Vulnerability remediation (Patch Management) Engineer
- Location
- New York, NY
- Work type
- Full Time · On-site
- Posted
- 2026-09-03
Job description
Key Responsibilities
Patch Deployment & Management
Plan, schedule, and deploy security patches and updates across Windows and Linux systems.
Use SCCM and Tanium for patch deployment, automation, and reporting.
Ensure timely patching aligned with organizational security SLAs and compliance requirements.
Vulnerability Assessment & Remediation
Analyze vulnerability scan outputs and translate them into actionable patching activities.
Validate findings to eliminate false positives and confirm true risk exposure.
Provide technical guidance on remediation steps including patching, configuration changes, and compensating controls.
Prioritize remediation based on severity, exploitability, and business impact.
Validate patch implementation and ensure vulnerabilities are effectively remediated.
Troubleshooting & Issue Resolution
Diagnose and resolve patch deployment issues and failures across environments.
Perform root cause analysis and fix compatibility or system-related issues.
Coordinate with application and infrastructure teams for issue resolution.
Scripting & Automation
Develop and use PowerShell and Shell scripts to automate patch deployment, validation, and reporting.
Improve patching efficiency through automation and process optimization.
Monitoring, Compliance & Reporting
Track patch compliance and generate reports for security and audit teams.
Ensure systems meet organizational security and regulatory standards.
Support audit remediation and security assessments.
Collaboration & Documentation
Work closely with security, infrastructure, and operations teams for coordinated patching activities.
Maintain SOPs, patch schedules, and documentation.
Participate in change management processes and maintenance windows.
Required Skills & Qualifications
8 10 years of strong hands-on experience in patch management and vulnerability remediation.
Drive end-to-end vulnerability remediation, from analysis of findings to closure validation.
Strong hands-on experience with SCCM and Tanium.
Good knowledge of Windows and Linux system administration.
Experience deploying, troubleshooting, and validating patches across environments.
Work closely with infrastructure, application, cloud, and network teams to remediate vulnerabilities across servers, endpoints, databases, and network devices.
Strong scripting skills (PowerShell, Shell scripting).
Familiarity with ITIL-based change and incident management.
Strong analytical, troubleshooting, and communication skills.
Preferred Skills / Certifications
Certifications such as CompTIA Security+, CEH, or equivalent.
Experience with vulnerability tools (Qualys, Tenable, Rapid7).
Exposure to automation frameworks or DevOps practices is an advantage.