EndPoint Infrastructure Patching And Vulnerability Management Administrator

Ernst & Young Advisory Services Sdn Bhd

Ernakulam

On-site

INR 1,500,000 - 2,300,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ernst & Young Advisory Services Sdn Bhd seeks an EndPoint Infrastructure Patching & Vulnerability Management Administrator to own the end-to-end patching lifecycle for ~450 SCCM/AppProxy servers, across production and non-production environments.

The role requires hands-on patching, vulnerability remediation, change management, and war-room coordination to keep systems secured and compliant, with rigorous validation and reporting to leadership.

Qualifications

  • Hands-on SCCM/APPPROXY server administration across a large enterprise estate.
  • Strong Windows Server administration including patching, restart sequencing and validation.
  • Knowledge of SQL Server CU/GDR updates and HA concepts.
  • Experience with enterprise change management (RFC/CAB/eCAB) and audit discipline.

Responsibilities

  • Patch and remediation of ~450 SCCM/APPPROXY servers across non-production and production environments.
  • Coordinate patch windows with SCCM/APPPROXY and SQL teams; validate restarts and sequencing.
  • Manage vulnerability remediation and SLA tracking; evidence for audit and closure.
  • Provide War Room coverage during patch surges and zero-day events; communicate status.

Skills

SCCM/APPPROXY admin
Windows Server admin
SQL Server knowledge
Change management
On-call/War Room

Job description

EndPoint Infrastructure Patching And Vulnerability Management Administrator

Other locations: Primary Location Only

Date: 17 Sept 2026

Requisition ID: 1744229

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

EndPoint Infrastructure Patching & Vulnerability Management Administrator

EndPoint Infrastructure Patching & Vulnerability Management Administrator

Digital Workplace Enablement Services (DWES) – EndPoint Management


Scope

Patching & vulnerability remediation of the ~450 on-prem SCCM/APPPROXY infrastructure servers (CAS, Primary Sites, SQL site databases and supporting server roles)

Job Description Summary

Maintain and secure the Endpoint Management infrastructure (approximately 450 SCCM and AppProxy servers) by ensuring systems remain patched, hardened, and free of known vulnerabilities. Own the end-to-end server patching and remediation lifecycle, including monitoring, validation, deployment coordination, post-patch verification, and driving vulnerability findings to closure.

The successful candidate will operate the patching lifecycle end to end: monitoring for released fixes, validating them, sequencing and executing patching in coordination with the SCCM and Approxy engineering team, restarting/validating servers, and driving vulnerability findings to closure.

The estate is split across non-production and production environments and includes the Central Administration Site (CAS), Primary Sites and their SQL site databases, which are the true single point of failure for a site. Work is executed against an accelerated cadence and, when required, under an Emergency/Zero-Day change model. The role is hands-on, evidence-driven and governed by EY change management (RFC / eCAB).

Key Responsibilities

Server Patching & Maintenance

  • Execute monthly, accelerated and emergency patching across the ~450 SCCM/AppProxy servers (non-production first, then production), following the confirmed environment sequence.
  • Sequence patching correctly so Windows/SQL work completes before SCCM/APPPROXY patching in each environment; perform and validate server restarts within the agreed windows.
  • Apply Microsoft SCCM/APPPROXY hotfixes and SQL Server cumulative updates (CU/GDR) as prerequisites for a healthy SCCM/APPPROXY platform, coordinating carefully around SQL site databases to avoid taking a whole site down.
  • Support High-Availability failover patching (patch passive node/SQL replica, switch active/passive, patch former active) to minimize outage windows.

Vulnerability Management & Remediation

  • Own the remediation of vulnerabilities flagged against the SCCM/APPPROXY server estate (e.g. GVM / scanner findings from tools such as Qualys / Tenable), tracking each item to closure within SLA.
  • Triage and prioritize findings by criticality (CVSS), separating in-scope SCCM/APPPROXY/SQL items from those owned by other teams and re-assigning out-of-scope items correctly (accurate CMDB ownership).
  • Validate that deployed fixes actually mitigate the reported vulnerability, remove flagged/unnecessary software, and capture evidence for audit and closure.
  • Maintain and report remediation status, backlog reduction and platform health metrics to the SCCM/APPPROXY lead and stakeholders.

