
• Reconcile data across Intune, Active Directory, Entra ID, RMM, vulnerability scanners, and CMDB platforms.
• Ensure endpoint ownership, lifecycle status, and configuration data remain current.
• Identify and resolve discrepancies in asset records.
Documentation & Process Improvement
• Develop and maintain operational runbooks and support documentation.
• Identify opportunities for automation using PowerShell and other scripting tools.
• Create dashboards and reporting to improve visibility into endpoint health and compliance.
• Continuously improve endpoint management processes and operational efficiency.
Required Qualifications
• 5+ years of experience in systems administration, endpoint administration, or infrastructure operations within a Windows-based enterprise environment.
• Experience managing Windows desktop environments.
• Experience with Microsoft Intune and Entra ID.
• Experience with patch management platforms and methodologies.
• Experience administering or supporting vulnerability management programs.
• Familiarity with endpoint security platforms.
• Strong troubleshooting and root-cause analysis skills.
• Experience with PowerShell scripting and automation.
• Strong documentation and organizational skills.
Preferred Qualifications
• Experience with endpoint management, RMM, and vulnerability management platforms such as Microsoft Intune, NinjaOne, ConnectWise RMM, Tenable, Rapid7, Microsoft Defender Vulnerability Management, or similar solutions.
• Experience with Microsoft Defender for Endpoint, SentinelOne, FortiClient EMS, Windows Autopilot, and Freshservice CMDB.
• Experience working in manufacturing or multi-site enterprise environments.
• Experience supporting cybersecurity initiatives aligned with CMMC, NIST, CIS Controls, or similar frameworks.