Patch Engineering Lead

NexusTek

Northern (KY)

Hybrid

USD 100,000 - 120,000

Full time

29 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Four weeks PTO annually
Company-paid life insurance & short/ln
Discretionary 401k match

Job summary

NexusTek is seeking an experienced Patch Engineering Lead to drive patch management and vulnerability remediation across on-prem, cloud, and hybrid environments. You will deploy OS and third-party patches using Automox, N-able, and Microsoft Intune, while ensuring HIPAA compliance and audit-ready records.

You will coordinate with NOC, Service Desk, and Security teams, prioritize remediation by risk, and guide policy improvements to reduce MTTR across clients.

Qualifications

  • At least 3–5 years in IT operations, systems administration, or security operations with patch/vulnerability focus.
  • Experience administering patch/RMM platforms ( Automox, N-able N-central/N-sight, Microsoft Intune ).
  • Familiarity with cloud patching (AWS Systems Manager, Azure Update Manager).

Responsibilities

  • Own end-to-end patch management lifecycle across Windows, Linux, macOS environments.
  • Configure and operate patch platforms to deploy OS and app patches.
  • Maintain HIPAA security alignment and audit-ready documentation.
  • Coordinate emergency/ out-of-band patching for critical CVEs.
  • Produce patch compliance and remediation reports for stakeholders.

Skills

Patch management
Automox
N-able N-central
Microsoft Intune
AWS Systems Manager
Azure Update Manager
Vulnerability management
HIPAA compliance
PowerShell
Bash
Python
ConnectWise/Autotask
TCP/IP, DNS, DHCP
Firmware updates

Education

IT operations or security operations experience

Tools

Tenable/Nessus
Qualys
Rapid7 InsightVM
WSUS/SCCM
IT Glue

Job description

Salary Range: $100,000.00 To $120,000.00 Annually

About the Role:

The Patch Engineering Lead is responsible for planning, coordinating, and executing patch management and vulnerability remediation across NexusTek's client and internal environments. This role ensures the timely and reliable deployment of operating system and third-party application patches across on-premises, cloud, and hybrid infrastructure, while maintaining compliance with regulatory frameworks such as HIPAA for clients handling Protected Health Information (PHI).

Location and Schedule:

Work from home, United States

Monday through Friday local business hours

You know how to:

  • Own the end-to-end patch management lifecycle — assessment, testing, scheduling, deployment, verification, and reporting — across Windows, Linux, and macOS servers and endpoints.
  • Configure, maintain, and operate patch and endpoint management platforms including Automox, N-able (N-central/N-sight), and Microsoft Intune to deploy OS and third-party application patches across managed client environments.
  • Manage patch compliance for cloud-hosted workloads using AWS Systems Manager (Patch Manager) and Azure Update Manager, including patch baselines, maintenance windows, and compliance reporting.
  • Develop, document, and continuously improve patch management policies, standard operating procedures, and client-specific maintenance windows in alignment with contracted SLAs.
  • Triage and remediate vulnerabilities identified through vulnerability scanning and management tools, prioritizing remediation based on severity, exploitability, and business risk.
  • Ensure patch management practices for healthcare and other regulated clients align with HIPAA Security Rule requirements, including safeguarding electronic Protected Health Information (ePHI) and maintaining audit-ready patch and remediation documentation.
  • Coordinate emergency and out-of-band patching for critical vulnerabilities and actively exploited CVEs, balancing urgency with change management and client communication requirements.
  • Validate patches in test/pilot device groups prior to broad deployment to minimize service disruption and identify compatibility issues before production rollout.
  • Coordinate firmware update cycles for network and infrastructure devices (e.g., switches, routers, firewalls, wireless controllers), evaluating vendor release notes and change logs to assess the potential impact on network stability, routing, and connectivity prior to deployment.
  • Identify the scope of systems, sites, and dependent services that could be affected by a given firmware or infrastructure update, and plan staged or phased rollouts to contain the risk of a single update causing widespread outages across the network.
  • Monitor patch deployment success/failure rates, investigate and remediate failed or stalled patch deployments, and re-run or re-schedule as needed.
  • Maintain accurate, current documentation of patch cycles, exceptions, deferrals, and remediation timelines within the PSA/ticketing system and documentation platform.
  • Produce regular patch compliance and vulnerability remediation reports for internal stakeholders and client-facing account teams.
  • Support internal and client audits and compliance assessments (e.g., HIPAA, SOC 2) by providing patch management evidence, metrics, and process documentation.
  • Collaborate with the NOC, Service Desk, and Security teams to schedule patch deployment windows that minimize impact to client operations.
  • Stay current on emerging vulnerabilities, vendor patch releases (including Microsoft Patch Tuesday), and CVE disclosures relevant to supported environments.
  • Participate in change management processes for all patch and remediation deployments, ensuring appropriate approvals and rollback plans are in place.
  • Continually identify opportunities to improve patch automation, reduce manual effort, and reduce mean-time-to-remediate across the client base.
  • At least 3–5 years of experience in IT operations, systems administration, or security operations, with a focus on patch and/or vulnerability management, ideally within an MSP or multi-client environment.
  • Hands-on experience administering patch/RMM platforms such as Automox, N-able N-central/N-sight, and Microsoft Intune/Endpoint Manager; familiarity with WSUS or SCCM is a plus.
  • Experience managing patching for cloud infrastructure in AWS (Systems Manager) and Azure (Update Manager, Azure Arc-enabled servers).
  • Familiarity with vulnerability scanning and management tools such as Tenable/Nessus, Qualys, or Rapid7 InsightVM.
  • Working knowledge of the HIPAA Security Rule and requirements for protecting electronic Protected Health Information (ePHI); experience supporting healthcare or other regulated clients preferred.
  • Familiarity with additional compliance frameworks (SOC 2, NIST CSF, CIS Controls) is a plus.
  • Scripting or automation experience (PowerShell, Bash, or Python) to support patch orchestration and reporting is a plus.
  • Experience working within a PSA/ticketing platform (e.g., ConnectWise, Autotask) and documentation systems (e.g., IT Glue).
  • Working knowledge of core networking concepts (TCP/IP, DNS, DHCP, VLANs, routing and switching, VPNs, and firewall rules) sufficient to understand how a device sits within, and depends on, the broader network.
  • Experience patching or upgrading firmware on network and infrastructure hardware (switches, routers, firewalls, wireless access points, or server/storage controllers), including recognizing how a single firmware issue can cascade into widespread connectivity or service outages.

