Experience
9 - 12 yrs
Job Location
Noida, India
Vacancy
1
Designation
Patch Management Engineer
Job Type
Not specified
Job Description
Location: Noida
Job Summary Role Overview Patch Management Software Deployment is a senior hands-on technical role within NTT DATA's Enterprise Endpoint Management (EPM) practice. This individual owns the design, execution, and continuous improvement of enterprise patch management and software deployment operations across Microsoft Endpoint Configuration Manager (SCCM/MECM) and Microsoft Intune for one or more enterprise client accounts.
At Grade 9, the engineer operates with a high degree of independence on complex patching and deployment challenges, serves as the L3 escalation point for patch and software deployment issues within the team, and actively contributes to process governance, automation, and junior team development. The role is critical to client patch compliance posture, vulnerability remediation SLA adherence, and software lifecycle discipline across large, diverse endpoint estates.
Key Responsibilities Patch Management SCCM / MECM - Design and govern the end-to-end software update management lifecycle in SCCM-from SUP synchronisation through ADR execution, deployment targeting, and compliance reporting.
- Architect and maintain WSUS topology - upstream/downstream server configuration, product and classification scoping, synchronisation schedules, and cleanup routines.
- Build and manage Automatic Deployment Rules (ADRs) for Patch Tuesday, out-of-band, and zero-day update scenarios across tiered deployment ring strategies.
- Define and enforce maintenance window frameworks across server, workstation, and critical asset device collections aligned to client change management policies.
- Manage phased patch deployment pipelines - Pilot, UAT, and Production ring progressions with dwell periods and compliance gates.
- Monitor patch compliance dashboards and produce client-facing SLA compliance reports; drive remediation for non-compliant devices.
- Govern Software Update Point (SUP) health - synchronisation failures, WSUS certificate management, expired update cleanup, and IIS health monitoring.
- Manage third-party patch management integration within SCCM where applicable - SCUP, or third-party update catalogue publishing.
- Lead post-patch validation activities - confirming deployment success, identifying failed devices, and driving re-deployment or manual remediation workflows.
- Design and manage Windows Update for Business (WUfB) update ring policies in Intune for Quality Updates, Feature Updates, and driver update management.
- Configure and maintain Feature Update policies and Windows 11 readiness targeting for Intune-managed device populations.
- Govern Intune update compliance reporting - identify deferred, failed, and non-compliant devices and drive resolution within SLA.
- Manage Expedite Update workflows in Intune for emergency/zero-day patch scenarios requiring accelerated deployment.
- Align Intune update ring configurations with SCCM co-management patch workload authority assignments to prevent policy conflicts.
- Support Windows Autopatch readiness assessment and onboarding activities for eligible client environments.
- Lead application and software deployment design in SCCM - MSI, MSIX, EXE, and script-based deployments with accurate detection rules, supersedence chains, and dependency modelling.
- Build and manage SCCM deployment types, requirement rules, and global conditions for complex multi-platform application targeting.
- Design and govern phased deployment pipelines for critical software rollouts - piloting, staged production expansion, and rollback capability.
- Manage SCCM application catalogue health, deployment monitoring, and failed deployment investigation across client device estates.
- Govern SCCM Distribution Point (DP) content management - content pre-staging, validation, redistribution, and bandwidth throttling for remote site deployments.
- Lead software lifecycle management within SCCM - application versioning, supersedence, retirement, and catalogue hygiene.
- Support Software Metering configuration for licence compliance monitoring and usage reporting.
- Build and manage Win32 application deployments in Intune - IntuneWinAppUtil packaging, detection rules, requirement rules, and dependency targeting.
- Manage LOB app, Microsoft Store for Business, and MSIX package deployments in Intune with appropriate assignment targeting.
- Govern app deployment monitoring and remediation - resolve installation failures, assignment conflicts, and detection rule mismatches.
- Manage Intune app supersedence and update workflows for deployed Win32 and LOB applications.
- Support PowerShell script and remediation deployment via Intune for configuration enforcement and break-fix automation.
- Produce and maintain patch compliance dashboards in SCCM SSRS, Power BI, or equivalent reporting tooling for client account review.
- Integrate patch compliance data with vulnerability management outputs (Qualys, Tenable, Defender Vulnerability Management) to drive prioritised remediation workflows.
- Maintain SLA compliance tracking for patch deployment targets - Critical, High, Medium, and Low severity update timelines.
- Lead monthly patch reporting packs for client QSR (Quarterly Service Review) inputs and governance reporting.
- Identify systemic compliance failures - analyse root causes (hardware, connectivity, agent health, exclusions) and drive permanent fixes.
- Develop and maintain PowerShell automation for SCCM patch operations - ADR management, collection membership, compliance queries, and remediation scripts.
- Build Microsoft Graph API integrations for Intune patch compliance reporting, update ring management, and bulk device operations.
- Automate WSUS maintenance routines - expired update decline, computer cleanup, and synchronisation health monitoring.
- Create PowerShell-based deployment health check scripts for post-patch and post-deployment validation.
- Author and maintain patch management SOPs, runbooks, deployment playbooks, and maintenance window calendars.
- Represent patch and deployment changes in the client CAB (Change Advisory Board) process - RFC preparation and impact assessment.
- Provide L3 technical guidance and mentoring to Grade 7 and Grade 8 engineers on patch and software deployment operations.
- Conduct peer reviews of deployment configurations, ADR setups, and compliance reporting produced by junior team members.
- Contribute to EPM practice knowledge base, lessons learned documentation, and internal technical communities.
- SCCM Current Branch Software Update Management: SUP, WSUS, ADR, Maintenance Windows, Phased Deployments (advanced level)
- Application deployment MSI/MSIX/EXE, detection rules, supersedence, dependency modelling, phased rollout
- Distribution Point management content prestaging, bandwidth throttling, remote DP operations
- SCCM reporting SSRS built-in reports, custom compliance queries, WQL collection queries
- Third-party patch integration SCUP or third-party catalogue publishing experience (desirable)
- Co-management patch workload authority, Intune/SCCM policy conflict avoidance
- Windows Update for Business (WUfB) update rings, Feature Update policies, driver management, expedite workflows
- Win32 app packaging and deployment IntuneWinAppUtil, detection rules, requirement rules, dependency
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
