EndPoint Infrastructure Patching & Vulnerability Management Administrator
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
JOB DESCRIPTION
EndPoint Infrastructure Patching & Vulnerability Management Administrator
Role Title EndPoint Infrastructure Patching & Vulnerability Management Administrator
Location Kochi, India and Manila, Philippines (War Room)
Function / Portfolio Digital Workplace Enablement Services (DWES) – EndPoint Management
Scope Patching & vulnerability remediation of the ~450 on-prem SCCM/APPPROXY infrastructure servers (CAS, Primary Sites, SQL site databases and supporting server roles)
Shift Model War Room / on-call coverage aligned to accelerated patch cycles (Patch Tuesday) and emergency/zero-day events
Job Description Summary
Maintain and secure the Endpoint Management infrastructure (approximately 450 SCCM and AppProxy servers) by ensuring systems remain patched, hardened, and free of known vulnerabilities. Own the end-to-end server patching and remediation lifecycle, including monitoring, validation, deployment coordination, post-patch verification, and driving vulnerability findings to closure.
The successful candidate will operate the patching lifecycle end to end: monitoring for released fixes, validating them, sequencing and executing patching in coordination with the SCCM and Approxy engineering team, restarting/validating servers, and driving vulnerability findings to closure.
The estate is split across non-production and production environments and includes the Central Administration Site (CAS), Primary Sites and their SQL site databases, which are the true single point of failure for a site. Work is executed against an accelerated cadence and, when required, under an Emergency/Zero-Day change model. The role is hands-on, evidence-driven and governed by EY change management (RFC / eCAB).
Key Responsibilities
Server Patching & Maintenance
• Execute monthly, accelerated and emergency patching across the ~450 SCCM/AppProxy servers (non-production first, then production), following the confirmed environment sequence.
• Sequence patching correctly so Windows/SQL work completes before SCCM/APPPROXY patching in each environment; perform and validate server restarts within the agreed windows.
• Apply Microsoft SCCM/APPPROXY hotfixes and SQL Server cumulative updates (CU/GDR) as prerequisites for a healthy SCCM/APPPROXY platform, coordinating carefully around SQL site databases to avoid taking a whole site down.
• Support High-Availability failover patching (patch passive node/SQL replica, switch active/passive, patch former active) to minimize outage windows.
Vulnerability Management & Remediation
• Own the remediation of vulnerabilities flagged against the SCCM/APPPROXY server estate (e.g. GVM / scanner findings from tools such as Qualys / Tenable), tracking each item to closure within SLA.
• Triage and prioritize findings by criticality (CVSS), separating in-scope SCCM/APPPROXY/SQL items from those owned by other teams and re-assigning out-of-scope items correctly (accurate CMDB ownership).
• Validate that deployed fixes actually mitigate the reported vulnerability, remove flagged/unnecessary software, and capture evidence for audit and closure.
• Maintain and report remediation status, backlog reduction and platform health metrics to the SCCM/APPPROXY lead and stakeholders.
Coordination, Change & War Room Operations
• Liaise daily with the core SCCM/APPPROXY engineering team, SQL/DBA, platform, and service management to plan and execute patch windows.
• Raise and manage changes through EY change management (RFC / eCAB), including emergency/zero-day changes, respecting change freezes and approvals.
• Provide War Room coverage during patch surges and zero-day events: readiness checks, live execution, validation, rollback if thresholds are exceeded, and clear stakeholder communication.
• Produce concise, evidence-based status updates and closure reports for leadership.
Required Skills & Experience
• Hands-on experience administering and patching SCCM/APPPROXY server infrastructure (CAS, Primary Sites, site system roles) in a large enterprise estate.
• Strong Windows Server administration skills (multi-domain Active Directory) including patching, restart sequencing and post-patch validation.
• Working knowledge of SQL Server as an SCCM/APPPROXY prerequisite — applying CU/GDR updates and understanding site-database criticality and Always On / HA concepts.
• Solid understanding of enterprise change management (RFC / CAB / eCAB) and evidence/audit discipline.
• Ability to work under pressure in a War Room / on-call model across accelerated and emergency patch cycles.
Out of Scope
To keep the role focused, the following are explicitly not the primary responsibility of this position:
• Day-to-day administration of the SCCM/APPPROXY application layer — application packaging/deployment, collections/targeting, task sequences, client health and end-user device compliance.
• Operating-system patching governance owned by other platform teams (the role executes/sequences server patching but does not own OS patch policy).
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.