Windows Client Engineer - Hybrid Pittsburgh

A.C. Coy•Pittsburgh, PA
•Hybrid

About The Position

The A.C.Coy company has an immediate opening for a Microsoft Windows Client Engineer. Ideal candidates must have 3- 5 years of experience engineering and administering Microsoft Windows endpoints in an enterprise environment. Hands-on experience with Microsoft Intune and SCCM/Configuration Manager including application packaging and deployment is also required.

Requirements

  • Experience engineering and administering Windows endpoints in an enterprise environment - 3-5 years
  • Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment
  • Strong PowerShell scripting skills for automation, detection, and remediation
  • Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates)
  • Familiarity with vulnerability management concepts and tooling — Tenable experience strongly preferred; comparable tools (Qualys, Rapid7) also relevant
  • Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions
  • Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD)
  • Ability to test changes carefully and roll out fixes without disrupting end users

Nice To Haves

  • Microsoft MD - 102, SC - 200, or CompTIA Security+ certifications
  • Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX
  • Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration
  • Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs)

Responsibilities

  • Manage and modernize the Windows endpoint estate through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on driving down vulnerability risk.
  • Partner closely with the security team to review findings from Tenable, translate them into deployable fixes, and build the packages, scripts, and configuration baselines that remediate them at scale.
  • Review outstanding vulnerabilities identified by Tenable Nessus / Tenable Security Center and own the endpoint-side remediation workflow from finding to closure.
  • Build, test, and deploy remediation packages and solutions using Intune and SCCM — application updates, patches, registry and configuration changes, and scripted fixes.
  • Author and maintain remediation scripts (PowerShell), including detection and remediation logic for Intune proactive remediations and SCCM configuration items.
  • Package and deploy third-party application updates that fall outside standard Microsoft patching (e.g., via Win32 apps in Intune, application deployments in SCCM, or a patching tool like PatchMyPC).
  • Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups, and ensure patch compliance reporting is accurate.
  • Partner with the security/vulnerability management team to triage findings, validate that deployed fixes actually clear the vulnerability, and provide feedback on false positives.
  • Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs.
  • Maintain configuration baselines and security hardening (e.g., CIS/DISA STIG alignment) across the Windows client fleet.
  • Support co-management, device onboarding, compliance policies, and conditional access as part of the broader Intune/SCCM environment.
  • Document remediation procedures and contribute to a repeatable, well-tested deployment process to avoid breaking production.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service