We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

System Configuration Engineer

Debevoise & Plimpton LLP
$130,000-$160,000
United States, New York, New York
66 Hudson Boulevard East (Show on map)
Sep 09, 2026
System Configuration Engineer
Information Services Department

Debevoise & Plimpton LLP is a premier law firm with market-leading practices, a global perspective and strong New York roots. Our clients look to us to bring a distinctively high degree of quality, intensity and creativity to resolve legal challenges effectively and cost efficiently. We believe in hiring talented and dedicated individuals as members of our administrative community. We draw on the strength of our culture and structure to deliver the best of our firm to our lawyers and clients through true collaboration.

The firm is seeking a System Configuration Engineer in our New York office.

The System Configuration Engineer has overall responsibility for the firm's enterprise patching and configuration management program across all Windows and Linux servers. This role administers Microsoft Configuration Manager (SCCM), leads the onboarding and management of on-premises servers through Azure Arc, and develops PowerShell-based automation to improve security, reliability, and operational efficiency in a global 24x7 environment. The position partners closely with Information Security to establish and maintain server security baselines aligned with current recommendations and best practices. This position reports to the Associate Director, Technology Engineering.

RESPONSIBILITIES include but are not limited to:
  • Own and manage the enterprise patching program for all Windows and Linux servers, including inventory, risk prioritization, testing, scheduling, deployment, validation, remediation, and compliance reporting.
  • Administer and optimize Microsoft Configuration Manager (SCCM), including software update points, WSUS, collections, automatic deployment rules, maintenance windows, distribution, compliance baselines, and reporting.
  • Lead the onboarding and lifecycle management of on-premises Windows and Linux servers in Azure Arc, including agent deployment, identity, network and proxy requirements, extensions, policies, tags, RBAC, connectivity, and health monitoring.
  • Use Azure Update Manager and related Azure Arc services to assess, schedule, deploy, and report updates for hybrid Windows and Linux servers.
  • Develop and maintain PowerShell scripts, reusable modules, and workflow automation for onboarding, patching, configuration, compliance reporting, and automated remediation.
  • Partner with the Information Security team to create, test, implement, and maintain server security baselines based on current Microsoft and vendor guidance, industry benchmarks, and firm requirements.
  • Monitor patch, configuration, vulnerability, and baseline compliance; investigate failures and exceptions; coordinate remediation; and provide clear metrics to technical and business stakeholders.
  • Define and enforce patching and configuration standards, change management practices, maintenance schedules, pilot procedures, rollback plans, and operational runbooks.
  • Serve as the primary escalation point for complex SCCM, Azure Arc, Windows, and automation issues; maintain comprehensive documentation; and perform other duties as deemed appropriate by the Associate Director, Technology Engineering.
REQUIREMENTS:
The ideal candidate possesses strong communication, organizational, and technical skills, with the ability to take ownership of enterprise-wide patching and configuration programs and collaborate effectively across teams. Must demonstrate a proven ability to automate complex processes, troubleshoot critical issues, and operate in a fast-paced, high-availability environment. Must be available to work outside of normal business hours as needed.
  • Minimum 7 years of experience in enterprise systems engineering, server administration, or infrastructure operations.
  • Minimum 5 years of hands-on experience administering Microsoft Configuration Manager (SCCM) in a large enterprise environment.
  • Minimum 3 years of hands-on experience with Azure Arc-enabled servers and hybrid server management.
  • Minimum 5 years of advanced PowerShell scripting and workflow automation experience, including reusable modules, remoting, REST APIs, structured error handling, logging, testing, and secure credential handling.
  • Proven experience designing and operating enterprise patching programs across Windows environments.
  • Deep expertise with SCCM software update management, including WSUS, software update points, collections, automatic deployment rules, maintenance windows, distribution points, boundaries, and compliance reporting.
  • Proven experience onboarding on-premises Windows servers to Azure Arc at scale using scripts, service principals, Configuration Manager, or other automated deployment methods.
  • Strong working knowledge of Azure Arc agents, extensions, resource organization, identity, RBAC, policy, network connectivity, proxy configuration, monitoring, and troubleshooting.
  • Experience using Azure Update Manager or comparable tools to assess, schedule, deploy, and report server updates.
  • Strong Windows Server administration experience, including Active Directory, Group Policy, Windows Update, certificates, services, and enterprise troubleshooting.
  • Strong Linux administration experience, including package managers, repositories, services, permissions, shell scripting, and troubleshooting across common enterprise distributions.
  • Experience developing and enforcing server configuration and security baselines in partnership with Information Security.
  • Strong understanding of vulnerability management, security hardening, least privilege, change management, exception management, and audit requirements.
  • Proven ability to plan pilot groups, phased deployments, maintenance windows, reboot coordination, and rollback strategies that minimize business impact.
  • Experience producing patch compliance dashboards, operational metrics, executive reporting, and audit evidence.
  • Demonstrated expertise in analyzing and resolving complex server, agent, identity, network, patching, and automation issues.
  • A strong sense of ownership and excellent attention to detail while working in a very fast-paced and energetic environment.
PREFERRED QUALIFICATIONS:
  • Microsoft certifications in Azure administration, Windows Server hybrid administration, endpoint management, or security strongly preferred.
  • Experience with Desired State Configuration, configuration-as-code, or infrastructure-as-code tools such as Ansible, Terraform, or Bicep.
  • Experience with Azure Automation, GitHub Actions, enterprise job scheduling, or other orchestration platforms.
  • Experience implementing CIS Benchmarks, Microsoft security baselines, or comparable hardening standards for Windows servers.
  • Experience managing enterprise VMware ESXi and vCenter environents, including workload deployments, HA/DRS, vMotion, Lifecycle Manager, templates, resource allocation, snapshots, migrations, capacity management, and troubleshooting.
  • Experience provisioning SAN storage for VMware and server workloads, including zoning, LUN creation and presentation, masking, multipathing, VMFS datastores, capacity planning, and performance management.
  • Experience integrating vulnerability management findings with patching, remediation, and exception workflows.
  • Experience using SQL, SSRS, Power BI, or similar tools for SCCM and compliance reporting.
  • Experience with structured project management or serving as technical lead on infrastructure, security remediation, or hybrid cloud initiatives.
  • Excellent documentation skills, including architecture diagrams, implementation plans, standards, and runbooks using tools such as Visio and Word.

TO APPLY:
When applying please specify where you saw this position posted for tracking purposes. Send cover letter, resume and salary requirements:

John Ferrigno

jferrigno@debevoise.com
212.909.8310

Applied = 0

(web-665cd84569-cc6jf)