About the group:
Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about accepting digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the constantly evolving needs of the digital era. Our broad approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to own the business in a secure environment.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Role: Windows Patching Lead
Location: Toronto, ON
ROLE SUMMARY
10+ years in Windows Server/desktop administration and patching; 4+ years as tower/pod lead
The Windows Patching Tower Lead (Onshore) is the subject matter expert and client-facing lead for all Windows patching across a 190,000+ endpoint estate. This individual owns the full Windows patch lifecycle — SCCM/MECM/WSUS/Intune/Tanium-driven wave execution, GPO management, reboot orchestration, and compliance reporting — while acting as the primary Wintel interface to client L2/L3 teams and application owners during Canada business hours and weekend change windows.
ROLE IN THE OPERATING MODEL
▸ Tower/pod lead and subject-matter expert for Windows patching — owns execution, quality, and compliance for the Windows tower
▸ Primary Wintel interface to client L2/L3 engineers and application owners during Canada hours and weekend windows
▸ Coordinates app-owner sign-off post-patching and owns Windows tower compliance reporting to the Patch Service Lead
▸ Operates as the Windows execution layer under client direction; gold image/packaging engineering remains client L2/L3 owned
▸ Directs and reviews the work of Windows-assigned offshore SMEs during onshore hours
KEY RESPONSIBILITIES
▸ Plan and execute monthly Patch-Tuesday cumulative/quality updates, hotfixes, and out-of-band/zero-day patches via SCCM/MECM, WSUS, Intune, and Tanium
▸ Manage SCCM/MECM deployment rings, collections, maintenance windows, WSUS approvals, and GPO-driven patch policies across servers and end-user devices
▸ Run pre-flight checks — disk space, connectivity, pending reboots, backup confirmation — and reboot orchestration with post-patch smoke tests
▸ Coordinate application-owner sign-off and change-window adherence; track compliance via Tenable/Qualys and remediate non-compliant assets
▸ Update CMDB patch levels, close vulnerability tickets, and maintain KEDB; perform RCA and rollback (KB uninstall) for failed patches
▸ Manage EOL/EOS tracking for Windows versions; flag end-of-support risks to the Patch Service Lead
▸ Own Windows tower compliance reporting; present KPIs and exception summaries to the Patch Service Lead for governance reviews
▸ Coordinate with client NOC during weekend change windows; manage escalation to client Wintel L2/L3 within agreed SLTs
TECHNICAL ACTIVITIES FOR THE SCOPE
▸ Execute monthly Patch-Tuesday and out-of-band patch cycles via SCCM/MECM, WSUS, Intune, and Tanium across Windows Server 2016–2025 and Windows 10/11
▸ Configure and manage SCCM/MECM collections, deployment rings, WSUS approval policies, and GPO-driven patch rollouts
▸ Run pre-flight readiness checks (disk, connectivity, pending reboots, backup), reboot orchestration, and post-patch smoke tests
▸ Track compliance posture via Tenable/Qualys; remediate non-compliant assets and close vulnerability tickets in ServiceNow
▸ Author and submit RFC/CAB documentation for Windows patch waves; coordinate maintenance window scheduling
▸ Perform KB uninstall rollback for failed patches; document RCA and update KEDB
▸ Generate Windows tower compliance reports for cycle governance and coordinate app-owner sign-off
SKILLS, TOOLS & COMPETENCIES
Primary Skills
OS Expertise Windows Server 2016–2025 · Windows 10/11 · Active Directory · Group Policy (GPO) · Servicing stack updates
Patch Tools SCCM/MECM (deep) · WSUS · Microsoft Intune · Tanium · Windows Update for Business · BigFix (consumer view)
Automation PowerShell scripting · Ansible (Windows modules) · Task Scheduler · WMI/CIM automation
ITSM & Vuln ServiceNow (Change/CMDB) · Tenable · Qualys · RFC/CAB lifecycle · KEDB management
Observability Splunk · Dynatrace · Moogsoft · Windows Event Log analysis
Secondary Skills
▸ PowerShell and Ansible playbook authoring for Windows patch automation
▸ SCCM application packaging awareness and end-user device management
▸ Virtualisation (VMware/Hyper-V) and Azure Windows fundamentals
▸ VDI patching awareness — Citrix or VMware Horizon
CERTIFICATIONS
Mandatory
▸ ITIL 4 Foundation
Preferred (one or more)
▸ Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800/AZ-801)
▸ Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) — SCCM/MECM/Intune
▸ Microsoft Certified: Azure Administrator Associate (AZ-104) — advantageous
▸ Legacy MCSA: Windows Server acceptable; Tanium Certified Operator a plus
NICE TO HAVE
▸ Experience managing SCCM environments with 100,000+ endpoints
▸ Microsoft Endpoint Manager / Intune co-management exposure
▸ Experience with Windows patch compliance in a regulated financial services environment
WORK MODEL & COMMITMENT
Hours Canada business hours + weekend change window coverage
Shift Model Hybrid onshore; participates in Patch-Tuesday and scheduled maintenance windows
On-Call Yes — weekend patch windows and zero-day escalations
Language English (mandatory)
Compensation: We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in Canada without requiring employer sponsorship, now or at any time in the future.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Acerca de Cognizant
Cognizant (Nasdaq: CTSH) es un creador de soluciones de IA y proveedor de servicios tecnológicos que conecta la inversión en IA con el valor empresarial mediante el desarrollo de soluciones de IA full‑stack para sus clientes. Su profundo conocimiento de la industria, junto con su experiencia en procesos e ingeniería, permite incorporar el contexto único de cada organización en sistemas tecnológicos que amplifican el potencial humano, generan resultados tangibles y mantienen a las empresas a la vanguardia en un entorno en constante cambio. Más información en cognizant.ai o @cognizant.
Información adicional sobre el empleo
La información sobre la compensación es exacta en la fecha de publicación de este anuncio. Cognizant se reserva el derecho de modificar esta información en cualquier momento, de conformidad con la legislación aplicable.
Es posible que se solicite a los solicitantes que asistan a entrevistas de forma presencial o mediante videoconferencia. Asimismo, durante cada entrevista, los candidatos podrán estar obligados a presentar un documento de identidad válido emitido por el estado o por el gobierno.
Cognizant es un empleador que ofrece igualdad de oportunidades. Su solicitud y candidatura no se evaluarán en función de la raza, el color, el sexo, la religión, el credo, la orientación sexual, la identidad de género, el origen nacional, la discapacidad, la información genética, el embarazo, la condición de veterano ni cualquier otra característica protegida por las leyes federales, estatales o locales.







