Patch/Deployment Management

NTT DATA

9–12 yrs Noida Full Time Hybrid (office + remote)
NTT DATA logo
Posted : 2 weeks ago Actively Hiring

Job description

Join NTT DATA, a leading global technology services provider, as a Patch/Deployment Management expert. This senior technical role is integral to our Enterprise Endpoint Management practice, focusing on the design, execution, and continuous enhancement of enterprise patch management and software deployment operations. You will leverage your expertise in Microsoft Endpoint Configuration Manager (SCCM/MECM) and Microsoft Intune to support major client accounts.

As a Grade 9 engineer, you will operate with significant autonomy, tackling complex patching and deployment challenges. You will serve as the L3 escalation point, contribute to process governance and automation, and mentor junior team members. This role is crucial for maintaining client patch compliance, adhering to vulnerability remediation SLAs, and managing software lifecycles across extensive and diverse endpoint environments.

NTT DATA is committed to fostering an inclusive, adaptable, and forward-thinking organization. We seek passionate individuals eager to grow with us and contribute to accelerating client success and making a positive societal impact through responsible innovation.

Responsibilities

Oversee the complete software update management lifecycle within SCCM, from SUP synchronization to ADR execution and compliance reporting. Architect and maintain WSUS topology, including server configurations and scoping. Build and manage Automatic Deployment Rules (ADRs) for various update scenarios, implementing tiered deployment ring strategies. Define and enforce maintenance window frameworks and manage phased patch deployment pipelines with compliance gates. Monitor patch compliance dashboards, generate client-facing SLA reports, and drive remediation for non-compliant devices.

Design and manage Windows Update for Business (WUfB) policies in Intune, including Quality Updates and Feature Updates. Configure Feature Update policies and assess Windows 11 readiness for Intune-managed devices. Govern Intune update compliance reporting and drive resolution for deferred or failed updates. Utilize Expedite Update workflows for emergency patching and align Intune configurations with SCCM co-management.

Lead application and software deployment design in SCCM, supporting various deployment types and complex targeting rules. Design and govern phased deployment pipelines for critical software rollouts, ensuring rollback capabilities. Manage SCCM application catalogue health and investigate deployment failures. Govern SCCM Distribution Point content management and lead software lifecycle management within SCCM.

Build and manage Win32 application deployments in Intune, including packaging and targeting. Manage LOB app, Microsoft Store for Business, and MSIX package deployments. Govern app deployment monitoring and remediation, resolving installation failures. Manage Intune app supersedence and update workflows, and support PowerShell script deployment via Intune for automation.

Produce and maintain patch compliance dashboards, integrating patch data with vulnerability management tools to prioritize remediation. Track SLA compliance for patch deployment targets and lead monthly patch reporting for client reviews. Identify systemic compliance failures and drive permanent fixes. Develop and maintain PowerShell automation for SCCM operations and Microsoft Graph API integrations for Intune. Automate WSUS maintenance routines and create deployment health check scripts.

Author and maintain patch management SOPs, runbooks, and deployment playbooks. Represent patch and deployment changes in the client Change Advisory Board (CAB) process. Provide L3 technical guidance and mentoring to junior engineers. Conduct peer reviews of deployment configurations and contribute to the EPM practice knowledge base.

Qualifications

A strong foundation in SCCM/MECM is essential, specifically in Software Update Management (SUP, WSUS, ADR, Maintenance Windows, Phased Deployments) and application deployment (MSI, MSIX, EXE, detection rules, supersedence, dependency modeling). Experience with Distribution Point management and SCCM reporting using SSRS is required. Familiarity with co-management, including patch workload authority and policy conflict avoidance, is also key.

Proficiency in Microsoft Intune is crucial, with expertise in Windows Update for Business (WUfB) update rings, Feature Update policies, and driver management. Experience with Win32 app packaging and deployment using IntuneWinAppUtil, along with Intune compliance and update reporting (including Graph API-based reporting), is necessary. The ability to manage remediation scripts and PowerShell deployment via Intune is also important.

Integration experience with vulnerability management tools such as Qualys VMDR, Tenable, or Microsoft Defender Vulnerability Management is required, alongside SLA-based patch compliance tracking and executive reporting. Development of patch compliance dashboards using Power BI or SSRS is a core requirement.

Advanced scripting skills in PowerShell for SCCM patch operations, WSUS maintenance, and Intune automation are mandatory. Experience with Microsoft Graph API for Intune management and bulk device operations is also required. Familiarity with WMI/CIM for SCCM device collection queries and patch state interrogation is beneficial.

Preferred qualifications include Microsoft Certified: Endpoint Administrator Associate (MD-102) or Azure Administrator Associate (AZ-104), and ITIL v4 Foundation certification. Experience with Windows Autopatch assessment and onboarding, SCCM CMG, and delivering patch compliance in regulated environments are advantageous.

This role demands 9–12 years of progressive experience in enterprise endpoint management, with a minimum of 5 years focused on SCCM/MECM Software Update Management and application deployment. A minimum of 2 years of experience with Microsoft Intune WUfB and Win32 application deployment is required. Proven success managing patch compliance across large enterprise estates (5,000+ endpoints) is essential. Experience in managed services or large enterprise IT delivery models is preferred.

Minimum education includes a B.E./B.Tech in Computer Science, Information Technology, or a related engineering discipline. An MCA or equivalent postgraduate qualification will be considered with commensurate experience.

Essential Skills

SCCMMECMSoftware Update ManagementWSUSADRMaintenance WindowsPhased DeploymentsApplication DeploymentMSIMSIXEXESupersedenceDependency ModelingDistribution Point ManagementSCCM ReportingSSRSWQLCo-managementMicrosoft IntuneWindows Update for BusinessUpdate RingsFeature Update PoliciesDriver ManagementExpedite WorkflowsWin32 App DeploymentIntuneWinAppUtilIntune Compliance ReportingMicrosoft Graph APIVulnerability ManagementQualys VMDRTenableMicrosoft Defender Vulnerability ManagementSLA TrackingPower BIPowerShellAutomationWMICIM

Good to Have

Third-party patch integrationSCUPAzure Administrator AssociateITIL v4 FoundationWindows AutopatchSCCM CMGISO 27001HIPAASOXPCI-DSS

More Details

RolePatch/Deployment Management
IndustryInformation Technology & Services, Telecommunications
DepartmentInformation Technology, Computer Systems Analyst
Employment TypeFull Time, Hybrid (office + remote)

About the Company

NTT DATA logo

NTT DATA

Information Technology & Services