Windows Client Engineer - Hybrid

Genesis10•Pittsburgh, PA
•Hybrid

About The Position

Genesis10 is seeking a Windows Client Engineer for a contract position with a Global Manufacturing Company in Pittsburgh, PA. This is a 12+ month contract opportunity. The role focuses on managing and modernizing the Windows endpoint estate using Microsoft Intune and SCCM (Configuration Manager), with a primary goal of reducing vulnerability risk. The engineer will collaborate with the security team to address findings, develop deployable fixes, and create packages and scripts for large-scale remediation.

Requirements

  • Bachelor's degree or higher.
  • 3-5+ years of experience engineering and administering Windows endpoints in an enterprise environment.
  • Hands-on experience with both Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment.
  • Strong PowerShell scripting skills for automation, detection, and remediation.
  • Experience with Windows patch management (Windows Update for Business, WSUS, or SCCM software updates).
  • Familiarity with vulnerability management concepts and tooling (Tenable experience strongly preferred).
  • Understanding of CVEs, CVSS scoring, and how vulnerability findings map to real remediation actions.
  • Solid grasp of Windows OS internals, Active Directory, Group Policy, and Entra ID (Azure AD).
  • Ability to test changes carefully and roll out fixes without disrupting end users.

Nice To Haves

  • Experience with application packaging tools (PSADT, PatchMyPC) and MSI/MSIX.
  • Exposure to Microsoft Defender for Endpoint and its vulnerability management (TVM) integration.
  • Knowledge of security hardening frameworks (CIS Benchmarks, DISA STIGs).
  • Relevant certifications (Microsoft MD-102, SC-200, or CompTIA Security+).

Responsibilities

  • Review outstanding vulnerabilities identified by Tenable and manage the endpoint-side remediation workflow.
  • Build, test, and deploy remediation packages and solutions using Intune and SCCM.
  • Author and maintain remediation scripts (PowerShell), including detection and remediation logic.
  • Package and deploy third-party application updates outside of standard Microsoft patching.
  • Manage Windows Update policy through Windows Update for Business / WSUS / SCCM software update groups.
  • Partner with the security/vulnerability management team to triage findings and validate fixes.
  • Track remediation progress and report on compliance, patch coverage, and outstanding risk against SLAs.
  • Maintain configuration baselines and security hardening across the Windows client fleet.
  • Support co-management, device onboarding, compliance policies, and conditional access.
  • Document remediation procedures and contribute to a repeatable, well-tested deployment process.

Benefits

  • Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years
  • The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years
  • Access to an experienced, caring recruiting team (more than 7 years of experience, on average)
  • Behavioral Health Platform
  • Medical, Dental, Vision
  • Health Savings Account
  • Voluntary Hospital Indemnity (Critical Illness & Accident)
  • Voluntary Term Life Insurance
  • 401K
  • Sick Pay (for applicable states/municipalities)
  • Commuter Benefits (Dallas, NYC, SF, and Illinois)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service