System Configuration Engineer

Debevoise & Plimpton LLP

New York (NY)

On-site

USD 140,000 - 180,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Debevoise & Plimpton LLP in New York seeks a System Configuration Engineer to lead the firm's enterprise patching and configuration management for Windows and Linux servers. You will administer Microsoft Configuration Manager (SCCM), oversee on‑premises server onboarding via Azure Arc, and build PowerShell automation to improve security and reliability.

You will partner with Information Security to establish server baselines, monitor compliance, and provide metrics to stakeholders in a

Qualifications

  • Seven years of enterprise systems engineering or infrastructure operations experience.
  • Five+ years hands-on SCCM administration in a large enterprise environment.
  • Three+ years Azure Arc-enabled server experience.
  • Five+ years PowerShell scripting and automation experience with modules, remoting, REST APIs, logging and secure credentials.
  • Proven experience designing and operating enterprise patching programs across Windows environments.
  • Experience developing and enforcing server configuration and security baselines with Information Security.

Responsibilities

  • Own and manage the enterprise patching program for Windows and Linux servers including inventory, risk prioritization, testing, scheduling, deployment, validation, remediation and compliance reporting.
  • Administer and optimize Microsoft Configuration Manager (SCCM) including software update points, WSUS, collections, automatic deployment rules, maintenance windows, distribution, compliance baselines, and reporting.
  • Lead onboarding and lifecycle management of on-premises Windows and Linux servers in Azure Arc including agent deployment, identity, network, extensions, policies, RBAC and health monitoring.
  • Use Azure Update Manager and related Azure Arc services to assess, schedule, deploy, and report updates for hybrid Windows and Linux servers.
  • Develop and maintain PowerShell scripts, reusable modules, and workflow automation for onboarding, patching, configuration, compliance reporting, and automated remediation.
  • Partner with Information Security to create, test, implement, and maintain server security baselines based on Microsoft and vendor guidance and firm requirements.
  • Monitor patch, configuration, vulnerability and baseline compliance; investigate failures; coordinate remediation; and provide clear metrics to stakeholders.
  • Define and enforce patching and configuration standards, change management, maintenance schedules, pilot procedures, rollback plans and runbooks.
  • Serve as escalation point for complex SCCM, Azure Arc, Windows and automation issues; maintain documentation; and perform other duties as needed.

Skills

SCCM administration
Azure Arc
PowerShell scripting
Windows Server
Linux administration
Automation workflows
Security baselines
Patch management
RBAC & IAM
SCCM reporting

Tools

SCCM
WSUS
Azure Arc
PowerShell
SQL/SSRS
Power BI
GitHub Actions
VMware

Job description

System Configuration Engineer

Information Services Department

Debevoise & Plimpton LLP is a premier law firm with market-leading practices, a global perspective and strong New York roots. Our clients look to us to bring a distinctively high degree of quality, intensity and creativity to resolve legal challenges effectively and cost efficiently. We believe in hiring talented and dedicated individuals as members of our administrative community. We draw on the strength of our culture and structure to deliver the best of our firm to our lawyers and clients through true collaboration.

The firm is seeking a System Configuration Engineer in our New York office.

The System Configuration Engineer has overall responsibility for the firm's enterprise patching and configuration management program across all Windows and Linux servers. This role administers Microsoft Configuration Manager (SCCM), leads the onboarding and management of on-premises servers through Azure Arc, and develops PowerShell-based automation to improve security, reliability, and operational efficiency in a global 24x7 environment. The position partners closely with Information Security to establish and maintain server security baselines aligned with current recommendations and best practices. This position reports to the Associate Director, Technology Engineering.

