Posted on: 23/07/2026
- Lead the enterprise endpoint Patch and Vulnerability Management program.
- Develop and maintain patch management policies, standards, and operational procedures.
- Define patch prioritization based on CVSS scores, exploitability, threat intelligence, business criticality, and risk.
- Manage OS and application patching across Windows, macOS, VMs, cloud platforms, firmware, and third-party software.
- Coordinate emergency patch deployments for zero-day vulnerabilities and critical/high security incidents.
- Integrate vulnerability scanning tools with patch management platforms to automate remediation workflows.
- Partner with Infrastructure, Cloud, Platform Engineering, and Application teams to reduce remediation timelines.
- Design and implement automated patch deployment pipelines using scripting and configuration management tools.
- Monitor patch compliance, remediation SLAs, and vulnerability trends via dashboards and executive reporting.
- Perform root cause analysis for patch failures and recommend preventive improvements.
- Support audits and regulatory compliance : ISO 27001, SOC 2, PCI DSS, HIPAA, NIST, Cyber Essentials Plus (Mandatory), and CIS Controls.
- Evaluate emerging technologies and recommend improvements to enterprise patch management capabilities.
- Mentor engineers and provide technical leadership across the organization.
Requirements :
Must-Haves :
- Bachelor's degree in Computer Science, Information Security, IT, or related field.
- 7-10 years of experience in Infrastructure, Systems Engineering, Cybersecurity, or Vulnerability Management.
- 5+ years leading enterprise patch management programs.
- Deep knowledge of Windows Client OS, Linux, VMware, cloud platforms (AWS, Azure, GCP), and enterprise endpoint management.
- Experience with at least one vulnerability management tool : Tenable, Qualys, Rapid7, InsightVM, or Microsoft Defender Vulnerability Management.
- Mandatory patch management tools : Microsoft Intune, JAMF, Automox.
- Strong PowerShell scripting (Mandatory); Python and Bash also required.
- Experience automating processes using Infrastructure as Code and configuration management tools.
- Solid understanding of CVSS, MITRE ATT&CK, and threat intelligence.
- Experience supporting large-scale enterprise environments with thousands of endpoints.
Nice-to-Haves :
- NinjaOne Patch Management, Kaseya VSA, ConnectWise Automate, Action1, SolarWinds Patch Manager.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1656953