06 Aug
|
Aziro
|
Bengaluru
Position: Principal Security Patch Management Engineer (Endpoint)
Shift: 2:00 PM 10:00 PM IST
Experience: 710 years overall; 5+ years in Endpoint Vulnerability Management
Mandatory Skills
Endpoint Vulnerability Management
Endpoint Patch Management
Microsoft Intune
JAMF
Microsoft Defender
Automox (preferred)
PowerShell
Windows & Mac Endpoint Management
Positive-to-Have Skills
Python
Bash Scripting
Qualys
AWS
Cyber Essentials Audit Experience
Additional Acceptable Tools
Patch My PC
Other enterprise patch management tools
------------------------------------------------------------------------------------------------------
Job Summary
We are seeking an experienced Principal Security Patch Management Engineer to lead the enterprise Endpoint Vulnerability Remediation and Patch Management program.
The role is responsible for developing and executing patch management strategies, reducing organizational cyber risk, driving automation, and ensuring timely remediation of security vulnerabilities across endpoints, cloud infrastructure, and enterprise applications.
As a technical leader, you will collaborate with Security Operations, Infrastructure, Cloud Engineering, DevOps, Application Owners, and Compliance teams to establish governance, optimize patch deployment processes, and improve the organizations overall security posture.
Key Responsibilities
- Lead the enterprise Endpoint Patch and Vulnerability Management program.
- Develop and maintain patch management policies, standards, and operational procedures.
- Define patch prioritization based on CVSS scores,
exploitability, threat intelligence, business criticality, and risk.
- Manage operating system and application patching across Windows, macOS, virtual machines, cloud platforms, firmware, and third-party software.
- Coordinate emergency patch deployments for zero-day vulnerabilities and critical/high-severity security incidents.
- Integrate vulnerability scanning tools with patch management platforms to automate remediation workflows.
- Partner with Infrastructure, Cloud, Platform Engineering, and Application teams to reduce remediation timelines.
- Design and implement automated patch deployment pipelines using scripting and configuration management tools.
- Monitor patch compliance, remediation SLAs, and vulnerability trends through dashboards and executive reporting.
- Perform root cause analysis for patch failures and recommend preventive improvements.
- Support audits and regulatory compliance requirements including ISO 27001, SOC 2, PCI DSS, HIPAA, NIST, Cyber Essentials Plus (Mandatory), and CIS Controls.
- Evaluate emerging technologies and recommend improvements to enterprise patch management capabilities.
- Mentor engineers and provide technical leadership across the organization.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field.
- 710 years of experience in Infrastructure, Systems Engineering, Cybersecurity, or Vulnerability Management.
- 5+ years leading enterprise patch management programs.
- Deep knowledge of Windows Client OS, Linux, VMware, AWS, Azure, GCP, and enterprise endpoint management.
- Experience with vulnerability management tools such as Qualys, Rapid7, or Microsoft Defender Vulnerability Management (any one is acceptable).
- Experience with Microsoft Intune (Mandatory), JAMF (Mandatory), Automox (Mandatory), and NinjaOne Patch Management (Optional).
- Strong scripting skills in PowerShell (Mandatory), Python, and Bash.
- Experience automating operational processes using Infrastructure as Code and configuration management tools.
- Solid understanding of CVSS, MITRE ATT&CK;, and threat intelligence.
- Experience supporting large-scale enterprise environments with thousands of endpoints.
Technical Skills
Vulnerability Management, Patch Management, Microsoft Intune, JAMF, PowerShell, Python, Bash, Azure, Microsoft Defender, Qualys, Rapid7, Automation, Risk Management
Key Competencies
- Technical Leadership
- Strategic Planning
- Risk Assessment
- Problem Solving
- Cross-functional Collaboration
- Incident Response Support
- Process Improvement
- Communication and Executive Reporting
- Decision Making
- Mentoring and Coaching
📌 Principal Security Patch Management Engineer (Endpoint) (Bengaluru)
🏢 Aziro
📍 Bengaluru