SCCM (Bengaluru)

SCCM (Bengaluru)

08 Sep
|
Athena Bharatjobs
|
Bengaluru

08 Sep

Athena Bharatjobs

Bengaluru

SCCM / MECM Engineer (L3) with Intune Knowledge — Revised

Position: SCCM / MECM Engineer – L3

Tower: End User Computing (EUC) / Windows Endpoint Management

Experience: 7–12 Years

Location: Hybrid / Remote / Onsite

Reporting To: Endpoint Management Lead / EUC Manager

Role Summary The SCCM / MECM Engineer (L3) is responsible for the architecture, administration, governance, and advanced support of a global, multi-region Windows endpoint management platform built on Microsoft Configuration Manager (SCCM/MECM Current Branch), with additional expertise in Microsoft Intune, Co-Management, Autopilot, and Modern Device Management technologies.

The environment operates at significant scale: ~600 servers (physical and virtual), 1 Central Administration Site with an Always-On High-Availability SQL Server Cluster, 5 Primary Sites (2 EMEA, 1 APAC, 1 NAFTA, 1 LATAM), 400+ tenants including 71 Smart Tenants, and ~4,000 IP boundaries, supporting Windows Office, Engineering, and Factory clients plus related Windows-based server systems.

The role serves as the highest technical escalation point for Windows endpoint lifecycle management, operating system deployment, software distribution, patch management, compliance enforcement, reporting, automation, and endpoint modernization initiatives, and plays a critical role supporting the organization's transition from traditional (Classic/SCCM) endpoint management to cloud-native (Modern/Intune) management models.

The role also operates and maintains an extensive stack of client-proprietary and legacy tools layered on top of SCCM — full onboarding training is provided (see Onboarding Note below).

Key Responsibilities

Enterprise SCCM Platform Architecture (Global, Multi-Region) —

- Design, administer, and maintain a global SCCM/MECM Current Branch infrastructure spanning 1 Central Administration Site (with an Always-On High-Availability SQL Server Cluster) and 5 Primary Sites across EMEA (x2), APAC, NAFTA, and LATAM.
- Administer and troubleshoot the SQL Server Always-On Availability Group backing the Central Administration Site, including failover testing and performance tuning.
- Manage the 400+ tenant / 71 Smart Tenant multi-tenancy model, including tenant creation, updates, and decommissioning of stale tenants.
- Monitor and maintain the Cloud Management Gateway (CMG) and Cloud Connector linking the on-premise environment to the client's central Entra ID / Intune tenant, including certificate renewal (currently a biennial cycle).
- Operate SCOM (System Center Operations Manager) for infrastructure health and event monitoring.
- Maintain the automation and configuration environment behind SCCM: a SharePoint Server with Nintex workflows and a System Center Orchestrator server used for ConfigMgr configuration automation and object creation.
- Own IP-address and boundary management across ~4,000 IP boundaries; perform ongoing housekeeping (collection evaluation, cleanup, tenant validation).

Client-Proprietary & Legacy Tooling (Mercedes-Benz Environment) —

- Operate, maintain, and where required extend the following tools as part of standard SCCM operations: NextSF (Next Script Framework), LaMa / LaMa Solution (local admin rights management, being succeeded by Windows LAPS), CoSyMa (Software Release Management & Application Deployment Tool), DynAppCo (application configuration), CoMobi (ConfigMgr onboarding from the SIT database), SIT / SIT@Web / Web SIT (packaging workflow — templates, conflict checks, SLA calculation, app onboarding to Intune), Software Release Creator (SCCM-based Task Sequence bundling), Software Update Deployment Creator (Maas Update Deployment configuration), System Center Updates Publisher (SCUP — legacy, unsupported), SoMaDS (application uninstallation), PADT (customized app deployment),



BIOS Framework (BIOS/firmware update installation), SMS Mini/Proxy Web Service, Driver Web Service, Upload Web Service, DataBee (on-prem Power BI reporting solution, being migrated to cloud reporting), PC Info (local/central settings display tool), Zero Balancing scripts (AD/SCCM/Entra ID/Intune object consistency), WMI class/provider extensions, and Trellix Client Security (formerly McAfee FRP, used for file-share encryption).
- Maintain and evolve scripts implementing the User-Setting-Data-Management (USDM) concept — post-provisioning configuration of user home directories, standard user data folders, and roaming settings.
- Own source code and IP custody for SCCM-related automation scripts and tools in GitHub; document and version all changes under change management.

SCCM / MECM Platform Administration

- Design, administer, and maintain SCCM/MECM infrastructure: Primary and Secondary Sites, Management Points, Distribution Points, Software Update Points, Reporting Services, Boundary Groups.
- Monitor platform health and performance; maintain client agent standards and compliance; troubleshoot SCCM infrastructure and client-related issues.

Operating System Deployment (OSD)

- Design and maintain Windows deployment solutions: Task Sequences, Boot Images, Driver Management, OS Images, PXE Deployments.
- Support Windows 10/11 deployment and refresh programs; troubleshoot deployment failures and imaging issues; manage feature update deployment strategies.

Software Distribution & Application Management

- Package and deploy enterprise applications using SCCM: MSI Packages, EXE Installations, PowerShell Deployments, Application Groups, Software Center Management.
- Manage software release processes and deployment governance; troubleshoot application deployment issues; support application lifecycle management.

