Vulnerability Management & Patching Specialist
Location
United States + 127 moreAll locations: United States, Canada, Brazil, Colombia, Argentina, Chile, Venezuela, Bolivarian Republic Of, Bolivia, Plurinational State Of, Ecuador, French Guiana, Guyana, Paraguay, Peru, Suriname, Uruguay, Mexico, Costa Rica, El Salvador, Guatemala, Honduras, Nicaragua, Panama, Dominican Republic, Puerto Rico, Bahamas, Guadeloupe, Haiti, Jamaica, Martinique, Montserrat, United Kingdom, Germany, France, Estonia, Portugal, Hungary, Poland, Ukraine, Romania, Bulgaria, Czech Republic, Slovakia, Belarus, Moldova, Republic Of, Sweden, Greece, Belgium, Italy, Ireland, Switzerland, Netherlands, Finland, Malta, Denmark, Lithuania, Croatia, Spain, Austria, Bosnia And Herzegovina, Iceland, Luxembourg, Macedonia, The Former Yugoslav Republic Of, Montenegro, Norway, Serbia, Slovenia, Albania, Cyprus, Latvia, Monaco, South Africa, Egypt, Algeria, Angola, Benin, Botswana, Burkina Faso, Burundi, Cameroon, Cape Verde, Central African Republic, Chad, Congo, Côte D'ivoire, Congo, The Democratic Republic Of The, Equatorial Guinea, Eritrea, Ethiopia, Gabon, Gambia, Ghana, Guinea, Guinea-bissau, Kenya, Lesotho, Liberia, Libyan Arab Jamahiriya, Madagascar, Malawi, Mali, Mauritania, Mauritius, Mayotte, Morocco, Mozambique, Namibia, Niger, Nigeria, Réunion, Rwanda, Senegal, Seychelles, Sierra Leone, Somalia, Sudan, Swaziland, Tanzania, United Republic Of, Togo, Tunisia, Uganda, Zambia, Zimbabwe
Posted
3 days ago
Salary
$25 / year
No structured requirement data.
Job Description
Role Description
The Vulnerability Management & Patching Specialist is responsible for delivering vulnerability identification, risk‑based prioritisation, remediation coordination, and patch compliance across multiple customer environments in a managed services model. The role operates within clearly defined service scopes and shared‑responsibility agreements, using tools such as Tenable and patch management platforms (e.g. ManageEngine Patch Manager Plus or equivalent) to reduce customer risk while meeting contractual SLAs, regulatory obligations, and operational stability requirements.
Core Responsibilities
-
Vulnerability Management
- Perform scheduled and ad‑hoc vulnerability scans across customer environments using Tenable or equivalent platforms, in line with contracted service scope.
-
Analyse scan results to:
- Validate findings and eliminate false positives.
- Assess risk based on severity, exploitability, and asset criticality.
- Determine remediation ownership under the shared‑responsibility model.
- Prioritise vulnerabilities according to customer SLAs, regulatory requirements, and threat exposure.
- Track vulnerabilities through their lifecycle, from detection to remediation, mitigation, exception, or risk acceptance.
- Support SOC escalation workflows for critical or actively exploited vulnerabilities.
-
Patch Management
- Plan, coordinate, and execute patching activities where patching is included in the managed service scope.
-
Use ManageEngine Patch Manager Plus or equivalent tools to:
- Automate patch deployment.
- Schedule maintenance windows.
- Enforce approval workflows.
- Monitor patch success and compliance.
- Support emergency and zero‑day patching in response to high‑risk vulnerabilities.
- Ensure patching activities minimise customer impact through testing, staged rollouts, and rollback planning.
- Maintain patch baselines across servers, endpoints, and supported applications, aligned to customer contracts.
-
Service Delivery, Governance & Reporting
-
Produce customer‑facing vulnerability and patch reports, including:
- Outstanding vulnerabilities by risk level.
- Patch compliance status.
- SLA performance and remediation trends.
- Provide clear remediation guidance to customers where patching responsibility remains client‑owned.
-
Maintain accurate documentation of:
- Patch schedules and deployment outcomes.
- Vulnerability exceptions and compensating controls.
- Risk acceptances and approvals.
- Support customer audits, cyber‑insurance, and regulatory evidence requests.
