Title - Senior Patch Management Engineer
Location - Cary, NC / Jacksonville, FL - (hybrid -3 days onsite a week)
ROLE SUMMARY
The L2 Senior Patch Management Engineer owns the end-to-end patch lifecycle for the end-user computing environment. Responsibilities include designing and maintaining patching baselines, automating patch workflows, resolving complex deployment failures, and acting as an escalation point for L1 analysts. The role also involves continuous improvement of patch tooling and processes.
KEY RESPONSIBILITIES
- Own the patch management lifecycle: assessment, testing, approval, deployment, validation, and reporting for all EUC endpoints.
- Design and maintain software update groups, collections, and deployment rules in SCCM/MECM and Microsoft Intune.
- Develop and maintain PowerShell / WMI scripts to automate patch compliance checks, remediation, and reporting.
- Act as L2 escalation for patch deployment failures, application compatibility issues, and non-compliant device investigations.
- Conduct patch testing in pilot/UAT rings before production rollout; document test results and obtain change approval.
- Integrate Qualys / Tenable vulnerability scan data to drive patch prioritisation based on CVSS scores.
- Define and enforce patching SLAs for Critical, High, Medium, and Low severity patches per security policy.
- Maintain and improve the patch management runbook, SOPs, and exception handling process.
- Collaborate with security operations (SOC) to address zero-day threats and emergency patch deployments.
- Produce monthly patch compliance reports and trend analysis for management review.
- Mentor and guide L1 analysts; review their tickets and provide technical feedback.
TECHNICAL SKILLS & KNOWLEDGE
- Deep expertise in SCCM/MECM – software update point, ADRs, deployment rings, client health.
- Hands-on experience with Microsoft Intune / Autopilot / Windows Update for Business.
- Advanced PowerShell scripting for automation (compliance remediation, report extraction, deployment triggers).
- Experience with vulnerability management tools: Qualys, Tenable Nessus, or Rapid7 InsightVM.
- Knowledge of Windows OS lifecycle, patch Tuesday cycle, CBS, WUA, and WinSxS.
- Familiarity with macOS patch management (Jamf Pro / Munki) is an advantage.
- Understanding of BitLocker, Windows Defender, and endpoint security baselines (CIS / STIG).
- Experience integrating patch workflows with ServiceNow ITSM and CMDB.
- Working knowledge of Azure AD, Entra ID, and Conditional Access policies.
SOFT SKILLS & COMPETENCIES
- Strong analytical and troubleshooting skills for complex patch failures.
- Excellent documentation skills – able to produce clear SOPs, RCAs, and change records.
- Effective communicator across technical and non-technical stakeholders.
- Proactive mindset – identifies process gaps and proposes improvements.
- Ability to manage concurrent workstreams under deadline pressure.
PREFERRED CERTIFICATIONS
- CompTIA Security+ or CySA+
- ITIL 4 Managing Professional (or Foundation)
- Qualys Certified Specialist – Vulnerability Management
Compensation and Benefits
A candidate’s pay within the range will depend on their skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies.
- medical
- dental
- vision
- pharmacy
- life
- accidental death & dismemberment
- disability insurance
- employee assistance program
- 401(k) retirement plan
- 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year)
- 10 paid holidays per year
Disclaimer
HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to secure@hcltech.com for investigation.