Patch & Update Management

- Administer Software Update Management (SUM): WSUS Integration, Automatic Deployment Rules (ADRs), Update Deployment Packages, Feature Updates, Quality Updates, Driver Updates.
- Monitor patch compliance and remediation; generate compliance reporting and dashboards.

Intune & Co-Management Support

- Support SCCM and Intune co-management environments; assist in workload transitions from SCCM to Intune, including Compliance Policies, Device Configuration Policies, Endpoint Security Profiles, and Windows Update for Business (WUfB).
- Manage the Cloud Attach configuration and hybrid Azure AD (Entra ID) device synchronization via Azure AD Connect.
- Troubleshoot enrollment and co-management issues; support hybrid and cloud-managed endpoint strategies.

Modern Workplace Technologies

- Support and administer Microsoft Intune, Windows Autopilot, Windows Autopatch, Microsoft Entra ID, Hybrid Join, Cloud Attach.
- Assist modernization initiatives focused on cloud-native management; support automated provisioning and zero-touch deployment strategies.

Endpoint Security & Compliance

- Implement and maintain compliance baselines, security policies, encryption standards, endpoint hardening controls.
- Support vulnerability remediation initiatives; work with Cyber Security teams on compliance requirements; ensure endpoint audit readiness.

Active Directory & Identity Integration

- Support integration with Active Directory, Microsoft Entra ID, and hybrid environments.
- Troubleshoot device registration, Group Policy issues, hybrid join failures,



and identity synchronization issues.
- Maintain endpoint identity lifecycle processes; perform AD compliance activities for the central SCCM environment; validate co-management scope on client devices.

Reporting, Automation & Continuous Improvement

- Develop automated administrative solutions using PowerShell, SCCM Automation, and Reporting Services.
- Support Client Health Reporting, Patch Compliance Reporting, Deployment Reporting, Asset Reporting.
- Drive operational efficiency and process optimization; run housekeeping activities to improve infrastructure stability.

Incident, Problem & Change Management

- Act as L3 escalation point for endpoint-related incidents; lead Root Cause Analysis (RCA) activities.
- Review high-risk changes and deployments; participate in CAB reviews; support Major Incident Management activities.
- Mentor and guide L1/L2 engineers.

Technical Skills (Mandatory)

Microsoft Endpoint Management

- SCCM / MECM Current Branch
- Endpoint Configuration Manager
- Client Health Management
- Boundary & Boundary Group Administration
- Software Update Management
- Operating System Deployment
- Software Distribution
- Application Packaging

Global Platform Architecture

- Multi-Region CAS / Primary Site Architecture (5-site global topology)
- SQL Server Always-On Availability Group Administration
- Cloud Management Gateway (CMG) & Cloud Connector Management
- SCOM (System Center Operations Manager)
- SharePoint / Nintex Workflow Administration
- System Center Orchestrator
- GitHub Source Control (script/tool IP custody)

Client-Proprietary Tooling (Trained during onboarding)

- NextSF (Next Script Framework)
- LaMa Solution (local admin rights)
- CoSyMa (Software Release Mgmt)
- SIT / SIT@Web (packaging workflow)
- DynAppCo, CoMobi, SoMaDS, PADT (application config/deployment tools)
- DataBee (on-prem Power BI reporting)
- USDM (User-Setting-Data-Management) concept

Contemporary Device Management

- Microsoft Intune
- Co-Management
- Cloud Attach
- Windows Autopilot
- Windows Autopatch
- Windows Update for Business (WUfB)
- Device Compliance Policies
- Device Configuration Profiles

Identity & Security

- Active Directory
- Microsoft Entra ID
- Hybrid Join
- Group Policy
- BitLocker
- Compliance Baselines
- Endpoint Security Policies
- LAPS

Scripting & Automation

- PowerShell
- Task Sequence Automation
- SCCM Scripting
- Reporting Automation
- SQL Query Fundamentals
- SSRS Reporting

ITSM & Governance

- ServiceNow
- Incident Management
- Problem Management
- Change Management
- Knowledge Management
- Governance Reporting

Preferred Skills
- Windows 11 Engineering
- Microsoft Graph API
- Azure Administration
- Endpoint Analytics
- Patch My PC
- App-V / MSIX Packaging
- Azure Virtual Desktop (AVD)
- Citrix Virtual Apps & Desktops
- Power BI Reporting
- German Language (B2) — preferred for DACH-region support rotations (confirm with account team)

Educational Qualification Bachelor's Degree in Computer Science, Information Technology, Engineering, or equivalent.

Preferred Certifications

Microsoft Certifications

- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Microsoft 365 Enterprise Administrator Expert
- Azure Administrator Associate (AZ-104)
- Microsoft 365 Fundamentals (MS-900)

Service Management

- ITIL Foundation Certification

Experience Requirements

Skill Area

Experience

SCCM / MECM Administration

5+ Years

Windows Endpoint Management

7+ Years

OS Deployment & Task Sequences

5+ Years

Patch & Compliance Management

5+ Years

Application Packaging & Deployment

4+ Years

Multi-Region / Multi-Site SCCM Architecture

3+ Years

SQL Server Always-On Administration

2+ Years

Microsoft Intune

2+ Years

PowerShell Automation

3+ Years

Technical Leadership

3+ Years

📌 SCCM (Bengaluru)
🏢 Athena Bharatjobs
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sccm (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: sccm (bengaluru) / bengaluru