Lead Enterprise Infrastructure Patch and Security Engineer

All Lines Technology
Hermitage, PA, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Bash Shell Cipher Cloud Computing Configuration Management Databases File System Permissions Networking Hardware Python (Programming Language) Linux System Administration System Center Configuration Manager Windows Servers Public Key Infrastructure Windows PowerShell
+5 more
Red Hat Enterprise Linux Ansible Scripting Patch Management Cisco

Job description

We are seeking a highly skilled Lead Infrastructure Security & Patch Management Engineer to reduce security risk and maintain patch compliance across Infrastructure Services. This role is responsible for managing enterprise-wide remediation efforts using approved tools and processes across Windows Server, Enterprise Linux, cloud and on-prem environments, network devices, and other in-scope assets., * Own and manage the Security Remediation Program, ensuring alignment with Security findings (Critical, High, Medium).

  • Plan, schedule, and execute monthly operating system patching for Windows and Linux environments, including canary deployments, defined maintenance windows, and rollback strategies.
  • Lead zero-day and out-of-band patching efforts with expedited risk assessment and adherence to change control processes.
  • Deliver extended remediation activities, including updates to ciphers, protocols, file permissions, and third-party applications; coordinate with vendors as needed.
  • Administer and operate enterprise patching and security tooling, including MECM/SCCM, Ansible, Rapid7, Ivanti ITSM, Cisco DNA, Panorama, and Venafi, with manual deployments when required.
  • Manage quarterly component updates and oversee certificate lifecycle processes (PKI/DigiCert), including feasibility analysis for migrations from self-signed to PKI certificates.
  • Develop and publish compliance reports, audit documentation, and governance updates.
  • Facilitate and lead weekly Security-Infrastructure standups to track remediation progress and address risks.

Requirements

  • 5+ years of experience in infrastructure security and patch management.
  • Strong expertise in Windows Server and Enterprise Linux environments (e.g., RHEL).
  • Hands-on experience with enterprise tools such as MECM/SCCM, Ansible, Rapid7, Ivanti ITSM, Cisco DNA, Panorama, and Venafi/PKI.
  • Solid understanding of ITIL processes, including change management, incident management, and CMDB maintenance.
  • Experience with compliance reporting and audit support.
  • Scripting proficiency in PowerShell, Bash, or Python.
  • Demonstrated experience with canary deployments and rollback procedures.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

7:31 min

Essential foundational skills and concepts for infrastructure roles

Megha Kadur · LIVE

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · World Congress 2025

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all