Patch Engineer – Endpoint Vulnerability Analysis & Remediation
Location: India Remote
Shift: 5:00 PM – 2:00 AM IST, Monday–Friday
Position Summary
We are seeking a highly skilled Patch Engineer to join our Enterprise Patch Management and Vulnerability Remediation team. This role is primarily focused on Windows endpoint patching and vulnerability remediation, including operating system, third-party, and open-source application patching.
The ideal candidate will have strong hands-on experience in vulnerability analysis, endpoint patch deployment, application packaging, and remediation validation. The role involves identifying vulnerabilities, determining appropriate remediation strategies, testing patches and application updates, deploying solutions through enterprise endpoint management platforms, and validating successful remediation.
Top 3 Technical Skills
- Vulnerability analysis and remediation
- Patch deployment using BigFix or MEMCM
- Application packaging
Primary Vulnerability Management Tool: Qualys
Key Responsibilities
- Analyze Qualys vulnerability reports and SCA findings to identify vulnerable open-source libraries, third-party applications, and software components across enterprise endpoints.
- Investigate vulnerabilities by validating affected software, installed versions, installation paths, dependencies, and potential business impact.
- Develop and recommend remediation plans that address vulnerabilities while minimizing operational risk and business disruption.
- Research vendor security advisories, release notes, CVEs, and remediation guidance to determine appropriate software versions and security updates.
- Perform Windows workstation and server operating system patching and support enterprise-wide vulnerability remediation initiatives.
- Deploy patches, application updates, and remediation solutions using BigFix, MEMCM/SCCM, or similar endpoint management platforms.
- Test patches, software updates, and application versions in lower environments before production deployment to ensure functionality, compatibility, and security.
- Validate remediation through follow-up vulnerability scans, patch compliance reports, and endpoint validation.
- Package and deploy third-party applications and updates where required.
- Coordinate with software vendors to open support cases, validate fixes, obtain technical guidance, and resolve product-specific security issues.
- Document remediation activities, testing results, deployment procedures, known issues, and recommendations.
- Partner with Information Security, Vulnerability Management, Application Support, Desktop Engineering/Packaging, and Infrastructure teams to meet remediation SLAs.
- Monitor emerging vulnerabilities, vendor advisories, CVEs, and software lifecycle changes that may impact enterprise applications.
- Participate in urgent security patch deployments and remediation activities for critical and zero-day vulnerabilities.
- Use Microsoft Excel extensively for large datasets, vulnerability tracking, reconciliation, analysis, and management reporting.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent professional experience.
- 7+ years of experience in enterprise patch management, endpoint engineering, application packaging, or vulnerability remediation.
- Strong knowledge of Windows workstation and server operating systems.
- Strong hands-on experience with at least one enterprise endpoint management platform, particularly BigFix or MEMCM/SCCM.
- Experience using endpoint management tools to deploy patches and remediate vulnerabilities.
- Experience analyzing vulnerability reports from Qualys, SCA tools, or similar vulnerability management platforms.
- Strong understanding of CVEs, third-party application vulnerabilities, open-source software components, and software dependencies.
- Experience with application packaging technologies such as MSI, MSIX, InstallShield, AdminStudio, or similar packaging technologies.
- Experience deploying applications through BigFix, Microsoft Intune, MECM/Configuration Manager, or comparable enterprise software distribution platforms.
- Strong troubleshooting and root-cause analysis skills, including the ability to identify affected software, versions, installation locations, and dependencies.
- Experience working with software vendors to troubleshoot vulnerabilities and validate remediation options.
- Strong Microsoft Excel skills, including formulas, data analysis, reconciliation, and reporting across large datasets.
- Excellent documentation, communication, and cross-functional collaboration skills.
Preferred Qualifications
- Experience packaging and deploying third-party application updates through BigFix or MEMCM while following enterprise change-management processes.
- Experience with vulnerability management platforms such as Qualys, Tenable, Rapid7, or Microsoft Defender Vulnerability Management.
- PowerShell or Python scripting experience for automation, application packaging, patching, or remediation.
- Experience supporting regulatory compliance requirements and vulnerability remediation SLAs.
- Ability to build strong partnerships with security teams, software vendors, application owners, and infrastructure teams.
- Experience handling critical and zero-day vulnerability remediation within aggressive SLA timelines.