Endpoint Management & Vulnerability Remediation Engineer

Lumen Solutions Group IncWashington, DC
Remote

About The Position

Position Summary We are seeking an experienced Endpoint Management & Vulnerability Remediation Engineer to support enterprise endpoint management, Windows patching, application deployment, vulnerability remediation, and security compliance activities. The ideal candidate will have strong hands-on experience with Microsoft Intune, MECM/SCCM, PowerShell, Windows patch management, application packaging, vulnerability remediation, Active Directory/Entra ID, and ServiceNow. This role will work closely with infrastructure, cybersecurity, application, audit, and compliance teams to maintain a secure and compliant enterprise endpoint environment.

Requirements

  • Strong hands-on experience with Microsoft Intune endpoint and mobile-device management.
  • Experience creating and managing Intune configuration profiles, compliance policies, security policies, and application deployments.
  • Hands-on experience packaging and deploying applications through Microsoft Intune.
  • Advanced administration experience with MECM/SCCM.
  • Experience creating, testing, deploying, and troubleshooting MECM/SCCM application packages.
  • Strong experience managing enterprise monthly Windows patching cycles through MECM/SCCM.
  • Ability to investigate and resolve patch failures, unhealthy clients, deployment errors, and endpoint compliance issues.
  • Experience producing MECM/SCCM operational and compliance reports.
  • Strong Windows PowerShell scripting and automation capabilities.
  • Experience administering Microsoft Entra ID/Azure AD and traditional Active Directory.
  • Hands-on vulnerability analysis and remediation experience in a large enterprise environment.
  • Experience creating dashboards, reports, or remediation records within ServiceNow.
  • Understanding of endpoint security controls, security baselines, change management, and audit-evidence requirements.
  • Ability to work independently while coordinating with infrastructure, cybersecurity, application, and compliance teams.

Nice To Haves

  • Experience supporting PCI-regulated or similarly controlled enterprise environments.
  • Familiarity with PCI DSS requirements related to patching, vulnerability management, access control, system hardening, and compliance evidence.
  • Experience working within a formal Infrastructure Risk Remediation or Vulnerability Management program.
  • Experience integrating or co-managing endpoints across Intune and MECM/SCCM.
  • Familiarity with Microsoft Defender for Endpoint, Windows Autopilot, Microsoft Entra ID, or related Microsoft security technologies.
  • Experience supporting migration or transition from MECM/SCCM to Microsoft Intune.
  • Experience working in a large, complex, highly regulated organization.
  • Relevant Microsoft, security, ITIL, or endpoint-management certifications are beneficial but not mandatory.

Responsibilities

  • Administer and support Microsoft Intune for enterprise endpoint and mobile-device management.
  • Configure and maintain Intune device enrollment, configuration profiles, compliance policies, security baselines, and application deployment policies.
  • Package, test, deploy, troubleshoot, and maintain enterprise applications through Microsoft Intune.
  • Administer Microsoft Endpoint Configuration Manager (MECM/SCCM), including collections, deployments, client health, software distribution, and reporting.
  • Package, test, deploy, and troubleshoot enterprise applications through MECM/SCCM.
  • Plan, coordinate, execute, and validate monthly Windows security patching activities.
  • Monitor patch deployment status, investigate failed installations, and remediate noncompliant or unreachable endpoints.
  • Analyze vulnerability findings and coordinate remediation activities across Windows endpoints and supporting infrastructure.
  • Prioritize vulnerabilities based on severity, business risk, asset criticality, exploitability, and compliance requirements.
  • Develop remediation plans and track vulnerabilities through validation and closure.
  • Use PowerShell to automate endpoint management, application deployment, reporting, patching, and remediation activities.
  • Support Microsoft Entra ID (Azure AD) and on-premises Active Directory administration.
  • Produce operational, patch-compliance, vulnerability, and risk-remediation reports using MECM/SCCM and ServiceNow.
  • Maintain accurate remediation records, technical documentation, operating procedures, and audit evidence.
  • Assist the Infrastructure Risk Remediation Team in maintaining a PCI-compliant environment.
  • Collaborate with cybersecurity, infrastructure, application, audit, and business teams to resolve endpoint risks and compliance gaps.
  • Recommend improvements to endpoint management, patching, application packaging, reporting, and remediation processes.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service