Licencses/Certifications: At least one of the following (or comparable):

  • CompTIA Security+
  • AWS Certified SysOps Administrator – Associate (or AWS Certified Solutions Architect – Associate)
  • ITIL Foundation (preferred, not required)

Pay and Benefits:

Estimated Starting Salary/Wage Range: $100,000 – $120,000 annual, based on candidate's experience, qualifications, and location.

In addition to legally-required benefits, NexusTek offers a benefit package to eligible full-time employees, which currently includes the following:

  • Four weeks of annual accrued PTO
  • Seven paid national holidays
  • Company-paid life insurance, short and long-term disability
  • Voluntary benefits such as critical illness and accident
  • Voluntary Legal Shield and identity theft protection
  • Discretionary annual 401k match plan
  • Employee Assistance Program
  • Access to over 90,000+ courses in ADP My Learning
  • StandOut employee engagement tools
  • Eligible to apply for a Pluralsight license
  • Eligible to apply for NexusTek Technical Academy or Leadership Academy

We’re happy to provide our comprehensive benefits guide. Each benefit is subject to eligibility requirements as specified in plan documents, and the Company reserves the right to modify the benefits it offers from time to time.

Interview Process

Application and Screening Stage

  • Our recruiters carefully consider each application. If you are selected to move forward, we will contact you for the 20 minute introductory screening to learn more about you and why you want to work for NexusTek.

Interview Stage

  • One-hour technical interview with hiring manager (virtual)
  • One-hour interview with VP-level team member (virtual)
  • References – 3 professional references at least one direct supervisor
  • You are welcome to request additional conversations with team members you didn’t get to meet during the process

N e x (I t) s h y k e P r e v i u etc

NexusTek provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws

NexusTek participates in E-Verify for all US Employees

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Systems Administrator
Systems Administrator

NexusTek • Westminster (CO)

On-site
USD 68,000 - 92,000
PTO accrual
Holiday pay
Medical insurance
+8
Support Technician III
Support Technician III

Nexus Technologies LLC • Monroe (CT)

On-site
USD 36,000 - 52,000
Four weeks PTO
Seven holidays
Life insurance
+3
Solutions Engineer
Solutions Engineer

Talentify • Las Vegas (NV)

Remote
USD 115,000 - 135,000
Four weeks PTO
Medical, dental, vision
Company-paid life insurance
+3
Support Technician (Sun-Thurs 2pm - 11pm EST)
Support Technician (Sun-Thurs 2pm - 11pm EST)

Nexus Technologies • United States

Remote
USD 34,000 - 37,000
PTO 4 weeks
7 holidays
Medical/dental/vision
+5
IT Knowledge Specialist
IT Knowledge Specialist

NexusTek • United States

Remote
USD 51,000 - 69,000
PTO
Holidays
Life insurance
+7
Sr Account Executive (New Business)
Sr Account Executive (New Business)

NexusTek • Northern (KY)

Hybrid
USD 160,000 - 220,000
Benefits package
Remote Patch Engineering Lead (Security & Compliance)
Remote Patch Engineering Lead (Security & Compliance)

NexusTek • Northern (KY)

Hybrid
USD 100,000 - 120,000
Four weeks PTO annually
Company-paid life insurance & short/ln
Discretionary 401k match
Senior Network Security Engineer
Senior Network Security Engineer

Cynet Systems Inc. • Tallahassee (FL)

On-site
USD 107,000 - 114,000
Medical, Dental, and Vision Insurance
401(k) Retirement Plan
Health Savings Account (HSA)
+3
Job Posting Title Information Systems Security Engineer (ISSE)
Job Posting Title Information Systems Security Engineer (ISSE)

TekSynap Corporation • Arlington (VA)

On-site
USD 130,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
System Engineer
System Engineer

Talentify • Tampa (FL)

On-site
USD 90,000 - 120,000
Medical, Dental, Vision
401(k) with company match
Life Insurance
+6