System Configuration Engineer

Debevoise-&-Plimpton-LL

New York (NY)

On-site

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Debevoise & Plimpton LLP is seeking a System Configuration Engineer in New York to own enterprise patching and configuration management across Windows and Linux servers. You will lead SCCM and Azure Arc onboarding, develop PowerShell automation, and collaborate with Information Security to maintain security baselines.

The role reports to the Associate Director, Technology Engineering and requires strong ownership, troubleshooting, and 24x7 operational readiness in a fast-paced environment.

Qualifications

  • Minimum 7 years of experience in enterprise systems engineering, server administration, or infrastructure operations.
  • Minimum 5 years of hands‑on experience administering Microsoft Configuration Manager (SCCM) in a large enterprise environment.
  • Minimum 3 years of hands‑on experience with Azure Arc‑enabled servers and hybrid server management.
  • Minimum 5 years of advanced PowerShell scripting and workflow automation experience, including reusable modules, remoting, REST APIs, structured error handling, logging, testing, and secure credential handling.
  • Proven experience designing and operating enterprise patching programs across Windows environments.
  • Deep expertise with SCCM software update management, including WSUS, software update points, collections, automatic deployment rules, maintenance windows, distribution points, boundaries, and compliance reporting.

Responsibilities

  • Own and manage the enterprise patching program for all Windows and Linux servers, including inventory, risk prioritization, testing, scheduling, deployment, validation, remediation, and compliance reporting.
  • Administer and optimize Microsoft Configuration Manager (SCCM), including software update points, WSUS, collections, automatic deployment rules, maintenance windows, distribution, compliance baselines, and reporting.
  • Lead the onboarding and lifecycle management of on-premises Windows and Linux servers in Azure Arc, including agent deployment, identity, network and proxy requirements, extensions, policies, tags, RBAC, connectivity, and health monitoring.
  • Use Azure Update Manager and related Azure Arc services to assess, schedule, deploy, and report updates for hybrid Windows and Linux servers.
  • Develop and maintain PowerShell scripts, reusable modules, and workflow automation for onboarding, patching, configuration, compliance reporting, and automated remediation.
  • Partner with the Information Security team to create, test, implement, and maintain server security baselines based on current Microsoft and vendor guidance, industry benchmarks, and firm requirements.
  • Monitor patch, configuration, vulnerability, and baseline compliance; investigate failures and exceptions; coordinate remediation; and provide clear metrics to technical and business stakeholders.
  • Define and enforce patching and configuration standards, change management practices, maintenance schedules, pilot procedures, rollback plans, and operational runbooks.
  • Serve as the primary escalation point for complex SCCM, Azure Arc, Windows, and automation issues; maintain comprehensive documentation; and perform other duties as deemed appropriate by the Associate Director, Technology Engineering.

Skills

PowerShell scripting
Azure Arc
SCCM
Windows Server
Linux administration
Automation
Vulnerability management
Change management
Documentation
On-prem to Azure Arc

Tools

SCCM
Azure Arc
WSUS
Azure Update Manager
GitHub Actions

Job description

You are currently not authorized to access this section.
Please contact your Administrator to change your authorization settings.

System Configuration Engineer
Information Services Department
Debevoise & Plimpton LLP is a premier law firm with market-leading practices, a global perspective and strong New York roots. Our clients look to us to bring a distinctively high degree of quality, intensity and creativity to resolve legal challenges effectively and cost efficiently. We believe in hiring talented and dedicated individuals as members of our administrative community. We draw on the strength of our culture and structure to deliver the best of our firm to our lawyers and clients through true collaboration.
The firm is seeking a System Configuration Engineer in our New York office.
The System Configuration Engineer has overall responsibility for the firm's enterprise patching and configuration management program across all Windows and Linux servers. This role administers Microsoft Configuration Manager (SCCM), leads the onboarding and management of on-premises servers through Azure Arc, and develops PowerShell-based automation to improve security, reliability, and operational efficiency in a global 24x7 environment. The position partners closely with Information Security to establish and maintain server security baselines aligned with current recommendations and best practices. This position reports to the Associate Director, Technology Engineering.

RESPONSIBILITIES include but are not limited to:
  • Own and manage the enterprise patching program for all Windows and Linux servers, including inventory, risk prioritization, testing, scheduling, deployment, validation, remediation, and compliance reporting.
  • Administer and optimize Microsoft Configuration Manager (SCCM), including software update points, WSUS, collections, automatic deployment rules, maintenance windows, distribution, compliance baselines, and reporting.
  • Lead the onboarding and lifecycle management of on-premises Windows and Linux servers in Azure Arc, including agent deployment, identity, network and proxy requirements, extensions, policies, tags, RBAC, connectivity, and health monitoring.
  • Use Azure Update Manager and related Azure Arc services to assess, schedule, deploy, and report updates for hybrid Windows and Linux servers.
  • Develop and maintain PowerShell scripts, reusable modules, and workflow automation for onboarding, patching, configuration, compliance reporting, and automated remediation.
  • Partner with the Information Security team to create, test, implement, and maintain server security baselines based on current Microsoft and vendor guidance, industry benchmarks, and firm requirements.
  • Monitor patch, configuration, vulnerability, and baseline compliance; investigate failures and exceptions; coordinate remediation; and provide clear metrics to technical and business stakeholders.
  • Define and enforce patching and configuration standards, change management practices, maintenance schedules, pilot procedures, rollback plans, and operational runbooks.
  • Serve as the primary escalation point for complex SCCM, Azure Arc, Windows, and automation issues; maintain comprehensive documentation; and perform other duties as deemed appropriate by the Associate Director, Technology Engineering.
REQUIREMENTS:

The ideal candidate possesses strong communication, organizational, and technical skills, with the ability to take ownership of enterprise-wide patching and configuration programs and collaborate effectively across teams. Must demonstrate a proven ability to automate complex processes, troubleshoot critical issues, and operate in a fast-paced, high-availability environment. Must be available to work outside of normal business hours as needed.

