Windows Endpoint Engineer

Nesco Resource ·nescoresource.com

Location Pittsburgh, PA
Salary USD 45 - 48 / hour
Type Full time
Level Mid
Source Shazamme
Information Technology 26-26560
Apply direct
Overview
Client is seeking a Windows Client Engineer to manage and modernize its Windows endpoint environment through Microsoft Intune and SCCM (Configuration Manager), with a primary focus on reducing vulnerability risk. This hands-on role partners closely with security teams to analyze vulnerability findings, develop remediation solutions, and deploy fixes across the enterprise.
The ideal candidate will have strong experience with Windows endpoint administration, endpoint vulnerability remediation, PowerShell scripting, and enterprise device management technologies. Success in this role requires the ability to investigate vulnerabilities, implement scalable fixes, and ensure compliance without disrupting end users.

Core Responsibilities
• Review vulnerabilities identified through Tenable tools and manage the endpoint remediation process from investigation through closure.
• Build, test, package, and deploy remediation solutions using Microsoft Intune and SCCM, including patches, application updates, configuration changes, registry modifications, and scripted fixes.
• Author and maintain PowerShell scripts for automation, detection, and remediation, including Intune proactive remediations and SCCM configuration items.
• Package and deploy third-party application updates through Intune, SCCM, or patch management tools.
• Manage Windows Update policies and patching processes using Windows Update for Business, WSUS, or SCCM software updates.
• Partner with vulnerability management and security teams to triage findings, validate remediation effectiveness, and identify false positives.
• Track remediation progress and provide reporting on compliance, patch coverage, and outstanding risks against established service levels.
• Maintain Windows configuration baselines and security hardening standards across endpoint devices.
• Support co-management, device onboarding, compliance policies, and conditional access initiatives within the endpoint management environment.
• Document remediation procedures and contribute to standardized, well-tested deployment practices.

Essential Qualifications, Skills, and Technologies
• Bachelor's degree or higher.
• 3 to 5 years of experience engineering and administering Windows endpoints in an enterprise environment.
• Proficiency with Microsoft Windows Client and Server operating systems.
• Hands-on experience with Microsoft Intune and SCCM/Configuration Manager, including application packaging and deployment.
• Strong PowerShell scripting skills for automation, detection, and remediation.
• Experience with Windows patch management using Windows Update for Business, WSUS, or SCCM software updates.
• Experience performing endpoint and vulnerability remediation, including investigating findings and implementing corrective actions.
• Familiarity with vulnerability management concepts and tools, with Tenable experience strongly preferred and comparable platforms such as Qualys or Rapid7 considered relevant.
• Understanding of CVEs, CVSS scoring, and translating vulnerability findings into remediation activities.
• Knowledge of Windows operating systems, Active Directory, Group Policy, and Entra ID (Azure AD).
• Ability to carefully test, validate, and deploy changes while minimizing impact to end users.
• Demonstrated ability to work independently and proactively drive vulnerability investigation and remediation efforts.

Preferred Skills or Experience
• Experience with application packaging tools such as PSADT, PatchMyPC, MSI, or MSIX.
• Exposure to Microsoft Defender for Endpoint and Threat & Vulnerability Management integration.
• Knowledge of security hardening frameworks, including CIS Benchmarks and DISA STIGs.
• Relevant certifications such as Microsoft MD-102, SC-200, or CompTIA Security+.

Work Details
• Contract position.
• First shift schedule: Monday through Friday, 8:00 AM to 5:00 PM.
• Interview required; an onsite visit is preferred but flexible.

Nesco Resource offers a comprehensive benefits package for our associates, which includes a MEC (Minimum Essential Coverage) plan that encompasses Medical, Vision, Dental, 401K, and EAP (Employee Assistance Program) services.

Nesco Resource provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Frequently asked questions

Who is hiring for the Windows Endpoint Engineer role?
Nesco Resource is hiring for the Windows Endpoint Engineer position, a Shazamme client. Apply directly on the employer's career site.
Where is the Windows Endpoint Engineer job located?
The Windows Endpoint Engineer role with Nesco Resource is based in Pittsburgh, PA, US.
What does the Windows Endpoint Engineer role pay?
Nesco Resource lists the Windows Endpoint Engineer role at USD 45–48 per hour.
Is the Windows Endpoint Engineer role full-time or contract?
This is a full time position at Nesco Resource.
What experience level is the Windows Endpoint Engineer role?
The Windows Endpoint Engineer position is aimed at mid-level candidates.
How do I apply for the Windows Endpoint Engineer role at Nesco Resource?
Apply directly on Nesco Resource's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct