Senior Administrator, Systems Management

Cencora•Conshohocken, PA

About The Position

Senior Administrator (Level 3) responsible for the design, deployment, and advanced support of endpoint management solutions across a large, distributed physical and virtual device estate using Microsoft Endpoint Configuration Manager (MECM) and Microsoft Intune in a co-managed environment. Owns application packaging, third-party patch management, security vulnerability remediation, advanced PowerShell automation, and at-scale incident troubleshooting, partnering closely with Information Security, Networking, and Support teams to keep the endpoint fleet secure, compliant, and reliable.

Requirements

  • Bachelor's degree, preferably in Computer Science, Management Information Systems, or a related technology field (equivalent experience considered).
  • At least 8 years of IT experience, including 5+ years in infrastructure/endpoint engineering.
  • Advanced, hands-on expertise with Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune, including co-management, Autopilot, compliance policies, and Win32 application deployment.
  • Demonstrated experience remediating security vulnerabilities – identifying, prioritizing, and patching OS and third-party application vulnerabilities, including CVE triage and patch-compliance reporting (Microsoft Defender/vulnerability management tooling).
  • Advanced PowerShell scripting ability (functions, modules, error handling, remoting, Graph API/Intune scripting), plus familiarity with VBScript for legacy support.
  • Proven ability to troubleshoot complex incidents at scale across large, distributed endpoint environments, with strong root-cause analysis skills.
  • Strong application packaging experience (.MSI/.MST, Win32; App-V/MSIX familiarity a plus) using, PSAppDeployToolkit, Advanced Installer, and Orca.
  • Experience managing third-party application patching programs (e.g., Patch My PC, Ivanti, or similar).
  • Solid understanding of Active Directory and Group Policy for managing user/computer objects, including GPO troubleshooting (gpresult, RSoP).
  • Working knowledge of wired/wireless networking fundamentals: DHCP, DNS, IP addressing, subnetting, and VLANs, and how they affect client-server communication and content distribution.
  • Familiarity with Windows 11 Enterprise features, settings, and deployment; BIOS/UEFI configuration; Bitlocker and Microsoft Defender.
  • Experience with virtualization technologies (Citrix, VMware) and thin/zero-client delivery is a plus.
  • Solid track record of delivering thoughtful, effective, and timely solutions to complex business problems that enhance the end-user experience.

Nice To Haves

  • AI-assisted automation and Copilot-style tools (Microsoft Copilot, GitHub Copilot, Claude) to speed up scripting, triage, and remediation.
  • Service-Now for Incident, request logging.
  • GitHub (or Azure DevOps) for version-controlled scripts and Intune/MECM configuration-as-code, including basic CI/CD pipelines.
  • JIRA (or similar) for ticketing, sprint/backlog tracking, and change management.
  • Working familiarity with Azure AD/Microsoft Entra ID, conditional access, and Windows Autopatch.
  • Experience mentoring Level 1/2 engineers and producing clear runbooks/knowledge-base documentation.
  • ITIL foundations or equivalent incident/problem/change management experience.

Responsibilities

  • Package, test, and deploy Windows and third-party applications through MECM and Intune (Win32 apps), using PSADT and other silent-install packages with reliable detection logic and dependency handling.
  • MECM/Intune co-management experience: client settings, boundaries and boundary groups, deployment collections, Autopilot profiles, compliance policies, and configuration baselines across the enterprise endpoint estate.
  • Design, write, and maintain advanced PowerShell scripts for automation, remediation, and reporting, including Intune and MECM.
  • Identify, prioritize, and remediate security vulnerabilities across the endpoint fleet in partnership with Information Security – driving CVE/patch-compliance reporting and mitigation timelines for OS and third-party applications.
  • Third-party application patching lifecycle – identifying, packaging, testing, and deploying updates (e.g., via Patch My PC, MECM, application/patch deployment) to minimize vulnerability exposure windows.
  • Networking knowledge (DNS, DHCP, IP addressing/subnetting, VLANs, boundary/content distribution) to resolve connectivity issues affecting client communication, application delivery, and patch distribution.
  • Leverage AI-assisted tools (Claude, Copilot and other scripting assistants) and automation/orchestration to streamline packaging, remediation, and reporting – tracking work in JIRA and version-controlling scripts/configs in GitHub.
  • Partner and collaborate with multiple technical teams (Architecture, Networking, Information Security, Support, etc.) to develop and support endpoint solutions.
  • Triage and resolve escalations from Endpoint Support and Security, acting as a technical escalation point for Level 1/2 teams.

Benefits

  • medical
  • dental
  • vision care
  • backup dependent care
  • adoption assistance
  • infertility coverage
  • family building support
  • behavioral health solutions
  • paid parental leave
  • paid caregiver leave
  • training programs
  • professional development resources
  • mentorship programs
  • employee resource groups
  • volunteer activities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service