  • Minimum 7 years of experience in enterprise systems engineering, server administration, or infrastructure operations.
  • Minimum 5 years of hands‑on experience administering Microsoft Configuration Manager (SCCM) in a large enterprise environment.
  • Minimum 3 years of hands‑on experience with Azure Arc‑enabled servers and hybrid server management.
  • Minimum 5 years of advanced PowerShell scripting and workflow automation experience, including reusable modules, remoting, REST APIs, structured error handling, logging, testing, and secure credential handling.
  • Proven experience designing and operating enterprise patching programs across Windows environments.
  • Deep expertise with SCCM software update management, including WSUS, software update points, collections, automatic deployment rules, maintenance windows, distribution points, boundaries, and compliance reporting.
  • Proven experience onboarding on‑premises Windows servers to Azure Arc at scale using scripts, service principals, Configuration Manager, or other automated deployment methods.
  • Strong working knowledge of Azure Arc agents, extensions, resource organization, identity, RBAC, policy, network connectivity, proxy configuration, monitoring, and troubleshooting.
  • Experience using Azure Update Manager or comparable tools to assess, schedule, deploy, and report server updates.
  • Strong Windows Server administration experience, including Active Directory, Group Policy, Windows Update, certificates, services, and enterprise troubleshooting.
  • Strong Linux administration experience, including package managers, repositories, services, permissions, shell scripting, and troubleshooting across common enterprise distributions.
  • Experience developing and enforcing server configuration and security baselines in partnership with Information Security.
  • Strong understanding of vulnerability management, security hardening, least privilege, change management, exception management, and audit requirements.
  • Proven ability to plan pilot groups, phased deployments, maintenance windows, reboot coordination, and rollback strategies that minimize business impact.
  • Experience producing patch compliance dashboards, operational metrics, executive reporting, and audit evidence.
  • Demonstrated expertise in analyzing and resolving complex server, agent, identity, network, patching, and automation issues.
  • A strong sense of ownership and excellent attention to detail while working in a very fast‑paced and energetic environment.
PREFERRED QUALIFICATIONS:
  • Microsoft certifications in Azure administration, Windows Server hybrid administration, endpoint management, or security strongly preferred.
  • Experience with Desired State Configuration, configuration‑as‑code, or infrastructure‑as‑code tools such as Ansible, Terraform, or Bicep.
  • Experience with Azure Automation, GitHub Actions, enterprise job scheduling, or other orchestration platforms.
  • Experience implementing CIS Benchmarks, Microsoft security baselines, or comparable hardening standards for Windows servers.
  • Experience managing enterprise VMware ESXi and vCenter environents, including workload deployments, HA/DRS, vMotion, Lifecycle Manager, templates, resource allocation, snapshots, migrations, capacity management, and troubleshooting.
  • Experience provisioning SAN storage for VMware and server workloads, including zoning, LUN creation and presentation, masking, multipathing, VMFS datastores, capacity planning, and performance management.
  • Experience integrating vulnerability management findings with patching, remediation, and exception workflows.
  • Experience using SQL, SSRS, Power BI, or similar tools for SCCM and compliance reporting.
  • Experience with structured project management or serving as technical lead on infrastructure, security remediation, or hybrid cloud initiatives.
  • Excellent documentation skills, including architecture diagrams, implementation plans, standards, and runbooks using tools such as Visio and Word.

Debevoise & Plimpton LLP is an equal opportunity employer. All qualified applicants will receive equal consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other legally protected category in accordance with U.S. law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Configuration Engineer
System Configuration Engineer

Debevoise & Plimpton LLP • New York (NY)

On-site
USD 140,000 - 180,000
Azure Arc SCCM Patch Engineer
Azure Arc SCCM Patch Engineer

Debevoise & Plimpton LLP • New York (NY)

On-site
USD 140,000 - 180,000
Senior Patch & Configuration Engineer — SCCM & Azure Arc
Senior Patch & Configuration Engineer — SCCM & Azure Arc

Debevoise-&-Plimpton-LL • New York (NY)

On-site
USD 120,000 - 180,000
Systems Engineer - Azure Arc| SCCM
Systems Engineer - Azure Arc| SCCM

Virtual Tech Gurus • New York (NY)

On-site
USD 100,000 - 150,000
Windows Server & Endpoint Patch Management Engineer
Windows Server & Endpoint Patch Management Engineer

Ampcus, Inc • Jersey City (NJ)

On-site
USD 120,000 - 150,000
SCCM Engineer
SCCM Engineer

Value2Biz de Mexico SC • Arkansas

On-site
USD 54,000 - 73,000
Patch Management Administrator
Patch Management Administrator

SMS Data Products Group, Inc. • Sumter (SC)

On-site
USD 85,000 - 120,000
SCCM Engineer (Patch management)
SCCM Engineer (Patch management)

New Millenium Consulting • New York (NY)

Hybrid
USD 75,000 - 95,000
Patch & Compliance Systems Engineer (Windows/Linux, SCCM)
Patch & Compliance Systems Engineer (Windows/Linux, SCCM)

Virtual Tech Gurus • New York (NY)

On-site
USD 100,000 - 150,000
Network & Computer Systems Administrator – SME
Network & Computer Systems Administrator – SME

Jobtailor • Jacksonville (FL)

On-site
USD 120,000 - 150,000