Senior Network Engineer

HCLTech

Town of Florida (NY)

On-site

USD 120,000 - 170,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HCLTech in Cary, NC or Jacksonville, FL is seeking a Senior Network Patch Management Engineer. You will own the firmware and software lifecycle across a multi-vendor estate, coordinating risk-based upgrades and automated workflows to minimize disruption.

Responsibilities include CVE mapping, runbook development, and cross-team collaboration with NOC, security, and ITSM. Strong scripting and vendor tool experience are essential for success.

Qualifications

  • Experience managing multi-vendor network patching lifecycles.
  • Ability to map CVEs to upgrades based on CVSS and business impact.
  • Develop and maintain patch runbooks with pre-checks, upgrades, rollback plans.
  • Automate patch workflows using scripting and vendor APIs.

Responsibilities

  • Own firmware/software lifecycle across multi-vendor estates.
  • Assess advisories and map CVEs to upgrades with CVSS priority.
  • Develop patch runbooks with pre-checks, upgrade steps, rollback plans.
  • Automate patch workflows using Ansible, Netmiko, NAPALM, or vendor APIs.
  • Lead maintenance window planning and CAB submissions.
  • Ensure backup integrity before patches (RANCID/Oxidised/Cisco NSO).
  • Coordinate with NOC, security, and ITSM teams for patches.
  • Report patch compliance to management and security teams.
  • Drive SLA adherence: critical within 72 hours, high within 14 days.

Job description

Job Role: Senior Network Patch Management Engineer
Location: Cary NC or Jacksonville FL (Onsite)
ROLE SUMMARY

The L2 Senior Network Patch Management Engineer owns the firmware and software lifecycle across a multi-vendor network estate (LAN, WAN, data centre fabrics, firewalls, load balancers, and wireless). Responsibilities include risk assessment, automated patching workflows, vulnerability-led prioritization, and cross-team co-ordination for zero-disruption maintenance. The role serves as an escalation point for L1 and leads continuous improvement of network patching practices.

KEY RESPONSIBILITIES
  • Manage the firmware / software lifecycle for routers, switches, firewalls, load balancers, and wireless controllers across multi-vendor environments (Cisco, Juniper, Aruba, Palo Alto, F5, Fortinet).
  • Assess vendor advisories (Cisco PSIRT, Juniper JSA, Palo Alto Security Advisories) and map CVEs to required upgrades; priorities based on business impact and CVSS score.
  • Develop and maintain device-specific patching runbooks including pre-check scripts, upgrade procedures, rollback steps, and post-validation checks.
  • Automate network patch workflows using Ansible, Netmiko, NAPALM, or vendor APIs (Cisco NSO / DNA Centre).
  • Lead maintenance window planning: impact analysis, rollback testing, stakeholder communication, and CAB submission.
  • Oversee configuration backup integrity (RANCID / Oxidised / Cisco NSO) before every patching activity.
  • Conduct structured rollback for failed upgrades; perform root cause analysis and document findings.
  • Integrate network vulnerability data from Qualys / Tenable into the patch prioritisation workflow.
  • Monitor network stability post-patching using NMS/IPAM tools (SolarWinds, NetBrain, Infoblox).
  • Act as L2 escalation for L1 patch-related issues and routing/connectivity incidents.
  • Produce patch compliance reports and present to network management and security teams.
  • Drive patching SLA adherence: Critical vulnerabilities within 72 hours, High within 14 days.
TECHNICAL SKILLS & KNOWLEDGE
  • Deep understanding of network protocols: OSPF, BGP, EIGRP, MPLS, VRF, STP, HSRP/VRRP.
  • Experience with automated patching toolchains: Ansible, Netmiko, NAPALM, Python (Paramiko).
  • Vendor firmware lifecycle knowledge including feature releases, maintenance releases, and ED/MD trains (Cisco SMU, Juniper package management).
  • Firewall firmware management: Palo Alto, Fortinet FortiOS, Cisco ASA/FTD upgrade procedures.
  • Load balancer firmware: F5 BIG-IP or Citrix ADC upgrade methodology.
  • Network management platforms: Cisco DNA Centre, SolarWinds NPM/NCM, NetBrain, Infoblox.
  • Vulnerability management: parsing Cisco PSIRT, Juniper JSA, and NVD CVE data.
  • ITSM integration: ServiceNow change management, CMDB for network asset tracking.
  • SD-WAN patching exposure (Cisco Viptela, VMware VeloCloud) is advantageous.
SOFT SKILLS & COMPETENCIES
  • Strong risk assessment skills: balances urgency with network stability.
  • Excellent planning skills for complex, multi-device maintenance windows.
  • Clear communicator with NOC, application, and security teams.
  • Methodical documentation – detailed runbooks, RCAs, and change records.
  • Proactive – stays current with vendor EOL/EOS notices and security advisories.
PREFERRED CERTIFICATIONS
  • Cisco Certified Network Professional (CCNP Enterprise or Security)
  • Juniper Networks Certified Professional (JNCIP-ENT or JNCIP-SEC)
  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • CompTIA Security+ or CySA+
  • ITIL 4 Foundation or Managing Professional
Disclaimer

HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to secure@hcltech.com for investigation.

Compensation and Benefits

A candidate’s pay within the range will depend on their work location, skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Infrastructure Engineer
Network Infrastructure Engineer

HCLTech • Cary (NC)

On-site
USD 120,000 - 150,000
Analyst
Analyst

HCLTech • North Carolina

On-site
USD 65,000 - 90,000
Medical benefits
Paid time off
10 holidays per year
Senior Network Engineer
Senior Network Engineer

HCLTech • Downers Grove (IL)

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Patch Management Engineer
Senior Patch Management Engineer

HCLTech • Cary (NC)

Hybrid
USD 110,000 - 150,000
Medical
Dental
Vision
+8
Senior Patch Management Engineer/ Data Center Infrastructure /L2 – Mid-Level
Senior Patch Management Engineer/ Data Center Infrastructure /L2 – Mid-Level

HCLTech • Cary (NC)

Hybrid
USD 90,000 - 130,000
Medical, Dental, Vision
Retirement plan (401(k)
Paid time off
+1
L1 Patch Management Analyst
L1 Patch Management Analyst

HCLTech • Cary (NC)

Hybrid
USD 65,000 - 90,000
Network Engineer
Network Engineer

HCLTech • Cary (NC)

On-site
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+5
Patch Management Analyst / Data Center Infrastructure / L1 – Junior
Patch Management Analyst / Data Center Infrastructure / L1 – Junior

HCLTech • Cary (NC)

Hybrid
USD 65,000 - 85,000
Medical insurance
Dental insurance
Vision insurance
+6
Network Development Specialist
Network Development Specialist

HCLTech • Jacksonville (FL)

Hybrid
USD 120,000 - 180,000
Senior Network Patch Automation Engineer
Senior Network Patch Automation Engineer

HCLTech • Cary (NC)

On-site
USD 120,000 - 150,000