Patch Compliance Engineer - Intune
Listed on 2026-07-01
-
IT/Tech
Cybersecurity, IT Support, Systems Administrator, Cloud Computing: Infrastructure & Operations
Security Compliance Engineer – Intune Workstation Patching
As a Security Compliance Engineer – Intune Workstation Patching, you will serve as the team's modern device management and Microsoft Intune expert. You will lead efforts to configure, deploy, and manage endpoint patches using Intune, ensuring alignment with Microsoft's cloud-first approach to device compliance.
You will play a key role in helping the organization transition from legacy SCCM-based deployments to Intune-centric patching workflows, including the use of Autopatch and mobile device management features. Your work will drive automation, improve compliance visibility, and reduce patching complexity across the enterprise.
Key Responsibilities
- Configure and manage patch deployment policies using Microsoft Intune
- Build and maintain compliance baselines, configuration profiles, and targeting groups
- Collaborate with Autopatch teams to support hybrid and cloud-native environments
Cross-Tool Integration
- Align Intune workflows with SCCM, Patch
MyPC, and Qualys-driven remediation priorities - Participate in patch calendar planning, scripting, and deployment lifecycle optimization
Proactive Remediation & Compliance
- Automate deployment of updates across diverse endpoint groups using Windows Update for Business and Autopatch
- Monitor compliance, remediate drift, and support modern provisioning strategies (e.g., Intune + Autopilot)
Reporting & Governance
- Support dashboards and reporting related to Intune compliance and deployment success
- Coordinate with vulnerability and operations teams to align patch data with Qualys and SLA metrics
Technology Stack & Tooling Focus
While Intune is your primary platform, collaboration across the ecosystem is required:
- Vulnerability Reporting:
Qualys, Qualys VMDR - Windows OS Patching:
Microsoft Intune, Windows Autopatch, SCCM - Microsoft Office Patching:
Cloud Update, SCCM - Third-Party Application Patching:
Patch
MyPC, SCCM, Qualys VMDR, Nexthink
Required Qualifications
- 5+ years of experience in endpoint security or IT operations, with deep focus on Microsoft Intune
- Demonstrated experience configuring Intune patch policies, compliance settings, and update rings
- Experience integrating Intune with SCCM, Patch
MyPC, or Autopatch in enterprise environments - Strong understanding of cloud-first device management, Windows Update for Business, and modern endpoint provisioning
- Scripting knowledge (e.g., Power Shell) to support automated remediation workflows
- Strong collaboration and communication skills
Preferred Qualifications
- Experience in large enterprise environments with 100,000+ endpoints
- Familiarity with Microsoft Autopilot and modern provisioning pipelines
- Knowledge of compliance standards (e.g., CIS Benchmarks, NIST)
- Experience with vulnerability management and risk orchestration tools, such as Brinqa and Vulcan
- Prior involvement in SCCM-to-Intune transformation initiatives
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).