About the group:
Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about accepting digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the constantly evolving needs of the digital era. Our broad approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to own the business in a secure environment.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Role: Windows Patching Lead
Location: Toronto, ON
ROLE SUMMARY
10+ years in Windows Server/desktop administration and patching; 4+ years as tower/pod lead
The Windows Patching Tower Lead (Onshore) is the subject matter expert and client-facing lead for all Windows patching across a 190,000+ endpoint estate. This individual owns the full Windows patch lifecycle — SCCM/MECM/WSUS/Intune/Tanium-driven wave execution, GPO management, reboot orchestration, and compliance reporting — while acting as the primary Wintel interface to client L2/L3 teams and application owners during Canada business hours and weekend change windows.
ROLE IN THE OPERATING MODEL
▸ Tower/pod lead and subject-matter expert for Windows patching — owns execution, quality, and compliance for the Windows tower
▸ Primary Wintel interface to client L2/L3 engineers and application owners during Canada hours and weekend windows
▸ Coordinates app-owner sign-off post-patching and owns Windows tower compliance reporting to the Patch Service Lead
▸ Operates as the Windows execution layer under client direction; gold image/packaging engineering remains client L2/L3 owned
▸ Directs and reviews the work of Windows-assigned offshore SMEs during onshore hours
KEY RESPONSIBILITIES
▸ Plan and execute monthly Patch-Tuesday cumulative/quality updates, hotfixes, and out-of-band/zero-day patches via SCCM/MECM, WSUS, Intune, and Tanium
▸ Manage SCCM/MECM deployment rings, collections, maintenance windows, WSUS approvals, and GPO-driven patch policies across servers and end-user devices
▸ Run pre-flight checks — disk space, connectivity, pending reboots, backup confirmation — and reboot orchestration with post-patch smoke tests
▸ Coordinate application-owner sign-off and change-window adherence; track compliance via Tenable/Qualys and remediate non-compliant assets
▸ Update CMDB patch levels, close vulnerability tickets, and maintain KEDB; perform RCA and rollback (KB uninstall) for failed patches
▸ Manage EOL/EOS tracking for Windows versions; flag end-of-support risks to the Patch Service Lead
▸ Own Windows tower compliance reporting; present KPIs and exception summaries to the Patch Service Lead for governance reviews
▸ Coordinate with client NOC during weekend change windows; manage escalation to client Wintel L2/L3 within agreed SLTs
TECHNICAL ACTIVITIES FOR THE SCOPE
▸ Execute monthly Patch-Tuesday and out-of-band patch cycles via SCCM/MECM, WSUS, Intune, and Tanium across Windows Server 2016–2025 and Windows 10/11
▸ Configure and manage SCCM/MECM collections, deployment rings, WSUS approval policies, and GPO-driven patch rollouts
▸ Run pre-flight readiness checks (disk, connectivity, pending reboots, backup), reboot orchestration, and post-patch smoke tests
▸ Track compliance posture via Tenable/Qualys; remediate non-compliant assets and close vulnerability tickets in ServiceNow
▸ Author and submit RFC/CAB documentation for Windows patch waves; coordinate maintenance window scheduling
▸ Perform KB uninstall rollback for failed patches; document RCA and update KEDB
▸ Generate Windows tower compliance reports for cycle governance and coordinate app-owner sign-off
SKILLS, TOOLS & COMPETENCIES
Primary Skills
OS Expertise Windows Server 2016–2025 · Windows 10/11 · Active Directory · Group Policy (GPO) · Servicing stack updates
Patch Tools SCCM/MECM (deep) · WSUS · Microsoft Intune · Tanium · Windows Update for Business · BigFix (consumer view)
Automation PowerShell scripting · Ansible (Windows modules) · Task Scheduler · WMI/CIM automation
ITSM & Vuln ServiceNow (Change/CMDB) · Tenable · Qualys · RFC/CAB lifecycle · KEDB management
Observability Splunk · Dynatrace · Moogsoft · Windows Event Log analysis
Secondary Skills
▸ PowerShell and Ansible playbook authoring for Windows patch automation
▸ SCCM application packaging awareness and end-user device management
▸ Virtualisation (VMware/Hyper-V) and Azure Windows fundamentals
▸ VDI patching awareness — Citrix or VMware Horizon
CERTIFICATIONS
Mandatory
▸ ITIL 4 Foundation
Preferred (one or more)
▸ Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800/AZ-801)
▸ Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) — SCCM/MECM/Intune
▸ Microsoft Certified: Azure Administrator Associate (AZ-104) — advantageous
▸ Legacy MCSA: Windows Server acceptable; Tanium Certified Operator a plus
NICE TO HAVE
▸ Experience managing SCCM environments with 100,000+ endpoints
▸ Microsoft Endpoint Manager / Intune co-management exposure
▸ Experience with Windows patch compliance in a regulated financial services environment
WORK MODEL & COMMITMENT
Hours Canada business hours + weekend change window coverage
Shift Model Hybrid onshore; participates in Patch-Tuesday and scheduled maintenance windows
On-Call Yes — weekend patch windows and zero-day escalations
Language English (mandatory)
Compensation: We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in Canada without requiring employer sponsorship, now or at any time in the future.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
About Cognizant:
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, bridging the gap between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, drive tangible outcomes and keep global enterprises ahead in a fast-changing world. See how at cognizant.ai or @cognizant.
Additional employment information
Compensation information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government issued ID during each interview.
Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.
If you have a disability that requires reasonable accommodation to search for a job opening or submit an application, please email [email protected] with your request and contact information.











