Patch Engineering Lead

Nexus Technologies
Remote

About The Position

The Patch Engineering Lead is responsible for planning, coordinating, and executing patch management and vulnerability remediation across NexusTek's client and internal environments. This role ensures the timely and reliable deployment of operating system and third-party application patches across on-premises, cloud, and hybrid infrastructure, while maintaining compliance with regulatory frameworks such as HIPAA for clients handling Protected Health Information (PHI).

Requirements

  • At least 3–5 years of experience in IT operations, systems administration, or security operations, with a focus on patch and/or vulnerability management, ideally within an MSP or multi-client environment.
  • Hands-on experience administering patch/RMM platforms such as Automox, N-able N-central/N-sight, and Microsoft Intune/Endpoint Manager; familiarity with WSUS or SCCM is a plus.
  • Experience managing patching for cloud infrastructure in AWS (Systems Manager) and Azure (Update Manager, Azure Arc-enabled servers).
  • Familiarity with vulnerability scanning and management tools such as Tenable/Nessus, Qualys, or Rapid7 InsightVM.
  • Working knowledge of the HIPAA Security Rule and requirements for protecting electronic Protected Health Information (ePHI); experience supporting healthcare or other regulated clients preferred.
  • Familiarity with additional compliance frameworks (SOC 2, NIST CSF, CIS Controls) is a plus.
  • Scripting or automation experience (PowerShell, Bash, or Python) to support patch orchestration and reporting is a plus.
  • Experience working within a PSA/ticketing platform (e.g., ConnectWise, Autotask) and documentation systems (e.g., IT Glue).
  • Working knowledge of core networking concepts (TCP/IP, DNS, DHCP, VLANs, routing and switching, VPNs, and firewall rules) sufficient to understand how a device sits within, and depends on, the broader network.
  • Experience patching or upgrading firmware on network and infrastructure hardware (switches, routers, firewalls, wireless access points, or server/storage controllers), including recognizing how a single firmware issue can cascade into widespread connectivity or service outages.
  • At least one of the following (or comparable): CompTIA Security+, Microsoft Certified: Azure Administrator Associate, AWS Certified SysOps Administrator – Associate (or AWS Certified Solutions Architect – Associate), ITIL Foundation (preferred, not required)

Nice To Haves

  • Familiarity with WSUS or SCCM is a plus.
  • Experience supporting healthcare or other regulated clients preferred.
  • Familiarity with additional compliance frameworks (SOC 2, NIST CSF, CIS Controls) is a plus.
  • Scripting or automation experience (PowerShell, Bash, or Python) to support patch orchestration and reporting is a plus.
  • ITIL Foundation (preferred, not required)

Responsibilities

  • Own the end-to-end patch management lifecycle — assessment, testing, scheduling, deployment, verification, and reporting — across Windows, Linux, and macOS servers and endpoints.
  • Configure, maintain, and operate patch and endpoint management platforms including Automox, N-able (N-central/N-sight), and Microsoft Intune to deploy OS and third-party application patches across managed client environments.
  • Manage patch compliance for cloud-hosted workloads using AWS Systems Manager (Patch Manager) and Azure Update Manager, including patch baselines, maintenance windows, and compliance reporting.
  • Develop, document, and continuously improve patch management policies, standard operating procedures, and client-specific maintenance windows in alignment with contracted SLAs.
  • Triage and remediate vulnerabilities identified through vulnerability scanning and management tools, prioritizing remediation based on severity, exploitability, and business risk.
  • Ensure patch management practices for healthcare and other regulated clients align with HIPAA Security Rule requirements, including safeguarding electronic Protected Health Information (ePHI) and maintaining audit-ready patch and remediation documentation.
  • Coordinate emergency and out-of-band patching for critical vulnerabilities and actively exploited CVEs, balancing urgency with change management and client communication requirements.
  • Validate patches in test/pilot device groups prior to broad deployment to minimize service disruption and identify compatibility issues before production rollout.
  • Coordinate firmware update cycles for network and infrastructure devices (e.g., switches, routers, firewalls, wireless controllers), evaluating vendor release notes and change logs to assess the potential impact on network stability, routing, and connectivity prior to deployment.
  • Identify the scope of systems, sites, and dependent services that could be affected by a given firmware or infrastructure update, and plan staged or phased rollouts to contain the risk of a single update causing widespread outages across the network.
  • Monitor patch deployment success/failure rates, investigate and remediate failed or stalled patch deployments, and re-run or re-schedule as needed.
  • Maintain accurate, current documentation of patch cycles, exceptions, deferrals, and remediation timelines within the PSA/ticketing system and documentation platform.
  • Produce regular patch compliance and vulnerability remediation reports for internal stakeholders and client-facing account teams.
  • Support internal and client audits and compliance assessments (e.g., HIPAA, SOC 2) by providing patch management evidence, metrics, and process documentation.
  • Collaborate with the NOC, Service Desk, and Security teams to schedule patch deployment windows that minimize impact to client operations.
  • Stay current on emerging vulnerabilities, vendor patch releases (including Microsoft Patch Tuesday), and CVE disclosures relevant to supported environments.
  • Participate in change management processes for all patch and remediation deployments, ensuring appropriate approvals and rollback plans are in place.
  • Continually identify opportunities to improve patch automation, reduce manual effort, and reduce mean-time-to-remediate across the client base.

Benefits

  • Four weeks of annual accrued PTO
  • Seven paid national holidays
  • Medical, dental, vision options
  • Company-paid life insurance, short and long-term disability
  • Voluntary benefits such as critical illness and accident
  • Voluntary Legal Shield and identity theft protection
  • Discretionary annual 401k match plan
  • Generous employee referral bonus plan
  • Employee Assistance Program
  • Access to over 90,000+ courses in ADP My Learning
  • StandOut employee engagement tools
  • Eligible to apply for a Pluralsight license
  • Eligible to apply for NexusTek Technical Academy or Leadership Academy
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service