Patch Management Engineer
Bangalore,
India
Bangalore,
India
Job Summary
We are seeking a skilled Patch Management Engineer to manage, automate, and optimize the patching lifecycle across servers, endpoints, and applications. The role focuses on security compliance, vulnerability remediation, risk reduction, and ensuring systems remain up to date with minimal business disruption.
Key Responsibilities
Patch & Vulnerability Management
- Plan, schedule, and deploy OS and application patches across Windows and Linux environments
- Manage patching for servers, endpoints, and virtual infrastructure
- Coordinate patching cycles (monthly, emergency, zero-day vulnerabilities)
- Analyze vulnerability scan results and prioritize remediation
Tools & Platforms
- Administer patching tools such as Ivanti EPM, Ivanti ISec, Qualys, WSUS
- Maintain patch repositories, baselines, and approval workflows
- Ensure accurate asset coverage and patch compliance reporting
Security & Compliance
- Ensure compliance with security standards (Saudi NCA regulations, ISO 27000, 27001, JCI, CBAHI, CIS, NIST, internal policies)
- Support audits by providing patch and vulnerability compliance reports
- Collaborate with Security teams to remediate critical and high-risk CVEs
Testing & Change Management
- Test patches in dev/test environments prior to production deployment
- Participate in Change Management (CAB) processes
- Plan rollback and contingency procedures
Automation & Reporting
- Develop automation scripts using PowerShell, Bash, or Python
- Create dashboards and reports on patch compliance, risk, and trends
- Continuously improve patch deployment efficiency and success rates
Incident & Operations Support
- Respond to patch-related incidents and failed deployments
- Troubleshoot patch conflicts, performance issues, and system failures
- Provide Level 2/3 support during patch windows
Required Skills & Qualifications
Technical Skills
- 5+ years of experience in Patch and Vulnerability Management
- Strong knowledge of Windows Server, Windows Client, and Linux patching
- Hands-on experience with SCCM/MECM, WSUS, or Intune
- Understanding of CVEs, vulnerability scoring (CVSS)
- Strong scripting skills (PowerShell preferred)
Preferred Skills
- Experience with cloud environments (Alibaba, OCI, Azure, AWS)
- Knowledge of endpoint security and hardening
- Familiarity with EDR and vulnerability scanning tools
- Experience in enterprise or regulated environments
Certifications (Preferred)
- Microsoft Certified: Endpoint / Windows Administration
- Security certifications (Security+, CEH, CISSP – plus)
- ITIL Foundation
Soft Skills
- Strong attention to detail and risk awareness
- Excellent coordination and communication skills
- Ability to work under tight timelines and pressure
- Strong documentation and reporting abilities
Work Environment
- Enterprise infrastructure with regular maintenance windows
- On-call or after-hours work during critical patch cycles