1,192,223open jobs
66,785companies
211,515added this week
Browse all
Salary
$100k – $120k per year
Location
Remote (likely United States)
Seniority
Staff · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Sep 9, 2026.

Overview
Company
Impact
Profile match
Empowering businesses with top-tier IT solutions, Nexustek provides managed IT services, cybersecurity, cloud solutions, and digital transformation support. Maximize productivity and enhance security with our custom IT solutions designed for business growth.

About the Role:

The Patch Engineering Lead is responsible for planning, coordinating, and executing patch management and vulnerability remediation across NexusTek's client and internal environments. This role ensures the timely and reliable deployment of operating system and third-party application patches across on-premises, cloud, and hybrid infrastructure, while maintaining compliance with regulatory frameworks such as HIPAA for clients handling Protected Health Information (PHI).

Location and Schedule:

Work from home, United States

Monday through Friday local business hours

You know how to:

  • Own the end-to-end patch management lifecycle - assessment, testing, scheduling, deployment, verification, and reporting - across Windows, Linux, and macOS servers and endpoints.
  • Configure, maintain, and operate patch and endpoint management platforms including Automox, N-able (N-central/N-sight), and Microsoft Intune to deploy OS and third-party application patches across managed client environments.
  • Manage patch compliance for cloud-hosted workloads using AWS Systems Manager (Patch Manager) and Azure Update Manager, including patch baselines, maintenance windows, and compliance reporting.
  • Develop, document, and continuously improve patch management policies, standard operating procedures, and client-specific maintenance windows in alignment with contracted SLAs.
  • Triage and remediate vulnerabilities identified through vulnerability scanning and management tools, prioritizing remediation based on severity, exploitability, and business risk.
  • Ensure patch management practices for healthcare and other regulated clients align with HIPAA Security Rule requirements, including safeguarding electronic Protected Health Information (ePHI) and maintaining audit-ready patch and remediation documentation.
  • Coordinate emergency and out-of-band patching for critical vulnerabilities and actively exploited CVEs, balancing urgency with change management and client communication requirements.
  • Validate patches in test/pilot device groups prior to broad deployment to minimize service disruption and identify compatibility issues before production rollout.
  • Coordinate firmware update cycles for network and infrastructure devices (e.g., switches, routers, firewalls, wireless controllers), evaluating vendor release notes and change logs to assess the potential impact on network stability, routing, and connectivity prior to deployment.
  • Identify the scope of systems, sites, and dependent services that could be affected by a given firmware or infrastructure update, and plan staged or phased rollouts to contain the risk of a single update causing widespread outages across the network.
  • Monitor patch deployment success/failure rates, investigate and remediate failed or stalled patch deployments, and re-run or re-schedule as needed.
  • Maintain accurate, current documentation of patch cycles, exceptions, deferrals, and remediation timelines within the PSA/ticketing system and documentation platform.
  • Produce regular patch compliance and vulnerability remediation reports for internal stakeholders and client-facing account teams.
  • Support internal and client audits and compliance assessments (e.g., HIPAA, SOC 2) by providing patch management evidence, metrics, and process documentation.
  • Collaborate with the NOC, Service Desk, and Security teams to schedule patch deployment windows that minimize impact to client operations.
  • Stay current on emerging vulnerabilities, vendor patch releases (including Microsoft Patch Tuesday), and CVE disclosures relevant to supported environments.
  • Participate in change management processes for all patch and remediation deployments, ensuring appropriate approvals and rollback plans are in place.
  • Continually identify opportunities to improve patch automation, reduce manual effort, and reduce mean-time-to-remediate across the client base.

Technology Proficiencies:

  • At least 3-5 years of experience in IT operations, systems administration, or security operations, with a focus on patch and/or vulnerability management, ideally within an MSP or multi-client environment.
  • Hands-on experience administering patch/RMM platforms such as Automox, N-able N-central/N-sight, and Microsoft Intune/Endpoint Manager; familiarity with WSUS or SCCM is a plus.
  • Experience managing patching for cloud infrastructure in AWS (Systems Manager) and Azure (Update Manager, Azure Arc-enabled servers).
  • Familiarity with vulnerability scanning and management tools such as Tenable/Nessus, Qualys, or Rapid7 InsightVM.
  • Working knowledge of the HIPAA Security Rule and requirements for protecting electronic Protected Health Information (ePHI); experience supporting healthcare or other regulated clients preferred.
  • Familiarity with additional compliance frameworks (SOC 2, NIST CSF, CIS Controls) is a plus.
  • Scripting or automation experience (PowerShell, Bash, or Python) to support patch orchestration and reporting is a plus.
  • Experience working within a PSA/ticketing platform (e.g., ConnectWise, Autotask) and documentation systems (e.g., IT Glue).
  • Working knowledge of core networking concepts (TCP/IP, DNS, DHCP, VLANs, routing and switching, VPNs, and firewall rules) sufficient to understand how a device sits within, and depends on, the broader network.
  • Experience patching or upgrading firmware on network and infrastructure hardware (switches, routers, firewalls, wireless access points, or server/storage controllers), including recognizing how a single firmware issue can cascade into widespread connectivity or service outages.

Licencses/Certifications: At least one of the following (or comparable):

  • CompTIA Security+
  • Microsoft Certified: Azure Administrator Associate
  • AWS Certified SysOps Administrator - Associate (or AWS Certified Solutions Architect - Associate)
  • ITIL Foundation (preferred, not required)

Pay and Benefits:

Estimated Starting Salary/Wage Range: $100,000 - $120,000 annual, based on candidate's experience, qualifications, and location.

