Enterprise Patch Management Engineer
Quick Overview
Job Description
Enterprise Patch Management Engineer
Location: Remote, US
Client - OCC Through NESS
Enterprise Patch Management Engineer
Infrastructure / Platform Engineering | Vulnerability & Patch Management
Role Type | Engineering / Advisory | Experience | 5+ years |
Primary Focus | Enterprise patching transformation | Openings | 3 anticipated |
Environment | Cross-platform enterprise infrastructure | Key Outcome | Risk-based, higher-frequency patching |
Position Summary
We are seeking an experienced Enterprise Patch Management Engineer to assess current patching processes across a broad technology environment and design a practical future-state approach that enables faster, more frequent, automated, and lower-risk patching. The engineer will work across infrastructure, platform, security, and application technology teams to document current practices, identify constraints, establish risk- and criticality-based patch cadences and service levels, and define an actionable roadmap for improvement.
This is not a narrowly focused patch-operations role. The successful candidate must be able to combine hands-on technical knowledge with process assessment, architecture/design thinking, automation, vulnerability management, stakeholder facilitation, and strong documentation.
Key Responsibilities
- Assess and document the current-state patching process for each major system and technology group, including ownership, tooling, dependencies, approvals, testing, deployment, rollback, exception handling, reporting, and governance.
- Evaluate patching practices across networking, operating systems, databases and middleware, virtualization and VDI, CI/CD and container platforms, storage, secrets/PKI/HSM platforms, and application security scanning.
- Identify gaps, bottlenecks, manual activities, technical dependencies, control requirements, and operational constraints that limit patch frequency or increase deployment risk.
- Analyze how vulnerabilities are identified, prioritized, remediated, validated, tracked, and reported across the enterprise.
- Develop a criticality and risk-scoring approach for technology groups, systems, or vulnerability classes and translate the model into target patch cadences and measurable SLAs.
- Design a future-state enterprise patching framework that supports higher-frequency patching while protecting application availability, resiliency, security, and business operations.
- Identify opportunities to automate patch assessment, testing, orchestration, deployment, validation, rollback, evidence collection, and compliance reporting.
- Recommend improvements to patch tooling, CI/CD integration, infrastructure automation, vulnerability scanning, change processes, maintenance windows, and operational runbooks.
- Define a pragmatic implementation roadmap, including priorities, sequencing, dependencies, quick wins, longer-term capabilities, and measurable success criteria.
- Facilitate workshops and working sessions with infrastructure, platform, security, application, operations, and other technical teams to validate findings and drive alignment.
- Present findings, design recommendations, risks, trade-offs, and implementation options to technical leads and stakeholders and build consensus around the future-state approach.
- Produce clear, reusable documentation including current-state assessments, process flows, future-state designs, patch standards, SLA frameworks, operating procedures, runbooks, and implementation recommendations.
Required Qualifications
- 5+ years of experience in infrastructure engineering, platform engineering, systems engineering, DevOps/SRE, security engineering, or a related enterprise technology discipline.
- Demonstrated exposure to enterprise patch management and/or vulnerability management in complex, production environments.
- Hands-on technical experience in at least two of the technology domains listed below.
- Experience assessing current-state technical processes and converting findings into a clear, actionable future-state plan.
- Experience developing or operating SLA-, severity-, criticality-, or risk-based patching/remediation frameworks.
- Strong understanding of patch lifecycle activities, including discovery, prioritization, dependency analysis, testing, change control, deployment, validation, rollback, exception management, and reporting.
- Ability to identify automation opportunities and design repeatable approaches that reduce manual effort and support increased patch frequency.
- Strong analytical and problem-solving skills, with the ability to balance cybersecurity risk, operational risk, application resiliency, and business requirements.
- Experience facilitating cross-functional technical workshops and driving agreement among teams with different platforms, priorities, and operating models.
- Strong written and verbal communication skills, including the ability to communicate technical findings and recommendations clearly to engineering and technology leadership.
- Excellent documentation skills, including process documentation, technical designs, standards, procedures, and runbooks.
Relevant Technical Experience
Candidates should have hands-on experience in at least two of the following areas:
- Network & Operating Systems: Cisco; Windows; Linux; Ansible; enterprise OS and network-device patching
- Database & Middleware: Oracle; Microsoft SQL Server; PostgreSQL; Apigee; database and middleware patching
- Virtualization & VDI: VMware; Hyper-V; Citrix; VMware Horizon
- CI/CD & Container Platforms: Jenkins; GitLab; Kubernetes; Kafka; container/platform lifecycle management
- Storage: SAN/NAS technologies; NetApp; Dell storage platforms
- Secrets, PKI & HSM: HashiCorp Vault; CyberArk; certificate lifecycle management; secrets management; HSM-related platforms
- Application Security: Application security scanning and vulnerability identification/remediation workflows
Preferred / Highly Desirable Experience
- Experience designing enterprise patching or vulnerability-remediation transformation programs spanning multiple infrastructure and platform teams.
- Knowledge of vulnerability severity and prioritization concepts such as CVSS, exploitability, asset criticality, business impact, exposure, compensating controls, and remediation SLAs.
- Experience with infrastructure-as-code, configuration management, scripting, or orchestration used to automate patching and platform maintenance.
- Familiarity with DevSecOps practices and integrating vulnerability remediation into CI/CD pipelines and platform engineering workflows.
- Experience in highly regulated, high-availability, or mission-critical environments where patching must be balanced against stringent resiliency and change-management requirements.
- Understanding of governance, audit evidence, patch exceptions, risk acceptance, compliance reporting, and metrics/KPIs for patch and vulnerability management.
- Experience developing executive or technical-lead presentations that summarize current-state findings, target-state architecture/processes, and transformation roadmaps.
Expected Deliverables
- Current-state patching assessment by technology/system group.
- Inventory of process gaps, bottlenecks, manual steps, risks, dependencies, and improvement opportunities.
- Risk/criticality classification model and recommended target patch cadences/SLAs.
- Future-state patching process and operating model, including automation opportunities and required controls.
- Technology/tooling and integration recommendations where appropriate.
- Prioritized implementation roadmap with sequencing, dependencies, and measurable outcomes.
- Supporting process documentation, technical designs, standards, and runbooks.
- Readout of findings and recommendations for technical leadership and cross-functional stakeholders.
Ideal Candidate Profile
The ideal candidate is a senior, hands-on infrastructure or platform engineer who has worked across multiple enterprise technology stacks and understands the realities of patching production systems. They can move beyond administering a single tool or platform to evaluate an end-to-end process, ask the right questions of specialized engineering teams, identify systemic constraints, and design a risk-based and automation-oriented approach that teams can realistically adopt.
Skills
Similar jobs
Genesys Cloud CX Specialist – Healthcare
AH Infotech · Princeton, United States
1 minute agoQA Test Enginner
TriosysIT Inc. · Dallas, United States
1 minute agoSr. AEM Lead MALVERN - PA - Pennsylvania
Sierra Business Solution LLC · Malvern, United States
2 minutes agoSecurity NLP Architect
I-Link Solutions · United States
2 minutes agoProduct Management - W2 - Onsite Phoenix, AZ
Incorporan Inc · Phoenix, United States
3 minutes agoSecurity Vetting Analyst with Security Clearance
Anduril Industries · Costa Mesa, United States
3 minutes ago$99k - $130k/yr