IT Platform Engineer
Our client, a large enterprise organization, is looking for an Endpoint Engineer to lead a focused initiative around patch compliance remediation. This role is dedicated to clearing an overdue backlog of medium-severity vulnerabilities on non-Java, Windows-based devices — patches dated 2025 and earlier that have gone unaddressed. You'll work primarily in Microsoft Intune, troubleshooting failed deployments, diagnosing root causes, and driving devices back into compliance at scale.This is a hands-on, execution-focused role. Success looks like measurable, week-over-week progress against the backlog and a clear, documented understanding of why patches fail and how they get fixed.What You'll DoOwn remediation of medium-severity, non-Java patch vulnerabilities across the device fleet, prioritizing the 2025-and-older backlog Diagnose and troubleshoot failed or stalled patch deployments in Intune — sync issues, policy conflicts, pending reboots, disk space, error codes, and other common failure points Manage and monitor update rings and compliance policies to ensure patches are reaching and applying to target devices Communicate regularly with device owners, IT stakeholders, and leadership on remediation progress, blockers, and timelines Document root causes and resolutions to build a repeatable troubleshooting process for the team Track progress against compliance/backlog metrics and report status consistently What You BringHands-on experience administering Microsoft Intune, including update rings, compliance policies, and app/patch deployment Strong troubleshooting skills — comfortable diagnosing why a specific device or group failed to patch, not just re-pushing a policy Experience working through a patch or vulnerability backlog in an enterprise environment Clear, professional communication skills; comfortable working directly with device owners and stakeholders across teams Familiarity with Windows Update for Business (WUfB), Windows Autopatch, or WSUS a plus Experience with PatchMyPC and/or Jamf a plus, but not required Nice to HaveExperience with macOS patching/Jamf if the environment is mixed-OS Prior experience specifically clearing an aged/overdue vulnerability backlog