Haystack
← Back to Jobs
Remote
Other

Enterprise Patch Management Engineer

K-Tek Resourcing LLCUnited States🇺🇸United StatesPosted 17 Aug 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Enterprise Patch Management Engineer

Location: Remote, US

Client - OCC Through NESS

Enterprise Patch Management Engineer

Infrastructure / Platform Engineering | Vulnerability & Patch Management

Role Type

Engineering / Advisory

Experience

5+ years

Primary Focus

Enterprise patching transformation

Openings

3 anticipated

Environment

Cross-platform enterprise infrastructure

Key Outcome

Risk-based, higher-frequency patching

Position Summary

We are seeking an experienced Enterprise Patch Management Engineer to assess current patching processes across a broad technology environment and design a practical future-state approach that enables faster, more frequent, automated, and lower-risk patching. The engineer will work across infrastructure, platform, security, and application technology teams to document current practices, identify constraints, establish risk- and criticality-based patch cadences and service levels, and define an actionable roadmap for improvement.

This is not a narrowly focused patch-operations role. The successful candidate must be able to combine hands-on technical knowledge with process assessment, architecture/design thinking, automation, vulnerability management, stakeholder facilitation, and strong documentation.

Key Responsibilities

  • Assess and document the current-state patching process for each major system and technology group, including ownership, tooling, dependencies, approvals, testing, deployment, rollback, exception handling, reporting, and governance.
  • Evaluate patching practices across networking, operating systems, databases and middleware, virtualization and VDI, CI/CD and container platforms, storage, secrets/PKI/HSM platforms, and application security scanning.
  • Identify gaps, bottlenecks, manual activities, technical dependencies, control requirements, and operational constraints that limit patch frequency or increase deployment risk.
  • Analyze how vulnerabilities are identified, prioritized, remediated, validated, tracked, and reported across the enterprise.
  • Develop a criticality and risk-scoring approach for technology groups, systems, or vulnerability classes and translate the model into target patch cadences and measurable SLAs.
  • Design a future-state enterprise patching framework that supports higher-frequency patching while protecting application availability, resiliency, security, and business operations.
  • Identify opportunities to automate patch assessment, testing, orchestration, deployment, validation, rollback, evidence collection, and compliance reporting.
  • Recommend improvements to patch tooling, CI/CD integration, infrastructure automation, vulnerability scanning, change processes, maintenance windows, and operational runbooks.
  • Define a pragmatic implementation roadmap, including priorities, sequencing, dependencies, quick wins, longer-term capabilities, and measurable success criteria.
  • Facilitate workshops and working sessions with infrastructure, platform, security, application, operations, and other technical teams to validate findings and drive alignment.
  • Present findings, design recommendations, risks, trade-offs, and implementation options to technical leads and stakeholders and build consensus around the future-state approach.
  • Produce clear, reusable documentation including current-state assessments, process flows, future-state designs, patch standards, SLA frameworks, operating procedures, runbooks, and implementation recommendations.

Required Qualifications

  • 5+ years of experience in infrastructure engineering, platform engineering, systems engineering, DevOps/SRE, security engineering, or a related enterprise technology discipline.
  • Demonstrated exposure to enterprise patch management and/or vulnerability management in complex, production environments.
  • Hands-on technical experience in at least two of the technology domains listed below.
  • Experience assessing current-state technical processes and converting findings into a clear, actionable future-state plan.
  • Experience developing or operating SLA-, severity-, criticality-, or risk-based patching/remediation frameworks.
  • Strong understanding of patch lifecycle activities, including discovery, prioritization, dependency analysis, testing, change control, deployment, validation, rollback, exception management, and reporting.
  • Ability to identify automation opportunities and design repeatable approaches that reduce manual effort and support increased patch frequency.
  • Strong analytical and problem-solving skills, with the ability to balance cybersecurity risk, operational risk, application resiliency, and business requirements.
  • Experience facilitating cross-functional technical workshops and driving agreement among teams with different platforms, priorities, and operating models.
  • Strong written and verbal communication skills, including the ability to communicate technical findings and recommendations clearly to engineering and technology leadership.
  • Excellent documentation skills, including process documentation, technical designs, standards, procedures, and runbooks.

Relevant Technical Experience

Candidates should have hands-on experience in at least two of the following areas:

  • Network & Operating Systems: Cisco; Windows; Linux; Ansible; enterprise OS and network-device patching
  • Database & Middleware: Oracle; Microsoft SQL Server; PostgreSQL; Apigee; database and middleware patching
  • Virtualization & VDI: VMware; Hyper-V; Citrix; VMware Horizon
  • CI/CD & Container Platforms: Jenkins; GitLab; Kubernetes; Kafka; container/platform lifecycle management
  • Storage: SAN/NAS technologies; NetApp; Dell storage platforms
  • Secrets, PKI & HSM: HashiCorp Vault; CyberArk; certificate lifecycle management; secrets management; HSM-related platforms
  • Application Security: Application security scanning and vulnerability identification/remediation workflows

Preferred / Highly Desirable Experience

  • Experience designing enterprise patching or vulnerability-remediation transformation programs spanning multiple infrastructure and platform teams.
  • Knowledge of vulnerability severity and prioritization concepts such as CVSS, exploitability, asset criticality, business impact, exposure, compensating controls, and remediation SLAs.
  • Experience with infrastructure-as-code, configuration management, scripting, or orchestration used to automate patching and platform maintenance.
  • Familiarity with DevSecOps practices and integrating vulnerability remediation into CI/CD pipelines and platform engineering workflows.
  • Experience in highly regulated, high-availability, or mission-critical environments where patching must be balanced against stringent resiliency and change-management requirements.
  • Understanding of governance, audit evidence, patch exceptions, risk acceptance, compliance reporting, and metrics/KPIs for patch and vulnerability management.
  • Experience developing executive or technical-lead presentations that summarize current-state findings, target-state architecture/processes, and transformation roadmaps.

Expected Deliverables

  • Current-state patching assessment by technology/system group.
  • Inventory of process gaps, bottlenecks, manual steps, risks, dependencies, and improvement opportunities.
  • Risk/criticality classification model and recommended target patch cadences/SLAs.
  • Future-state patching process and operating model, including automation opportunities and required controls.
  • Technology/tooling and integration recommendations where appropriate.
  • Prioritized implementation roadmap with sequencing, dependencies, and measurable outcomes.
  • Supporting process documentation, technical designs, standards, and runbooks.
  • Readout of findings and recommendations for technical leadership and cross-functional stakeholders.

Ideal Candidate Profile

The ideal candidate is a senior, hands-on infrastructure or platform engineer who has worked across multiple enterprise technology stacks and understands the realities of patching production systems. They can move beyond administering a single tool or platform to evaluate an end-to-end process, ask the right questions of specialized engineering teams, identify systemic constraints, and design a risk-based and automation-oriented approach that teams can realistically adopt.

Skills

Oracle
SQL
SQL Server
Ansible
Compliance
Jenkins
Kafka
Kubernetes
PKI
PostgreSQL
VMware
Vault

Similar jobs