The position is responsible for operational support and management for operating system patching activities covering the global user workstation landscape.
This position will require deep analytical thinking with the ability to combine security related information from multiple data sources and using that data to determine deployment methods and timelines for software patches, registry updates, and other security related configurations. The Engineer will work with business units to plan and coordinate the patching activities with a focus on minimizing business impact during the event and ensuring systems are returned to optimal state after patching activities have been completed.
In addition to patch management functions the team will also be responsible for the entire system lifecycle related to compliance which will include hardening for system builds, ongoing CIS standards, and compliance related configuration management.
This position will require working during business offer hours and weekends in order to minimize impact during the patching events.
- Develop and optimize pre- and post- patching process to ensure proper implementation without any outages.
- Evaluate patches based on risks and prioritize fixes in order to meet pre-determined deployment timelines for the patch risk level.
- Coordinate patch schedule with business units and other internal teams such as infrastructure management, security operations, governance & risk.
- Have the ability to create deployment patch packages using tools such as ManageEngine Patch Manager Plus, SCCM, WSUS, SolarWinds Patch Manager.
- Ensure patches are deployed and tested in pilot groups prior to full deployment to all user systems.
- Able to remediate vulnerabilities. Often, requiring fixes beyond system patches, which could include items like changing registry values, firewall changes, and other configuration items.
- Assist in the process for vulnerability and patch management ensuring they are compatible with the company's business needs and strategic objectives.
- Research, evaluate, develop, design and implement patch remediation standards following industry best practices
- Develop and implement patch and vulnerability remediation process including package creation, testing and deployment
Patching Administrators leveled up to Security Engineers focused on Vulnerability Management and Remediation.
A blend of Windows and Unix system engineering, patch deployment, vulnerability remediation, data analytics, and automation.
- Comptia Security Plus (Easy we study as a group)
- Excel Data Analysis
- Vulnerability Assessment & Remediation using Tenable SC and IO
- Enterprise Patching with Manage Engine EndPointCentral
Products we use
- Manage Engine End Point Central (Patching)
- Tenable sc & io (Vulnerabilities)
- Excel (DataAnalysis)
- Power BI (Reporting)
- Powershell\Python\Ansible\PowerAutomate (Automation)