In addition to legally-required benefits, NexusTek offers a benefit package to eligible full-time employees, which currently includes the following:

  • Four weeks of annual accrued PTO
  • Seven paid national holidays
  • Medical, dental, vision options
  • Company-paid life insurance, short and long-term disability
  • Voluntary benefits such as critical illness and accident
  • Voluntary Legal Shield and identity theft protection
  • Discretionary annual 401k match plan
  • Generous employee referral bonus plan
  • Employee Assistance Program
  • Access to over 90,000+ courses in ADP My Learning
  • StandOut employee engagement tools
  • Eligible to apply for a Pluralsight license
  • Eligible to apply for NexusTek Technical Academy or Leadership Academy

We’re happy to provide our comprehensive benefits guide. Each benefit is subject to eligibility requirements as specified in plan documents, and the Company reserves the right to modify the benefits it offers from time to time.

Interview Process- Typical interview process for this role:

Application and Screening Stage- Thanks for showing interest!

  • Submit your application
  • Our recruiters carefully consider each application. If you are selected to move forward, we will contact you for the 20 minute introductory screening to learn more about you and why you want to work for NexusTek.

Interview Stage - We’ll dive into your experience more in depth

  • One-hour technical interview with hiring manager (virtual)
  • One-hour interview with VP-level team member (virtual)
  • References - 3 professional references at least one direct supervisor
  • You are welcome to request additional conversations with team members you didn’t get to meet during the process

NexusTek provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws

NexusTek participates in E-Verify for all US Employees

Please be aware of potential recruitment fraud and fake social media pages. NexusTek will never ask you to pay a fee as part of the interview process. Additionally, we will not ask for your personal banking information until you have signed an employment offer and completed virtual onboarding training and paperwork provided by our HR team.

All communications with NexusTek professionals will only be sent from an @nexustek.com or ADP email address and never originate from gmail.com, yahoo.com, or other commercial email services. If you are viewing this job post outside of our website and interested in exploring opportunities, please go directly to our Careers Page: https://www.nexustek.com/nexustek-careers/ or https://workforcenow.adp.com/mascsr/default/mdf/recruitment/recruitment.html?cid=567e686e-7575-49d9-b29f-985e7365f987&ccId=19000101_000001&type=MP&lang=en_US

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,192,223 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Management
Similar stack
Same company
In your city
≈ $104k – $206k per year (Estimated) • Remote (United States) • Full-Time
Management
Dropbox
Apply
≈ $110k – $225k per year (Estimated) • Remote (United States)
Apply
≈ $65k – $139k per year (Estimated) • Remote (MENA, Europe, Africa) • Full-Time • Germany
Apply
Remote (Hong Kong) • Hong Kong
Apply
≈ $21k – $55k per year (Estimated) • Remote (South Africa) • Full-Time • Sandton
Apply
≈ $50k – $128k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Porto
JavaScript
Node JS
Node JS
Commander.js
DevOps
Azure
AWS
Cloudflare
IAM
DNS
DHCP
VPN
Wi-Fi
Cybersecurity
Microsoft Sentinel
Microsoft Defender
SIEM
Management
Agile
ITIL
Apply
FinOps Analyst 2 days ago
≈ $22k – $56k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Sofia
Python
SQL
PowerShell
AI/ML
AI Agents
DevOps
Azure
AWS
FinOps
Analytics
Power BI
Apply
Software Engineer 2 days ago
≈ $9k – $27k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Chennai
JavaScript
Java
TypeScript
SQL
C#
Java
Spring Boot
C#
.NET
Frontend
Angular
Bootstrap
React.js
DevOps
GCP
Azure
AWS
Management
Agile
Scrum
Apply
≈ $20k – $55k per year (Estimated) • In office • Full-Time • Phnom Penh
Python
JavaScript
Java
SQL
C#
C++
C++
TensorFlow C++
PyTorch C++
AI/ML
Scikit-learn
AI Agents
TensorFlow
PyTorch
Machine Learning
Frontend
Bootstrap
DevOps
GCP
Azure
Git
AWS
Analytics
Tableau
Power BI
Management
Agile
Apply
≈ $52k – $132k per year (Estimated) • In office • Full-Time • 5+ years exp • Phnom Penh
Python
Go
SQL
AI/ML
Copilot
Cursor
Claude Code
DevOps
Terraform
Ansible
GCP
OpenTelemetry
Prometheus
Azure
CI/CD
AWS
Kubernetes
Grafana
Platform Engineering
Configuration Management
Self-Healing
Incident Management
SLI/SLO/SLA
Apply
Sr. System Engineer 3 days ago
$110k – $120k per year • Hybrid • Full-Time • United States
Python
PowerShell
Bash
DevOps
Terraform
Ansible
GCP
GitLab CI
Azure
CI/CD
Windows Server
Jenkins
AWS
Docker
Kubernetes
Configuration Management
Amazon EKS
AWS Lambda
Amazon EC2
SLI/SLO/SLA
Amazon S3
IAM
Amazon CloudWatch
AWS Step Functions
API Gateway
Windows
VPN
Cybersecurity
SOC 2
HIPAA
Microsoft Entra ID
Active Directory
SIEM
Management
Gmail
Apply
Solutions Engineer 12 days ago
up to $115k per year • Hybrid • Full-Time • United States
AI/ML
Copilot
DevOps
GCP
Azure
AWS
Cybersecurity
SOC 2
Microsoft Entra ID
SIEM
Management
Gmail
Microsoft Office
Apply
$160k – $220k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Boston
Management
Gmail
Apply
≈ $120k – $248k per year (Estimated) • In office • Full-Time • 7+ years exp • San Francisco
AI/ML
AI Agents
DevOps
GCP
VMWare
Azure
AWS
FinOps
Cybersecurity
Zero Trust
Management
Gmail
Apply
See all jobs
This is one of many
1,192,223 more open roles from verified company boards, updated every day.