EndPoint Infrastructure Patching
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
EndPoint Infrastructure Patching & Vulnerability Management Administrator
Location: Taguig
Other locations: Primary Location Only
Date: 15 Sept 2026
Requisition ID: 1744233
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
JOB DESCRIPTION
EndPoint Infrastructure Patching & Vulnerability Management Administrator
Role Title EndPoint Infrastructure Patching & Vulnerability Management Administrator
Location Kochi, India and Manila, Philippines (War Room)
Function / Portfolio Digital Workplace Enablement Services (DWES) – EndPoint Management
Scope Patching & vulnerability remediation of the ~450 on-prem SCCM/APPPROXY infrastructure servers (CAS, Primary Sites, SQL site databases and supporting server roles)
Shift Model War Room / on-call coverage aligned to accelerated patch cycles (Patch Tuesday) and emergency/zero-day events
Job Description Summary
Maintain and secure the Endpoint Management infrastructure (approximately 450 SCCM and AppProxy servers) by ensuring systems remain patched, hardened, and free of known vulnerabilities. Own the end-to-end server patching and remediation lifecycle, including monitoring, validation, deployment coordination, post-patch verification, and driving vulnerability findings to closure.
The successful candidate will operate the patching lifecycle end to end: monitoring for released fixes, validating them, sequencing and executing patching in coordination with the SCCM and Approxy engineering team, restarting/validating servers, and driving vulnerability findings to closure.
The estate is split across non-production and production environments and includes the Central Administration Site (CAS), Primary Sites and their SQL site databases, which are the true single point of failure for a site. Work is executed against an accelerated cadence and, when required, under an Emergency/Zero-Day change model. The role is hands-on, evidence-driven and governed by EY change management (RFC / eCAB).
Key Responsibilities
Server Patching & Maintenance
- Execute monthly, accelerated and emergency patching across the ~450 SCCM/AppProxy servers (non-production first, then production), following the confirmed environment sequence.
- Sequence patching correctly so Windows/SQL work completes before SCCM/APPPROXY patching in each environment; perform and validate server restarts within the agreed windows.
- Apply Microsoft SCCM/APPPROXY hotfixes and SQL Server cumulative updates (CU/GDR) as prerequisites for a healthy SCCM/APPPROXY platform, coordinating carefully around SQL site databases to avoid taking a whole site down.
- Support High-Availability failover patching (patch passive node/SQL replica, switch active/passive, patch former active) to minimize outage windows.
Vulnerability Management & Remediation
- Own the remediation of vulnerabilities flagged against the SCCM/APPPROXY server estate (e.g. GVM / scanner findings from tools such as Qualys / Tenable), tracking each item to closure within SLA.
- Triage and prioritize findings by criticality (CVSS), separating in-scope SCCM/APPPROXY/SQL items from those owned by other teams and re-assigning out-of-scope items correctly (accurate CMDB ownership).
- Validate that deployed fixes actually mitigate the reported vulnerability, remove flagged/unnecessary software, and capture evidence for audit and closure.
- Maintain and report remediation status, backlog reduction and platform health metrics to the SCCM/APPPROXY lead and stakeholders.
Coordination, Change & War Room Operations
- Liaise daily with the core SCCM/APPPROXY engineering team, SQL/DBA, platform, and service management to plan and execute patch windows.
- Raise and manage changes through EY change management (RFC / eCAB), including emergency/zero-day changes, respecting change freezes and approvals.
- Provide War Room coverage during patch surges and zero-day events: readiness checks, live execution, validation, rollback if thresholds are exceeded, and clear stakeholder communication.
- Produce concise, evidence-based status updates and closure reports for leadership.
Required Skills & Experience
- Hands-on experience administering and patching SCCM/APPPROXY server infrastructure (CAS, Primary Sites, site system roles) in a large enterprise estate.
- Strong Windows Server administration skills (multi-domain Active Directory) including patching, restart sequencing a