Windows Patching Engineer Department Managed services Position Type Full Time
Remote Company
ALIANDO is an award-winning Azure Expert Managed Service solutions company focused on selling and deploying Microsoft technologies for U.S. and international companies. For over 20 years Microsoft and its partners have recommended ALIANDO for licensing consulting and managed services to corporations large and small. The company offers competitive pay and comprehensive employee benefits including health insurance fitness allowances work-from-home allowances paid maternity and parental leave and generous PTO. At ALIANDO we aim to unleash the potential of people and technology. Our company was built around the idea that there is no success without team success. We foster a culture of inclusion and fairness where diverse interests experiences and backgrounds are celebrated. We strive to empower and unleash the potential of everyone to ensure that every employee has a path to success. We're in it together to make life better for each other our customers our partners and our communities.
Patch Planning and Deployment Plan schedule and execute monthly and out-of-band patch cycles for Windows servers Windows endpoints and third-party applications across all managed client estates. Build ring-based deployment approaches that move updates from pilot groups to production in a controlled sequence with defined pause and rollback criteria. Coordinate maintenance windows with clients and application owners and confirm service health before and after each cycle. Respond to critical vulnerability advisories with emergency patch cycles working with the security team to prioritise by risk and exposure. Platform Administration Administer Azure Update Manager including maintenance configurations dynamic scopes assessment schedules and periodic assessment for Azure and Arc-enabled servers. Manage Microsoft Configuration Manager (SCCM) software update points automatic deployment rules update groups deployment packages maintenance windows and collection targeting. Administer WSUS including product and classification selection approvals synchronisation computer group structure declining superseded updates and routine database maintenance. Operate Patch My PC for third-party application patching and packaging keeping the application catalogue current and validating publishing into Configuration Manager or Intune. Maintain client-side update health including Windows Update client configuration Group Policy settings content distribution and agent remediation. Compliance Troubleshooting and Reporting Track patch compliance against agreed targets investigate failed and pending installations and remediate systematically rather than machine by machine. Troubleshoot update failures from Windows Update Configuration Manager and WSUS logs and resolve recurring causes at source. Produce monthly patch compliance reporting for service delivery managers and client stakeholders with clear commentary on exceptions and planned remediation. Conduct root cause analysis on recurring patch failures and drive permanent fixes through the problem management process. Service Delivery Automation and Documentation Raise own and close change records for every patch cycle with tested implementation and rollback plans. Handle incidents and service requests within agreed SLA targets keeping ticket records accurate and current. Automate reporting remediation and routine health checks using PowerShell and contribute reusable scripts to the team's automation library. Maintain runbooks and as-built documentation so that the service desk can act confidently on first contact and mentor junior engineers on patching practice. Participate in the on-call rotation and support out-of-hours maintenance windows which is where the majority of patching work is delivered.
Bachelor's degree in computer science information technology or engineering or equivalent practical experience. Four to seven years in Windows infrastructure support with at least three years focused on enterprise patch management. Hands-on administration experience with Azure Update Manager Microsoft Configuration Manager (SCCM) software updates and WSUS. Practical experience with third-party application patching ideally using Patch My PC. Strong Windows Server administration skills including Active Directory Group Policy and the Windows Update client with confident troubleshooting of update failures from logs. Working PowerShell scripting ability for reporting and bulk remediation. Experience working to formal ITIL processes for incident problem and change management within a ticketing platform such as Jira Service Management or ServiceNow. Willingness to work rotational shifts and scheduled maintenance windows including nights and weekends as part of a 24x7 support roster. Clear written and spoken English with confidence in client-facing communication.
Microsoft certification such as AZ-800 AZ-801 AZ-104 or MD-102. Experience with Microsoft Intune for update rings Windows Autopatch or co-managed workload configuration. Familiarity with vulnerability management tooling such as Microsoft Defender Vulnerability Management Qualys or Tenable and with mapping findings to patch cycles. Experience patching clustered and highly available workloads such as failover clusters SQL Server or Exchange. Experience supporting multiple customer environments for a managed services or outsourcing provider. ITIL 4 Foundation certification. ALIANDO is an equal-opportunity employer committed to Diversity Inclusion & Belonging. Individuals seeking employment at ALIANDO are considered without regard to any protected category including but not limited to race color religion national origin age sex marital status ancestry disability veteran status gender identity or sexual orientation.
Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.