17 Aug
|
Cognizant
|
Ontario
About the group:
Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about accepting digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the constantly evolving needs of the digital era. Our broad approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to own the business in a secure environment.
Please note, this role is not able to offer visa transfer or sponsorship now or in the future
Role: Windows Patching Lead
Location: Toronto, ON
ROLE SUMMARY
10+ years in Windows Server/desktop administration and patching; 4+ years as tower/pod lead
The Windows Patching Tower Lead (Onshore) is the subject matter expert and client-facing lead for all Windows patching across a 190,000+ endpoint estate. This individual owns the full Windows patch lifecycle — SCCM/MECM/WSUS/Intune/Tanium-driven wave execution, GPO management, reboot orchestration, and compliance reporting — while acting as the primary Wintel interface to client L2/L3 teams and application owners during Canada business hours and weekend change windows.
ROLE IN THE OPERATING MODEL
Tower/pod lead and subject-matter expert for Windows patching — owns execution, quality, and compliance for the Windows tower
Primary Wintel interface to client L2/L3 engineers and application owners during Canada hours and weekend windows
Coordinates app-owner sign-off post-patching and owns Windows tower compliance reporting to the Patch Service Lead
Operates as the Windows execution layer under client direction; gold image/packaging engineering remains client L2/L3 owned
Directs and reviews the work of Windows-assigned offshore SMEs during onshore hours
KEY RESPONSIBILITIES
Plan and execute monthly Patch-Tuesday cumulative/quality updates, hotfixes, and out-of-band/zero-day patches via SCCM/MECM, WSUS, Intune, and Tanium
Manage SCCM/MECM deployment rings, collections, maintenance windows, WSUS approvals, and GPO-driven patch policies across servers and end-user devices
Run pre-flight checks — disk space, connectivity, pending reboots,
backup confirmation — and reboot orchestration with post-patch smoke tests
Coordinate application-owner sign-off and change-window adherence; track compliance via Tenable/Qualys and remediate non-compliant assets
Update CMDB patch levels, close vulnerability tickets, and maintain KEDB; perform RCA and rollback (KB uninstall) for failed patches
Manage EOL/EOS tracking for Windows versions; flag end-of-support risks to the Patch Service Lead
Own Windows tower compliance reporting; present KPIs and exception summaries to the Patch Service Lead for governance reviews
Coordinate with client NOC during weekend change windows; manage escalation to client Wintel L2/L3 within agreed SLTs
TECHNICAL ACTIVITIES FOR THE SCOPE
Execute monthly Patch-Tuesday and out-of-battery patch cycles via SCCM/MECM, WSUS, Intune, and Tanium across Windows Server 2016–2025 and Windows 10/11
Configure and manage SCCM/MECM collections, deployment rings, WSUS approval policies, and GPO-driven patch rollouts
Run pre-flight readiness checks (disk, connectivity, pending reboots, backup), reboot orchestration, and post-patch smoke tests
Track compliance posture via Tenable/Qualys; remediate non-compliant assets and close vulnerability tickets in ServiceNow
Author and submit RFC/CAB documentation for Windows patch waves; coordinate maintenance window scheduling
Perform KB uninstall rollback for failed patches; document RCA and update KEDB
Generate Windows tower compliance reports for cycle governance and coordinate app-owner sign-off
SKILLS, TOOLS & COMPETENCIES
Primary Skills
OS Expertise Windows Server 2016–2025 · Windows 10/11 · Active Directory · Group Policy (GPO) · Servicing stack updates
Patch Tools SCCM/MECM (deep)
· WSUS · Microsoft Intune · Tanium · Windows Update for Business · BigFix (consumer view)
Automation PowerShell scripting · Ansible (Windows modules) · Task Scheduler · WMI/CIM automation
ITSM & Vuln ServiceNow (Change/CMDB) · Tenable · Qualys · RFC/CAB lifecycle · KEDB management
Observability Splunk · Dynatrace · Moogsoft · Windows Event Log analysis
Secondary Skills
PowerShell and Ansible playbook authoring for Windows patch automation
SCCM application packaging awareness and end-user device management
Virtualisation (VMware/Hyper-V) and Azure Windows fundamentals
VDI patching awareness — Citrix or VMware Horizon
CERTIFICATIONS
Mandatory
ITIL 4 Foundation
Preferred (one or more)
Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800/AZ-801)
Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) — SCCM/MECM/Intune
Microsoft Certified: Azure Administrator Associate (AZ-104) — advantageous
Legacy MCSA: Windows Server acceptable; Tanium Certified Operator a plus
NICE TO HAVE
Experience managing SCCM environments with 100,000+ endpoints
Microsoft Endpoint Manager / Intune co-management exposure
Experience with Windows patch compliance in a regulated financial services environment
WORK MODEL & COMMITMENT
Hours
Canada business hours + weekend change window coverage
Shift Model
Hybrid onshore; participates in Patch-Tuesday and scheduled maintenance windows
On-Call
Yes — weekend patch windows and zero-day escalations
Language
English (mandatory)
Compensation
We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in Canada without requiring employer sponsorship, now or at any time in the future.
Disclaimer
The salary, other compensation, and advantages information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
Please note, this role is not able to offer visa transfer or sponsorship now or in the future
#J-18808-Ljbffr
📌 Windows Patching Lead (Ontario)
🏢 Cognizant
📍 Ontario