-
Produce customer‑facing vulnerability and patch reports, including:
Qualifications
- 3–5 years’ experience in vulnerability management, patch management, SOC, or MSSP operations.
-
Hands‑on experience with vulnerability management tools, such as:
- Tenable Vulnerability Management / Tenable Security Center.
- Qualys or equivalent (transferable skills accepted).
-
Experience with patch management platforms, such as:
- ManageEngine Patch Manager Plus.
- SCCM, WSUS, BigFix, Tanium, or similar.
-
Strong understanding of:
- CVEs, CVSS, exploitability, and risk‑based remediation.
- Windows and Linux patching models.
- Third‑party application patching.
- Experience working in multi‑tenant, SLA‑driven environments.
- Familiarity with ITIL processes, particularly Change, Incident, and Problem Management.
-
Relevant certifications (preferred but not mandatory):
- Tenable certifications.
- Security+ or equivalent.
- ITIL Foundation.
Personal Attributes
- Strong organisational skills to manage multiple customers concurrently.
- Ability to clearly communicate risk, remediation status, and ownership boundaries to customers.
- Comfortable operating in high‑pressure, incident‑driven scenarios.
- Detail‑oriented with a strong focus on evidence, reporting accuracy, and audit readiness.
- Proactive mindset focused on continuous service improvement.
Job Requirements
- 3–5 years’ experience in vulnerability management, patch management, SOC, or MSSP operations.
- Hands‑on experience with vulnerability management tools, such as: Tenable Vulnerability Management / Tenable Security Center.
- Qualys or equivalent (transferable skills accepted).
- Experience with patch management platforms, such as: ManageEngine Patch Manager Plus.
- SCCM, WSUS, BigFix, Tanium, or similar.
- Strong understanding of: CVEs, CVSS, exploitability, and risk‑based remediation.
- Windows and Linux patching models.
- Third‑party application patching.
- Experience working in multi‑tenant, SLA‑driven environments.
- Familiarity with ITIL processes, particularly Change, Incident, and Problem Management.
- Relevant certifications (preferred but not mandatory): Tenable certifications.
- Security+ or equivalent.
- ITIL Foundation.
- Personal Attributes
- Strong organisational skills to manage multiple customers concurrently.
- Ability to clearly communicate risk, remediation status, and ownership boundaries to customers.
- Comfortable operating in high‑pressure, incident‑driven scenarios.
- Detail‑oriented with a strong focus on evidence, reporting accuracy, and audit readiness.
- Proactive mindset focused on continuous service improvement.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Senior Regional Safety Manager
Kellermeyer Bergensons ServicesKellermeyer Bergensons Services (KBS) is the largest privately held provider of facility services in North America, servicing over 2 billion square feet of space daily. We help industry leaders across a wide range of key verticals—including retail, industrial and logistics, healthcare, education, manufacturing, and more—maintain clean, efficient and welcoming spaces that support their operations. As we continue to grow, we’re looking for team members who are dedicated, reliable, and ready to contribute to a culture built on respect, opportunity, and pride in service.
The Senior Regional Safety Manager ensures that their region complies with OSHA health and safety rules and regulations. This role is responsible for establishing and maintaining safe workplace policies. Requires excellent attention to detail and the ability to assess opportuniti...
Senior Security Control Assessor
Arlo Solutions LLCArlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. The Department of Defense’s (DoD) Chief Digital and Artificial Intelligence Office (CDAO) is at the forefront of supporting the DoD with the adoption of innovative technologies such as data, analytics, and artificial intelligence to help accelerate predictions, forecasts, and interpretations for both strategic and tactical decisions across the enterprise.
The Department of Defense’s (DoW) Office of the Undersecretary of War for Research and Engineering (OUSW (R&E)) is at the forefront of supporting the DoW with the adoption of innovative technologies such as data, analytics, and artificial intelligence to help accelerate predict...
Senior Investigator, Aetna SIU (Must reside in Ohio)
CVS HealthBringing our heart to every moment of your health.
The Senior Investigator conducts high-level, complex investigations into suspected healthcare fraud and abuse, often involving sensitive, high-profile, or national scope cases within Medicaid lines of business. This role involves researching, documenting case activity, facilitating recovery of lost funds, and providing guidance and training to less experienced investigators.
Cybersecurity Analyst supporting NASA’s enterprise business solutions