跳到主要內容

Windows Patching Lead

00070233571

About the group:

Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about accepting digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the constantly evolving needs of the digital era. Our broad approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to own the business in a secure environment.

*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*

Role: Windows Patching Lead

Location: Toronto, ON

ROLE SUMMARY

10+ years in Windows Server/desktop administration and patching; 4+ years as tower/pod lead

The Windows Patching Tower Lead (Onshore) is the subject matter expert and client-facing lead for all Windows patching across a 190,000+ endpoint estate. This individual owns the full Windows patch lifecycle — SCCM/MECM/WSUS/Intune/Tanium-driven wave execution, GPO management, reboot orchestration, and compliance reporting — while acting as the primary Wintel interface to client L2/L3 teams and application owners during Canada business hours and weekend change windows.

ROLE IN THE OPERATING MODEL

▸ Tower/pod lead and subject-matter expert for Windows patching — owns execution, quality, and compliance for the Windows tower

▸ Primary Wintel interface to client L2/L3 engineers and application owners during Canada hours and weekend windows

▸ Coordinates app-owner sign-off post-patching and owns Windows tower compliance reporting to the Patch Service Lead

▸ Operates as the Windows execution layer under client direction; gold image/packaging engineering remains client L2/L3 owned

▸ Directs and reviews the work of Windows-assigned offshore SMEs during onshore hours

KEY RESPONSIBILITIES

▸ Plan and execute monthly Patch-Tuesday cumulative/quality updates, hotfixes, and out-of-band/zero-day patches via SCCM/MECM, WSUS, Intune, and Tanium

▸ Manage SCCM/MECM deployment rings, collections, maintenance windows, WSUS approvals, and GPO-driven patch policies across servers and end-user devices

▸ Run pre-flight checks — disk space, connectivity, pending reboots, backup confirmation — and reboot orchestration with post-patch smoke tests

▸ Coordinate application-owner sign-off and change-window adherence; track compliance via Tenable/Qualys and remediate non-compliant assets

▸ Update CMDB patch levels, close vulnerability tickets, and maintain KEDB; perform RCA and rollback (KB uninstall) for failed patches

▸ Manage EOL/EOS tracking for Windows versions; flag end-of-support risks to the Patch Service Lead

▸ Own Windows tower compliance reporting; present KPIs and exception summaries to the Patch Service Lead for governance reviews

▸ Coordinate with client NOC during weekend change windows; manage escalation to client Wintel L2/L3 within agreed SLTs

TECHNICAL ACTIVITIES FOR THE SCOPE

▸ Execute monthly Patch-Tuesday and out-of-band patch cycles via SCCM/MECM, WSUS, Intune, and Tanium across Windows Server 2016–2025 and Windows 10/11

▸ Configure and manage SCCM/MECM collections, deployment rings, WSUS approval policies, and GPO-driven patch rollouts

▸ Run pre-flight readiness checks (disk, connectivity, pending reboots, backup), reboot orchestration, and post-patch smoke tests

▸ Track compliance posture via Tenable/Qualys; remediate non-compliant assets and close vulnerability tickets in ServiceNow

▸ Author and submit RFC/CAB documentation for Windows patch waves; coordinate maintenance window scheduling

▸ Perform KB uninstall rollback for failed patches; document RCA and update KEDB

▸ Generate Windows tower compliance reports for cycle governance and coordinate app-owner sign-off

SKILLS, TOOLS & COMPETENCIES

Primary Skills

OS Expertise Windows Server 2016–2025 · Windows 10/11 · Active Directory · Group Policy (GPO) · Servicing stack updates

Patch Tools SCCM/MECM (deep) · WSUS · Microsoft Intune · Tanium · Windows Update for Business · BigFix (consumer view)

Automation PowerShell scripting · Ansible (Windows modules) · Task Scheduler · WMI/CIM automation

ITSM & Vuln ServiceNow (Change/CMDB) · Tenable · Qualys · RFC/CAB lifecycle · KEDB management

Observability Splunk · Dynatrace · Moogsoft · Windows Event Log analysis

Secondary Skills

▸ PowerShell and Ansible playbook authoring for Windows patch automation

▸ SCCM application packaging awareness and end-user device management

▸ Virtualisation (VMware/Hyper-V) and Azure Windows fundamentals

▸ VDI patching awareness — Citrix or VMware Horizon

CERTIFICATIONS

Mandatory

▸ ITIL 4 Foundation

Preferred (one or more)

▸ Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800/AZ-801)

▸ Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) — SCCM/MECM/Intune

▸ Microsoft Certified: Azure Administrator Associate (AZ-104) — advantageous

▸ Legacy MCSA: Windows Server acceptable; Tanium Certified Operator a plus

NICE TO HAVE

Experience managing SCCM environments with 100,000+ endpoints

Microsoft Endpoint Manager / Intune co-management exposure

Experience with Windows patch compliance in a regulated financial services environment

WORK MODEL & COMMITMENT

Hours Canada business hours + weekend change window coverage

Shift Model Hybrid onshore; participates in Patch-Tuesday and scheduled maintenance windows

On-Call Yes — weekend patch windows and zero-day escalations

Language English (mandatory)

Compensation: We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in Canada without requiring employer sponsorship, now or at any time in the future.

Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.

*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*


关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。

补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。

帮助您蓬勃发展与成长的福利

我们的福利计划以您为中心打造——帮助您享受充实、平衡且健康的生活。
有葉子的植物的藍色線條圖

财务健康

我们会定期审查市场数据,确保薪酬体现您所带来的价值。您的福利不仅限于薪资,还可能包括退休计划、财务教育等。

Stay Healthy Midnight Blue RGB

身心健康

我们通过带薪休假、在条件允许下的灵活工作安排、医疗保障计划、心理咨询、心理健康盟友计划等,赋能您将身心健康放在首位。

Build The Career You Want Midnight Blue RGB

您的职业发展,由您做主

在 Cognizant 提供的 35 万多个岗位中,您将有机会探索新的技术、行业和工作地点,并打造推动职业发展的关键技能。

Making A Meaningful Impact Midnight Blue RGB

现实世界的影响力

想想您所依赖的那些知名品牌。很可能,他们也依赖我们来帮助强化其业务。在这里,您将把大胆的想法转化为改善全球生活的解决方案。

还没有找到合适的机会吗?

获取为您量身定制的最新职位机会、招聘活动和公司新闻!

掌握最新动态