Patch/Deployment Management

NTT DATA, Inc.

Dadri

On-site

INR 1,200,000 - 1,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NTT DATA, Inc. in Noida, Uttar Pradesh is seeking a Senior Specialist in Patch Management & Software Deployment. This role focuses on executing and improving enterprise patch management operations using SCCM and Microsoft Intune.

The ideal candidate will have extensive experience overseeing patch lifecycles, ensuring compliance across 5,000+ endpoints, and mentoring junior engineers. Strong knowledge of automation via PowerShell scripting is essential.

Qualifications

  • 9-12 years of experience in enterprise endpoint management.
  • Minimum 5 years of hands-on SCCM/MECM experience.
  • Familiarity with compliance frameworks such as ISO 27001.

Responsibilities

  • Own the design, execution, and improvement of patch management operations.
  • Manage SCCM application deployment and monitor compliance.
  • Lead post-patch validation activities and report compliance.

Skills

SCCM Current Branch - Software Update Management
PowerShell scripting
Microsoft Intune
Compliance reporting
Patch lifecycle management

Education

B.E. / B.Tech in Computer Science or related field
MCA or equivalent postgraduate qualification

Tools

SCCM/MECM
Microsoft Graph API
Power BI

Job description

We are currently seeking a Patch/Deployment Management to join our team in Noida, Uttar Pradesh (IN-UP), India (IN).

Role Overview

The Grade 9 Senior Specialist – Patch Management & Software Deployment is a senior hands‑on technical role within NTT DATA’s Enterprise Endpoint Management (EPM) practice. This individual owns the design, execution, and continuous improvement of enterprise patch management and software deployment operations across Microsoft Endpoint Configuration Manager (SCCM/MECM) and Microsoft Intune for one or more enterprise client accounts.

At Grade 9, the engineer operates with a high degree of independence on complex patching and deployment challenges, serves as the L3 escalation point for patch and software deployment issues within the team, and actively contributes to process governance, automation, and junior team development. The role is critical to client patch compliance posture, vulnerability remediation SLA adherence, and software lifecycle discipline across large, diverse endpoint estates.

