Newmark is seeking an MECM Support Engineer to support and maintain the firm's Microsoft Configuration Manager (MECM/SCCM) platform, with a primary focus on the server estate. This role is centred on day-to-day MECM support for Windows servers patch deployment, compliance reporting, and client health troubleshooting — helping keep the firm's server infrastructure secure, compliant, and up to date. The successful candidate will work closely with Infrastructure and Security teams, providing reliable operational support and clear, actionable compliance reporting for stakeholders.
This is a hands-on support role for someone who is comfortable working within established MECM processes — deploying, patching, monitoring, and reporting across the server environment — and who takes pride in keeping the platform running smoothly day to day in a fast-paced financial services environment.
Key Responsibilities
- Provide day-to-day support for the MECM (Configuration Manager) environment — monitoring site systems, distribution points, and client health across the Windows server estate — and apply platform updates and hotfixes in line with change control, under guidance from senior engineers.
- Package, test, and deploy software updates via MECM as part of the monthly server patch management cycle: software update groups, deployment rings, maintenance windows, and post-patch validation.
- Maintain and update compliance and patch-status reporting (e.g. dashboards, scheduled reports) to give Infrastructure, Security, and management visibility into server compliance, scan errors, and outstanding remediation.
- Investigate and resolve MECM client health issues, scan errors, non-compliant servers, and clients missing from the console, escalating where required.
- Assist Security teams in prioritising and remediating server vulnerabilities identified through vulnerability management and compliance dashboards.
- Support automation of routine MECM administration and reporting tasks using PowerShell and maintain documentation of support processes and troubleshooting runbooks for the wider Infrastructure team.
Qualifications
Essential
- Hands-on 8+ Years experience supporting Microsoft Endpoint Configuration Manager (MECM/SCCM) for a Windows Server estate in a production enterprise environment.
- Strong understanding of software update/patch management within MECM, specifically for Windows Server operating systems.
- Working knowledge of Windows Server administration, Active Directory, and Group Policy.
- Experience producing or maintaining compliance/status reporting (e.g. via SQL queries, Power BI, or MECM's native reporting) for server patch and device compliance.
- Solid understanding of vulnerability and patch management concepts, including prioritisation of critical and high‑severity patches on servers.
- Strong troubleshooting skills and comfort working directly against MECM's Log files to diagnose server client issues.
- Clear written and verbal communication skills, with the ability to translate technical detail into reporting that non-technical stakeholders can act on.
Highly Desirable
- Proficiency with PowerShell (or Python) for scripting, automation, and reporting against MECM, including lightweight internal tools.
- Exposure to Power BI or SQL Server Reporting Services (SSRS) for building or maintaining compliance, vulnerability, or patch reporting dashboards.
- Familiarity with vulnerability management platforms (e.g. Rapid7) or Microsoft Defender for Endpoint, and correlating findings with MECM remediation.
- Experience with server virtualisation platforms (e.g. VMware, Hyper‑V) and general server hardware/lifecycle awareness.
- Experience in a financial services or other regulated environment, with an appreciation for change control and audit requirements.
- Relevant certifications (e.g. Microsoft Certified: Windows Server Hybrid Administrator, or equivalent).
Personal Attributes
- Self-directed and comfortable managing a queue of BAU support requests alongside project work.
- Strong stakeholder management: able to ask the right questions and communicate clearly across technical and non-technical audiences.
- Collaborative team member within a wider Infrastructure and Security function.
- Pragmatic and security-conscious: able to balance operational urgency with appropriate governance and risk controls.