Coordination, Change & War Room Operations

  • Liaise daily with the core SCCM/APPPROXY engineering team, SQL/DBA, platform, and service management to plan and execute patch windows.
  • Raise and manage changes through EY change management (RFC / eCAB), including emergency/zero-day changes, respecting change freezes and approvals.
  • Provide War Room coverage during patch surges and zero-day events: readiness checks, live execution, validation, rollback if thresholds are exceeded, and clear stakeholder communication.
  • Produce concise, evidence-based status updates and closure reports for leadership.

Required Skills & Experience

  • Hands-on experience administering and patching SCCM/APPPROXY server infrastructure (CAS, Primary Sites, site system roles) in a large enterprise estate.
  • Strong Windows Server administration skills (multi-domain Active Directory) including patching, restart sequencing and post-patch validation.
  • Working knowledge of SQL Server as an SCCM/APPPROXY prerequisite — applying CU/GDR updates and understanding site-database criticality and Always On / HA concepts.
  • Solid understanding of enterprise change management (RFC / CAB / eCAB) and evidence/audit discipline.
  • Ability to work under pressure in a War Room / on-call model across accelerated and emergency patch cycles.

Out of Scope

To keep the role focused, the following are explicitly not the primary responsibility of this position:

  • Day-to-day administration of the SCCM/APPPROXY application layer — application packaging/deployment, collections/targeting, task sequences, client health and end-user device compliance.
  • Operating-system patching governance owned by other platform teams (the role executes/sequences server patching but does not own OS patch policy).

EY | Building a better working world

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

EndPoint Infrastructure Patching And Vulnerability Management Administrator
EndPoint Infrastructure Patching And Vulnerability Management Administrator

EY • Ernakulam

On-site
INR 1,000,000 - 1,800,000
Platform Infrastructure Patching and Vulnerability Compliance Lead
Platform Infrastructure Patching and Vulnerability Compliance Lead

Ernst & Young Advisory Services Sdn Bhd • Ernakulam

On-site
INR 4,000,000 - 7,000,000
Continuous learning
Career development
Total rewards
Platform Infrastructure Patching And Vulnerability Compliance Lead
Platform Infrastructure Patching And Vulnerability Compliance Lead

EY • Gurugram District

On-site
INR 3,000,000 - 5,400,000
Continuous learning
Flexible working
Total rewards package
+1
Platform Infrastructure Patching and Vulnerability Compliance Lead
Platform Infrastructure Patching and Vulnerability Compliance Lead

EY • Ernakulam

Hybrid
INR 3,500,000 - 6,000,000
Continuous learning
Flexible working
Career development
+1
Windows and Linux Compliance SME
Windows and Linux Compliance SME

Ernst & Young Advisory Services Sdn Bhd • Thrippunithura

Hybrid
INR 1,800,000 - 2,400,000
GMS-Senior-VM - Qualys
GMS-Senior-VM - Qualys

EY • Bengaluru

On-site
INR 2,400,000 - 3,200,000
ET Stay-In-Compliance Consultant
ET Stay-In-Compliance Consultant

EY • Ernakulam

On-site
INR 3,500,000 - 6,500,000
Endpoint Vulnerability Engineer
Endpoint Vulnerability Engineer

Foundever • Gurgaon

On-site
INR 900,000 - 1,400,000
Endpoint Vulnerability Engineer
Endpoint Vulnerability Engineer

Foundever • Gurugram District

On-site
INR 1,400,000 - 2,400,000
MS Exchange Administrator
MS Exchange Administrator

EY • Gurugram District

On-site
INR 1,800,000 - 2,400,000