About the group:
Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about accepting digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the constantly evolving needs of the digital era. Our broad approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to own the business in a secure environment.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Role: Windows Patching Lead
Location: Toronto, ON
ROLE SUMMARY
10+ years in Windows Server/desktop administration and patching; 4+ years as tower/pod lead
The Windows Patching Tower Lead (Onshore) is the subject matter expert and client-facing lead for all Windows patching across a 190,000+ endpoint estate. This individual owns the full Windows patch lifecycle — SCCM/MECM/WSUS/Intune/Tanium-driven wave execution, GPO management, reboot orchestration, and compliance reporting — while acting as the primary Wintel interface to client L2/L3 teams and application owners during Canada business hours and weekend change windows.
ROLE IN THE OPERATING MODEL
▸ Tower/pod lead and subject-matter expert for Windows patching — owns execution, quality, and compliance for the Windows tower
▸ Primary Wintel interface to client L2/L3 engineers and application owners during Canada hours and weekend windows
▸ Coordinates app-owner sign-off post-patching and owns Windows tower compliance reporting to the Patch Service Lead
▸ Operates as the Windows execution layer under client direction; gold image/packaging engineering remains client L2/L3 owned
▸ Directs and reviews the work of Windows-assigned offshore SMEs during onshore hours
KEY RESPONSIBILITIES
▸ Plan and execute monthly Patch-Tuesday cumulative/quality updates, hotfixes, and out-of-band/zero-day patches via SCCM/MECM, WSUS, Intune, and Tanium
▸ Manage SCCM/MECM deployment rings, collections, maintenance windows, WSUS approvals, and GPO-driven patch policies across servers and end-user devices
▸ Run pre-flight checks — disk space, connectivity, pending reboots, backup confirmation — and reboot orchestration with post-patch smoke tests
▸ Coordinate application-owner sign-off and change-window adherence; track compliance via Tenable/Qualys and remediate non-compliant assets
▸ Update CMDB patch levels, close vulnerability tickets, and maintain KEDB; perform RCA and rollback (KB uninstall) for failed patches
▸ Manage EOL/EOS tracking for Windows versions; flag end-of-support risks to the Patch Service Lead
▸ Own Windows tower compliance reporting; present KPIs and exception summaries to the Patch Service Lead for governance reviews
▸ Coordinate with client NOC during weekend change windows; manage escalation to client Wintel L2/L3 within agreed SLTs
TECHNICAL ACTIVITIES FOR THE SCOPE
▸ Execute monthly Patch-Tuesday and out-of-band patch cycles via SCCM/MECM, WSUS, Intune, and Tanium across Windows Server 2016–2025 and Windows 10/11
▸ Configure and manage SCCM/MECM collections, deployment rings, WSUS approval policies, and GPO-driven patch rollouts
▸ Run pre-flight readiness checks (disk, connectivity, pending reboots, backup), reboot orchestration, and post-patch smoke tests
▸ Track compliance posture via Tenable/Qualys; remediate non-compliant assets and close vulnerability tickets in ServiceNow
▸ Author and submit RFC/CAB documentation for Windows patch waves; coordinate maintenance window scheduling
▸ Perform KB uninstall rollback for failed patches; document RCA and update KEDB
▸ Generate Windows tower compliance reports for cycle governance and coordinate app-owner sign-off
SKILLS, TOOLS & COMPETENCIES
Primary Skills
OS Expertise Windows Server 2016–2025 · Windows 10/11 · Active Directory · Group Policy (GPO) · Servicing stack updates
Patch Tools SCCM/MECM (deep) · WSUS · Microsoft Intune · Tanium · Windows Update for Business · BigFix (consumer view)
Automation PowerShell scripting · Ansible (Windows modules) · Task Scheduler · WMI/CIM automation
ITSM & Vuln ServiceNow (Change/CMDB) · Tenable · Qualys · RFC/CAB lifecycle · KEDB management
Observability Splunk · Dynatrace · Moogsoft · Windows Event Log analysis
Secondary Skills
▸ PowerShell and Ansible playbook authoring for Windows patch automation
▸ SCCM application packaging awareness and end-user device management
▸ Virtualisation (VMware/Hyper-V) and Azure Windows fundamentals
▸ VDI patching awareness — Citrix or VMware Horizon
CERTIFICATIONS
Mandatory
▸ ITIL 4 Foundation
Preferred (one or more)
▸ Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800/AZ-801)
▸ Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) — SCCM/MECM/Intune
▸ Microsoft Certified: Azure Administrator Associate (AZ-104) — advantageous
▸ Legacy MCSA: Windows Server acceptable; Tanium Certified Operator a plus
NICE TO HAVE
▸ Experience managing SCCM environments with 100,000+ endpoints
▸ Microsoft Endpoint Manager / Intune co-management exposure
▸ Experience with Windows patch compliance in a regulated financial services environment
WORK MODEL & COMMITMENT
Hours Canada business hours + weekend change window coverage
Shift Model Hybrid onshore; participates in Patch-Tuesday and scheduled maintenance windows
On-Call Yes — weekend patch windows and zero-day escalations
Language English (mandatory)
Compensation: We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in Canada without requiring employer sponsorship, now or at any time in the future.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
À propos de Cognizant
Cognizant (NASDAQ : CTSH) est un AI Builder et une entreprise de services numériques (ESN) élaborant des solutions complètes d’IA maximisant les investissements pour des résultats concrets. Sa profonde expertise des métiers, des processus et des technologies lui permet d’intégrer dans les systèmes technologiques le contexte unique de chaque organisation de l’ingénierie à la production à l’échelle. Son objectif : améliorer l’efficacité des équipes, créer de la valeur et permettre aux grandes entreprises de rester performantes dans un monde qui évolue rapidement. Pour en savoir plus : cognizant.ai ou @cognizant.
Renseignments suppplémentaires sur l'emploi
Les informations relatives à la rémunération du poste à pourvoir dépendent de la date de publication de l’offre de poste. Cognizant se réserve le droit de modifier ces informations à tout moment, sous réserve des lois applicables.
Cognizant est un employeur soucieux de l'égalité des chances entre candidats. Votre candidature sera étudiée indépendamment de votre race, couleur, sexe, religion, croyances, orientation sexuelle, identité de genre, origine, handicap, informations génétiques, grossesse, statut d'ancien militaire ou de toute autre critère jugé discriminant par les lois européennes ou françaises.
Vous êtes porteur d'un handicap, vous pouvez-nous contacter par courriel [email protected] si vous souhaitez préciser les aménagements nécessaires pour le poste ou les entretiens à venir.
Les candidats peuvent être invités à participer à des entretiens en face à face ou par vidéoconférence. En outre, les candidats peuvent être amenés à présenter une carte d'identité valide lors de chaque entretien.







