Principal Security Patch Management Engineer (Endpoint) (Bengaluru)

Principal Security Patch Management Engineer (Endpoint) (Bengaluru)

06 Aug
|
Aziro
|
Bengaluru

06 Aug

Aziro

Bengaluru

Position: Principal Security Patch Management Engineer (Endpoint)

Shift: 2:00 PM 10:00 PM IST

Experience: 710 years overall; 5+ years in Endpoint Vulnerability Management

Mandatory Skills

Endpoint Vulnerability Management

Endpoint Patch Management

Microsoft Intune

JAMF

Microsoft Defender

Automox (preferred)

PowerShell

Windows & Mac Endpoint Management

Positive-to-Have Skills

Python

Bash Scripting

Qualys

AWS

Cyber Essentials Audit Experience

Additional Acceptable Tools

Patch My PC

Other enterprise patch management tools

------------------------------------------------------------------------------------------------------

Job Summary

We are seeking an experienced Principal Security Patch Management Engineer to lead the enterprise Endpoint Vulnerability Remediation and Patch Management program.

The role is responsible for developing and executing patch management strategies, reducing organizational cyber risk, driving automation, and ensuring timely remediation of security vulnerabilities across endpoints, cloud infrastructure, and enterprise applications.

As a technical leader, you will collaborate with Security Operations, Infrastructure, Cloud Engineering, DevOps, Application Owners, and Compliance teams to establish governance, optimize patch deployment processes, and improve the organizations overall security posture.

Key Responsibilities

- Lead the enterprise Endpoint Patch and Vulnerability Management program.
- Develop and maintain patch management policies, standards, and operational procedures.
- Define patch prioritization based on CVSS scores,



exploitability, threat intelligence, business criticality, and risk.
- Manage operating system and application patching across Windows, macOS, virtual machines, cloud platforms, firmware, and third-party software.
- Coordinate emergency patch deployments for zero-day vulnerabilities and critical/high-severity security incidents.
- Integrate vulnerability scanning tools with patch management platforms to automate remediation workflows.
- Partner with Infrastructure, Cloud, Platform Engineering, and Application teams to reduce remediation timelines.
- Design and implement automated patch deployment pipelines using scripting and configuration management tools.
- Monitor patch compliance, remediation SLAs, and vulnerability trends through dashboards and executive reporting.
- Perform root cause analysis for patch failures and recommend preventive improvements.
- Support audits and regulatory compliance requirements including ISO 27001, SOC 2, PCI DSS, HIPAA, NIST, Cyber Essentials Plus (Mandatory), and CIS Controls.
- Evaluate emerging technologies and recommend improvements to enterprise patch management capabilities.




- Mentor engineers and provide technical leadership across the organization.

Required Qualifications

- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field.
- 710 years of experience in Infrastructure, Systems Engineering, Cybersecurity, or Vulnerability Management.
- 5+ years leading enterprise patch management programs.
- Deep knowledge of Windows Client OS, Linux, VMware, AWS, Azure, GCP, and enterprise endpoint management.
- Experience with vulnerability management tools such as Qualys, Rapid7, or Microsoft Defender Vulnerability Management (any one is acceptable).
- Experience with Microsoft Intune (Mandatory), JAMF (Mandatory), Automox (Mandatory), and NinjaOne Patch Management (Optional).
- Strong scripting skills in PowerShell (Mandatory), Python, and Bash.
- Experience automating operational processes using Infrastructure as Code and configuration management tools.
- Solid understanding of CVSS, MITRE ATT&CK;, and threat intelligence.
- Experience supporting large-scale enterprise environments with thousands of endpoints.

Technical Skills

Vulnerability Management, Patch Management, Microsoft Intune, JAMF, PowerShell, Python, Bash, Azure, Microsoft Defender, Qualys, Rapid7, Automation, Risk Management

Key Competencies

- Technical Leadership
- Strategic Planning
- Risk Assessment
- Problem Solving
- Cross-functional Collaboration
- Incident Response Support
- Process Improvement
- Communication and Executive Reporting
- Decision Making
- Mentoring and Coaching

📌 Principal Security Patch Management Engineer (Endpoint) (Bengaluru)
🏢 Aziro
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: principal security patch management engineer (endpoint) (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: principal security patch management engineer (endpoint) (bengaluru) / bengaluru