RESPONSIBILITIES include but are not limited to:
  • Own and manage the enterprise patching program for all Windows and Linux servers, including inventory, risk prioritization, testing, scheduling, deployment, validation, remediation, and compliance reporting.
  • Administer and optimize Microsoft Configuration Manager (SCCM), including software update points, WSUS, collections, automatic deployment rules, maintenance windows, distribution, compliance baselines, and reporting.
  • Lead the onboarding and lifecycle management of on-premises Windows and Linux servers in Azure Arc, including agent deployment, identity, network and proxy requirements, extensions, policies, tags, RBAC, connectivity, and health monitoring.
  • Use Azure Update Manager and related Azure Arc services to assess, schedule, deploy, and report updates for hybrid Windows and Linux servers.
  • Develop and maintain PowerShell scripts, reusable modules, and workflow automation for onboarding, patching, configuration, compliance reporting, and automated remediation.
  • Partner with the Information Security team to create, test, implement, and maintain server security baselines based on current Microsoft and vendor guidance, industry benchmarks, and firm requirements.
  • Monitor patch, configuration, vulnerability, and baseline compliance; investigate failures and exceptions; coordinate remediation; and provide clear metrics to technical and business stakeholders.
  • Define and enforce patching and configuration standards, change management practices, maintenance schedules, pilot procedures, rollback plans, and operational runbooks.
  • Serve as the primary escalation point for complex SCCM, Azure Arc, Windows, and automation issues; maintain comprehensive documentation; and perform other duties as deemed appropriate by the Associate Director, Technology Engineering.
REQUIREMENTS:
  • Minimum 7 years of experience in enterprise systems engineering, server administration, or infrastructure operations.
  • Minimum 5 years of hands‑on experience administering Microsoft Configuration Manager (SCCM) in a large enterprise environment.
  • Minimum 3 years of hands‑on experience with Azure Arc-enabled servers and hybrid server management.
  • Minimum 5 years of advanced PowerShell scripting and workflow automation experience, including reusable modules, remoting, REST APIs, structured error handling, logging, testing, and secure credential handling.
  • Proven experience designing and operating enterprise patching programs across Windows environments.
  • Deep expertise with SCCM software update management, including WSUS, software update points, collections, automatic deployment rules, maintenance windows, distribution points, boundaries, and compliance reporting.
  • Proven experience onboarding on‑premises Windows servers to Azure Arc at scale using scripts, service principals, Configuration Manager, or other automated deployment methods.
  • Strong working knowledge of Azure Arc agents, extensions, resource organization, identity, RBAC, policy, network connectivity, proxy configuration, monitoring, and troubleshooting.
  • Experience using Azure Update Manager or comparable tools to assess, schedule, deploy, and report server updates.
  • Strong Windows Server administration experience, including Active Directory, Group Policy, Windows Update, certificates, services, and enterprise troubleshooting.
  • Strong Linux administration experience, including package managers, repositories, services, permissions, shell scripting, and troubleshooting across common enterprise distributions.
  • Experience developing and enforcing server configuration and security baselines in partnership with Information Security.
  • Strong understanding of vulnerability management, security hardening, least privilege, change management, exception management, and audit requirements.
  • Proven ability to plan pilot groups, phased deployments, maintenance windows, reboot coordination, and rollback strategies that minimize business impact.
  • Experience producing patch compliance dashboards, operational metrics, executive reporting, and audit evidence.
  • Demonstrated expertise in analyzing and resolving complex server, agent, identity, network, patching, and automation issues.
  • A strong sense of ownership and excellent attention to detail while working in a very fast‑paced and energetic environment.
PREFERRED QUALIFICATIONS:
  • Microsoft certifications in Azure administration, Windows Server hybrid administration, endpoint management, or security strongly preferred.
  • Experience with Desired State Configuration, configuration-as-code, or infrastructure-as-code tools such as Ansible, Terraform, or Bicep.
  • Experience with Azure Automation, GitHub Actions, enterprise job scheduling, or other orchestration platforms.
  • Experience implementing CIS Benchmarks, Microsoft security baselines, or comparable hardening standards for Windows servers.
  • Experience managing enterprise VMware ESXi and vCenter environents, including workload deployments, HA/DRS, vMotion, Lifecycle Manager, templates, resource allocation, snapshots, migrations, capacity management, and troubleshooting.
  • Experience provisioning SAN storage for VMware and server workloads, including zoning, LUN creation and presentation, masking, multipathing, VMFS datastores, capacity planning, and performance management.
  • Experience integrating vulnerability management findings with patching, remediation, and exception workflows.
  • Experience using SQL, SSRS, Power BI, or similar tools for SCCM and compliance reporting.
  • Experience with structured project management or serving as technical lead on infrastructure, security remediation, or hybrid cloud initiatives.
  • Excellent documentation skills, including architecture diagrams, implementation plans, standards, and runbooks using tools such as Visio and Word.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Configuration Engineer
System Configuration Engineer

Debevoise-&-Plimpton-LL • New York (NY)

On-site
USD 120,000 - 180,000
Senior Patch & Configuration Engineer — SCCM & Azure Arc
Senior Patch & Configuration Engineer — SCCM & Azure Arc

Debevoise-&-Plimpton-LL • New York (NY)

On-site
USD 120,000 - 180,000
Azure Arc SCCM Patch Engineer
Azure Arc SCCM Patch Engineer

Debevoise & Plimpton LLP • New York (NY)

On-site
USD 140,000 - 180,000
Systems Engineer - Azure Arc| SCCM
Systems Engineer - Azure Arc| SCCM

Virtual Tech Gurus • New York (NY)

On-site
USD 100,000 - 150,000
System Administrator
System Administrator

Dunhill Professional Search & Government Solutions • Washington

Hybrid
USD 110,000 - 140,000
Senior System Engineer
Senior System Engineer

Marcum Asia CPAs LLP • New York (NY)

Hybrid
USD 120,000 - 180,000
Systems Administrator
Systems Administrator

ECS Corporate Services • Quantico (VA)

On-site
USD 95,000 - 135,000
SCCM Engineer
SCCM Engineer

Value2Biz de Mexico SC • Arkansas

On-site
USD 54,000 - 73,000
Patch & Compliance Systems Engineer (Windows/Linux, SCCM)
Patch & Compliance Systems Engineer (Windows/Linux, SCCM)

Virtual Tech Gurus • New York (NY)

On-site
USD 100,000 - 150,000
System Admin / Onsite / Mesa
System Admin / Onsite / Mesa

Motion Recruitment Partners LLC • Mesa (AZ)

Hybrid
USD 120,000 - 160,000