Key Responsibilities
Patch Management – SCCM / MECM
  • Design and govern the end-to-end software update management lifecycle in SCCM — from SUP synchronisation through ADR execution, deployment targeting, and compliance reporting.
  • Architect and maintain WSUS topology — upstream/downstream server configuration, product and classification scoping, synchronisation schedules, and cleanup routines.
  • Build and manage Automatic Deployment Rules (ADRs) for Patch Tuesday, out-of-band, and zero‑day update scenarios across tiered deployment ring strategies.
  • Define and enforce maintenance window frameworks across server, workstation, and critical asset device collections aligned to client change management policies.
  • Manage phased patch deployment pipelines — Pilot, UAT, and Production ring progressions with dwell periods and compliance gates.
  • Monitor patch compliance dashboards and produce client‑facing SLA compliance reports; drive remediation for non‑compliant devices.
  • Govern Software Update Point (SUP) health — synchronisation failures, WSUS certificate management, expired update cleanup, and IIS health monitoring.
  • Manage third‑party patch management integration within SCCM where applicable — SCUP, or third‑party update catalogue publishing.
  • Lead post‑patch validation activities — confirming deployment success, identifying failed devices, and driving re‑deployment or manual remediation workflows.
Patch Management – Microsoft Intune / Windows Update for Business
  • Design and manage Windows Update for Business (WUfB) update ring policies in Intune for Quality Updates, Feature Updates, and driver update management.
  • Configure and maintain Feature Update policies and Windows 11 readiness targeting for Intune‑managed device populations.
  • Govern Intune update compliance reporting — identify deferred, failed, and non‑compliant devices and drive resolution within SLA.
  • Manage Expedite Update workflows in Intune for emergency/zero‑day patch scenarios requiring accelerated deployment.
  • Align Intune update ring configurations with SCCM co‑management patch workload authority assignments to prevent policy conflicts.
  • Support Windows Autopatch readiness assessment and onboarding activities for eligible client environments.
Software Deployment – SCCM / MECM
  • Lead application and software deployment design in SCCM — MSI, MSIX, EXE, and script‑based deployments with accurate detection rules, supersedence chains, and dependency modelling.
  • Build and manage SCCM deployment types, requirement rules, and global conditions for complex multi‑platform application targeting.
  • Design and govern phased deployment pipelines for critical software rollouts — piloting, staged production expansion, and rollback capability.
  • Manage SCCM application catalogue health, deployment monitoring, and failed deployment investigation across client device estates.
  • Govern SCCM Distribution Point (DP) content management — content pre‑staging, validation, redistribution, and bandwidth throttling for remote site deployments.
  • Lead software lifecycle management within SCCM — application versioning, supersedence, retirement, and catalogue hygiene.
  • Support Software Metering configuration for licence compliance monitoring and usage reporting.
Software Deployment – Microsoft Intune
  • Build and manage Win32 application deployments in Intune — IntuneWinAppUtil packaging, detection rules, requirement rules, and dependency targeting.
  • Manage LOB app, Microsoft Store for Business, and MSIX package deployments in Intune with appropriate assignment targeting.
  • Govern app deployment monitoring and remediation — resolve installation failures, assignment conflicts, and detection rule mismatches.
  • Manage Intune app supersedence and update workflows for deployed Win32 and LOB applications.
  • Support PowerShell script and remediation deployment via Intune for configuration enforcement and break‑fix automation.
Compliance Reporting & Vulnerability Remediation
  • Produce and maintain patch compliance dashboards in SCCM SSRS, Power BI, or equivalent reporting tooling for client account review.
  • Integrate patch compliance data with vulnerability management outputs (Qualys, Tenable, Defender Vulnerability Management) to drive prioritised remediation workflows.
  • Maintain SLA compliance tracking for patch deployment targets — Critical, High, Medium, and Low severity update timelines.
  • Lead monthly patch reporting packs for client QSR (Quarterly Service Review) inputs and governance reporting.
  • Identify systemic compliance failures — analyse root causes (hardware, connectivity, agent health, exclusions) and drive permanent fixes.
Automation & Scripting
  • Develop and maintain PowerShell automation for SCCM patch operations — ADR management, collection membership, compliance queries, and remediation scripts.
  • Build Microsoft Graph API integrations for Intune patch compliance reporting, update ring management, and bulk device operations.
  • Automate WSUS maintenance routines — expired update decline, computer cleanup, and synchronisation health monitoring.
  • Create PowerShell‑based deployment health check scripts for post‑patch and post‑deployment validation.
Documentation, Governance & Mentoring
  • Author and maintain patch management SOPs, runbooks, deployment playbooks, and maintenance window calendars.
  • Represent patch and deployment changes in the client CAB (Change Advisory Board) process — RFC preparation and impact assessment.
  • Provide L3 technical guidance and mentoring to Grade 7 and Grade 8 engineers on patch and software deployment operations.
  • Conduct peer reviews of deployment configurations, ADR setups, and compliance reporting produced by junior team members.
  • Contribute to EPM practice knowledge base, lessons learned documentation, and internal technical communities.
Required Skills
SCCM / MECM – Patch & Deployment
  • SCCM Current Branch – Software Update Management: SUP, WSUS, ADR, Maintenance Windows, Phased Deployments (advanced level)
  • Distribution Point management – content prerestaging, bandwidth throttling, remote DP operations
  • Third‑party patch integration – SCUP or third‑party catalogue publishing experience (desirable)
  • Co‑management – patch workload authority, Intune/SCCM policy conflict avoidance
Microsoft Intune – Patch & Deployment
  • Windows Update for Business (WUfB) – update rings, Feature Update policies, driver management, expedite workflows
  • Win32 app packaging and deployment – IntuneWinAppUtil, detection rules, requirement rules, dependency
  • Intune compliance and update reporting – built‑in reports, Graph API‑based custom reporting
  • Remediation scripts and PowerShell deployment via Intune
  • Intune co‑management alignment – patch workload and policy authority coordination with SCCM
Vulnerability & Compliance Integration
  • Integration of patch compliance with vulnerability management tools – Qualys VMDR, Tenable, or Microsoft Defender Vulnerability Management
  • SLA‑based patch compliance tracking and executive reporting
  • Power BI or SSRS for patch compliance dashboard development
Scripting & Automation
  • PowerShell – advanced scripting for SCCM patch operations, WSUS maintenance, Intune automation
  • Microsoft Graph API – Intune patch compliance, update ring management, bulk device operations
Preferred Qualifications
  • Microsoft Certified: Endpoint Administrator Associate (MD‑102) – held or in progress
  • ITIL v4 Foundation
  • Experience with Windows Autopatch assessment and onboarding
  • Familiarity with SCCM CMG (Cloud Management Gateway) for internet‑based patch management
  • Exposure to Qualys VMDR, Tenable.io, or Microsoft Defender Vulnerability Management integration with SCCM/Intune
  • Prior experience delivering patch compliance in regulated environments — ISO 27001, HIPAA, SOX, or PCI‑DSS
Experience Profile
  • 9–12 years of progressive experience in enterprise endpoint management.
  • Minimum 5 years of hands‑on SCCM/MECM Software Update Management and application deployment experience.
  • Minimum 2 years of Microsoft Intune WUfB and Win32 application deployment experience.
  • Proven track record managing patch compliance across multi‑site enterprise estates of 5,000+ endpoints.
  • Experience working in managed services, IT outsourcing, or large enterprise IT delivery models preferred.
  • B.E. / B.Tech in Computer Science, Information Technology, or a related engineering discipline.
  • MCA or equivalent postgraduate qualification considered with commensurate experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SCCM Admin II
SCCM Admin II

Stefanini North America and APAC • Pune District

On-site
INR 900,000 - 1,300,000
SSCM Admin L3
SSCM Admin L3

Stefanini • Hyderabad, Pune District, Dadri

On-site
INR 1,200,000 - 1,800,000
SCCM Administrator
SCCM Administrator

Optum • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Endpoint & Patch Management Engineer
Endpoint & Patch Management Engineer

Forward Eye Technologies • Surat

On-site
INR 900,000 - 1,500,000
Endpoint & Patch Management Engineer
Endpoint & Patch Management Engineer

Forward Eye Technologies • Lucknow

On-site
INR 700,000 - 1,100,000
Technical Support Specialist
Technical Support Specialist

Infinite Computer Solutions • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Systems Engineering Senior Specialist-SCCM/MECM
Systems Engineering Senior Specialist-SCCM/MECM

NTT DATA, Inc. • Hyderabad

On-site
INR 1,500,000 - 2,000,000
SCCM System Administrator
SCCM System Administrator

Tata Consultancy Services • Hyderabad

On-site
INR 1,400,000 - 2,200,000
SCCM Administrator L3
SCCM Administrator L3

Stefanini North America and APAC • Hyderabad

On-site
INR 600,000 - 1,200,000
SCCM Administrator
SCCM Administrator

Si2 Tech • Vadodara

On-site
INR 1,200,000 - 2,400,000