The Vulnerability & Patching Operations Engineer will support enterprise endpoint security by managing vulnerability remediation, patch deployment, compliance monitoring, and operational reporting across Windows and macOS environments. The role will work closely with Security, EUC, Infrastructure, and application teams to maintain a secure and compliant endpoint setting.
Key Responsibilities
Vulnerability Management
- Monitor endpoint vulnerabilities using approved security and vulnerability management tools.
- Track remediation progress and coordinate closure of identified vulnerabilities.
- Follow up with stakeholders to ensure timely remediation of security findings.
- Support vulnerability compliance reporting and audits.
Patch Management
- Manage operating system and third-party application patching activities.
- Monitor patch deployment success and investigate deployment failures.
- Coordinate patch testing, validation, and production rollout activities.
- Ensure endpoints maintain required patch compliance levels.
Compliance & Reporting
- Generate vulnerability and patch compliance reports and dashboards.
- Track remediation SLAs and compliance metrics.
- Support audit requests and security compliance initiatives.
- Maintain operational documentation and runbooks.
EUC Operations Support
- Support endpoint security initiatives and agent health monitoring.
- Collaborate with EUC and Security teams on compliance and remediation activities.
- Assist with endpoint management and operational improvement initiatives.
Required Qualifications
- 3-5 years of experience in Vulnerability Management, Patch Management, Endpoint Administration, or IT Security Operations.
- Experience with vulnerability management platforms such as Qualys, Tenable, Rapid7, Defender Vulnerability Management, or equivalent.
- Experience managing Windows and macOS patching processes.
- Familiarity with endpoint management solutions such as Intune, MECM/SCCM, Workspace ONE, or Jamf.
- Strong analytical, reporting, and troubleshooting skills.
- Experience with ServiceNow or similar ITSM platforms.
Preferred Qualifications
- Experience with CrowdStrike, Microsoft Defender, Tanium, or other endpoint security tools.
- Knowledge of CIS Benchmarks and security compliance frameworks.
- PowerShell or scripting experience.
- ITIL Foundation certification.