End User Computing Engineer

Cynet SystemsJacksonville, FL

About The Position

This role focuses on managing the patch management lifecycle for End User Computing (EUC) endpoints. The engineer will be responsible for assessment, testing, approval, deployment, validation, and reporting of patches. This includes designing and maintaining update groups, developing automation scripts, and acting as a technical escalation point for patch-related issues. The position requires strong analytical and troubleshooting skills, excellent documentation abilities, and a proactive approach to process improvement. Collaboration with security operations and mentoring junior analysts are also key aspects of the role.

Requirements

  • Deep expertise in SCCM/MECM – software update point, ADRs, deployment rings, client health.
  • Hands-on experience with Microsoft Intune / Autopilot / Windows Update for Business.
  • Advanced PowerShell scripting for automation (compliance remediation, report extraction, deployment triggers).
  • Experience with vulnerability management tools: Qualys, Tenable Nessus, or Rapid7 InsightVM.
  • Knowledge of Windows OS lifecycle, patch Tuesday cycle, CBS, WUA, and WinSxS.
  • Understanding of BitLocker, Windows Defender, and endpoint security baselines (CIS / STIG).
  • Experience integrating patch workflows with ServiceNow ITSM and CMDB.
  • Working knowledge of Azure AD, Entra ID, and Conditional Access policies.
  • Strong analytical and troubleshooting skills for complex patch failures.
  • Excellent documentation skills – able to produce clear SOPs, RCAs, and change records.
  • Strong verbal and written communication skills.
  • Proactive mindset – identifies process gaps and proposes improvements.
  • Ability to manage concurrent workstreams under deadline pressure.

Nice To Haves

  • Familiarity with macOS patch management (Jamf Pro / Munki) is an advantage.
  • Microsoft 365 Certified: Endpoint Administrator Associate (MD-102).
  • Microsoft Certified: Azure Administrator Associate (AZ-104).
  • CompTIA Security+ or CySA+.
  • ITIL 4 Managing Professional (or Foundation).
  • Qualys Certified Specialist – Vulnerability Management.

Responsibilities

  • Own the patch management lifecycle: assessment, testing, approval, deployment, validation, and reporting for all EUC endpoints.
  • Design and maintain software update groups, collections, and deployment rules in SCCM/MECM and Microsoft Intune.
  • Develop and maintain PowerShell / WMI scripts to automate patch compliance checks, remediation, and reporting.
  • Act as L2 escalation for patch deployment failures, application compatibility issues, and non-compliant device investigations.
  • Conduct patch testing in pilot/UAT rings before production rollout; document test results and obtain change approval.
  • Integrate Qualys / Tenable vulnerability scan data to drive patch prioritization based on CVSS scores.
  • Define and enforce patching SLAs for Critical, High, Medium, and Low severity patches per security policy.
  • Maintain and improve the patch management runbook, SOPs, and exception handling process.
  • Collaborate with security operations (SOC) to address zero-day threats and emergency patch deployments.
  • Produce monthly patch compliance reports and trend analysis for management review.
  • Mentor and guide L1 analysts; review their tickets and provide technical feedback.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service