Consultant Systems Engineer-SCCM Intune
Role / Job Summary -
Key Responsibilities:
Design and maintain enterprise GPO architecture (OU design, WMI filters, ADMX/ADML, version control) to enforce consistent security and configuration baselines.
Own the SCCM/MECM architecture (Site, DPs, MPs, SUP/WSUS, CMG) for high availability and performance at scale.
Define and maintain Windows workstation standards (builds, baselines, posture, CIS/NIST-aligned hardening, BitLocker, Defender).
Lead the transition/maturity towards co-management and modern management (Intune/Entra ID) where applicable.
Manage gold images, deployment, and automation.
Create and maintain GPOs for performance and security.
Troubleshoot complex endpoint issues.
Develop automation using PowerShell.
Maintain documentation and audit readiness.
Required Skills & Experience:
Advanced expertise in GPO and Windows policy governance.
Strong experience with SCCM/MECM site administration.
Deep hands-on Windows 10/11 workstation engineering knowledge.
Strong PowerShell scripting capabilities.
Understanding of DNS, HTTP/S, PKI, and Windows networking.
Knowledge of CIS/NIST security baselines.
Years of Experience -
8 years of relevant experience in Project handling and DWS services.
10 or more years of overall IT experience.
Qualification / Certification -
Diploma / Degree (mandatory)
ITIL Foundation (optional)
Windows workstation certification (optional)
Windows server certification (optional)
Mandatory Skills / Experience -
GPO: Advanced design, inheritance modeling, loopback, WMI filtering, ADMX central store, troubleshooting (Resultant Set of Policy, gpresult, event tracing).
SCCM/MECM: Site administration, boundaries, content distribution, SUP/WSUS, task sequences (OSD/WinRE), ADRs , Collections strategy.
Windows Workstation (10/11): Imaging, feature update management, driver/firmware lifecycle, Defender/BitLocker/Firewall configuration, performance tuning.
Automation: Strong PowerShell (PSADT, WMI/CIM, CM cmdlets), Git, desired state & remediation scripts.
Networking & Infra Basics: DNS, HTTP/S, proxies, PKI/Certs, WinRM, content delivery (DP/Peer Cache/Delivery Optimization).
Security & Compliance: CIS/NIST benchmarks, vulnerability remediation orchestration, ASR/Defender policies, device control.
Good to have skills / Experience -
Experience with co-management and Autopilot
Experience with Configuration Baselines, Proactive Remediations, KQL (Defender/Log Analytics)
Agile methodologies