{"id":1689339,"url":"https://alion.io/job/nexustek-patch-engineering-lead","title":"Patch Engineering Lead","company":{"id":2054979,"name":"NexusTek","domain":"nexustek.com","url":"https://alion.io/company/nexustek","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"ADP","truth_index":null},"role":"Management","role_family":"Management","seniority":"lead","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"inferred_payroll_markers","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":100000,"max":120000,"currency":"USD","period":"year","gross":null,"usd_annual":120000},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CVE","optional":false},{"name":"HIPAA","optional":false},{"name":"Linux","optional":false},{"name":"Service Desk","optional":false},{"name":"SOC 2","optional":false},{"name":"Windows","optional":false},{"name":"Bash","optional":true},{"name":"DHCP","optional":true},{"name":"DNS","optional":true},{"name":"Gmail","optional":true},{"name":"ITIL","optional":true},{"name":"Nessus","optional":true},{"name":"NIST CSF","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Qualys Cloud Platform","optional":true},{"name":"TCP/IP","optional":true}],"status":"closed","first_seen_at":"2026-09-09T23:17:00Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-10-05T16:45:47Z","board_verified":false,"closed_at":"2026-10-05T16:45:47Z","days_open":25,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":25},"description":"About the Role:\nThe Patch Engineering Lead is responsible for planning, coordinating, and executing patch management and vulnerability remediation across NexusTek's client and internal environments. This role ensures the timely and reliable deployment of operating system and third-party application patches across on-premises, cloud, and hybrid infrastructure, while maintaining compliance with regulatory frameworks such as HIPAA for clients handling Protected Health Information (PHI).\nLocation and Schedule:\nWork from home, United States\nMonday through Friday local business hours\nYou know how to:\nOwn the end-to-end patch management lifecycle - assessment, testing, scheduling, deployment, verification, and reporting - across Windows, Linux, and macOS servers and endpoints.\nConfigure, maintain, and operate patch and endpoint management platforms including Automox, N-able (N-central/N-sight), and Microsoft Intune to deploy OS and third-party application patches across managed client environments.\nManage patch compliance for cloud-hosted workloads using AWS Systems Manager (Patch Manager) and Azure Update Manager, including patch baselines, maintenance windows, and compliance reporting.\nDevelop, document, and continuously improve patch management policies, standard operating procedures, and client-specific maintenance windows in alignment with contracted SLAs.\nTriage and remediate vulnerabilities identified through vulnerability scanning and management tools, prioritizing remediation based on severity, exploitability, and business risk.\nEnsure patch management practices for healthcare and other regulated clients align with HIPAA Security Rule requirements, including safeguarding electronic Protected Health Information (ePHI) and maintaining audit-ready patch and remediation documentation.\nCoordinate emergency and out-of-band patching for critical vulnerabilities and actively exploited CVEs, balancing urgency with change management and client communication requirements.\nValidate patches in test/pilot device groups prior to broad deployment to minimize service disruption and identify compatibility issues before production rollout.\nCoordinate firmware update cycles for network and infrastructure devices (e.g., switches, routers, firewalls, wireless controllers), evaluating vendor release notes and change logs to assess the potential impact on network stability, routing, and connectivity prior to deployment.\nIdentify the scope of systems, sites, and dependent services that could be affected by a given firmware or infrastructure update, and plan staged or phased rollouts to contain the risk of a single update causing widespread outages across the network.\nMonitor patch deployment success/failure rates, investigate and remediate failed or stalled patch deployments, and re-run or re-schedule as needed.\nMaintain accurate, current documentation of patch cycles, exceptions, deferrals, and remediation timelines within the PSA/ticketing system and documentation platform.\nProduce regular patch compliance and vulnerability remediation reports for internal stakeholders and client-facing account teams.\nSupport internal and client audits and compliance assessments (e.g., HIPAA, SOC 2) by providing patch management evidence, metrics, and process documentation.\nCollaborate with the NOC, Service Desk, and Security teams to schedule patch deployment windows that minimize impact to client operations.\nStay current on emerging vulnerabilities, vendor patch releases (including Microsoft Patch Tuesday), and CVE disclosures relevant to supported environments.\nParticipate in change management processes for all patch and remediation deployments, ensuring appropriate approvals and rollback plans are in place.\nContinually identify opportunities to improve patch automation, reduce manual effort, and reduce mean-time-to-remediate across the client base.\nTechnology Proficiencies:\nAt least 3-5 years of experience in IT operations, systems administration, or security operations, with a focus on patch and/or vulnerability management, ideally within an MSP or multi-client environment.\nHands-on experience administering patch/RMM platforms such as Automox, N-able N-central/N-sight, and Microsoft Intune/Endpoint Manager; familiarity with WSUS or SCCM is a plus.\nExperience managing patching for cloud infrastructure in AWS (Systems Manager) and Azure (Update Manager, Azure Arc-enabled servers).\nFamiliarity with vulnerability scanning and management tools such as Tenable/Nessus, Qualys, or Rapid7 InsightVM.\nWorking knowledge of the HIPAA Security Rule and requirements for protecting electronic Protected Health Information (ePHI); experience supporting healthcare or other regulated clients preferred.\nFamiliarity with additional compliance frameworks (SOC 2, NIST CSF, CIS Controls) is a plus.\nScripting or automation experience (PowerShell, Bash, or Python) to support patch orchestration and reporting is a plus.\nExperience working within a PSA/ticketing platform (e.g., ConnectWise, Autotask) and documentation systems (e.g., IT Glue).\nWorking knowledge of core networking concepts (TCP/IP, DNS, DHCP, VLANs, routing and switching, VPNs, and firewall rules) sufficient to understand how a device sits within, and depends on, the broader network.\nExperience patching or upgrading firmware on network and infrastructure hardware (switches, routers, firewalls, wireless access points, or server/storage controllers), including recognizing how a single firmware issue can cascade into widespread connectivity or service outages.\nLicencses/Certifications: At least one of the following (or comparable):\nCompTIA Security+\nMicrosoft Certified: Azure Administrator Associate\nAWS Certified SysOps Administrator - Associate (or AWS Certified Solutions Architect - Associate)\nITIL Foundation (preferred, not required)\nPay and Benefits:\nEstimated Starting Salary/Wage Range: $100,000 - $120,000 annual, based on candidate's experience, qualifications, and location.\nIn addition to legally-required benefits, NexusTek offers a benefit package to eligible full-time employees, which currently includes the following:\nFour weeks of annual accrued PTO \nSeven paid national holidays \nMedical, dental, vision options \nCompany-paid life insurance, short and long-term disability \nVoluntary benefits such as critical illness and accident \nVoluntary Legal Shield and identity theft protection \nDiscretionary annual 401k match plan \nGenerous employee referral bonus plan \nEmployee Assistance Program \nAccess to over 90,000+ courses in ADP My Learning \nStandOut employee engagement tools \nEligible to apply for a Pluralsight license \nEligible to apply for NexusTek Technical Academy or Leadership Academy \nWe’re happy to provide our comprehensive benefits guide. Each benefit is subject to eligibility requirements as specified in plan documents, and the Company reserves the right to modify the benefits it offers from time to time.\nInterview Process- Typical interview process for this role:\nApplication and Screening Stage- Thanks for showing interest!\nSubmit your application\nOur recruiters carefully consider each application. If you are selected to move forward, we will contact you for the 20 minute introductory screening to learn more about you and why you want to work for NexusTek.\nInterview Stage - We’ll dive into your experience more in depth\nOne-hour technical interview with hiring manager (virtual) \nOne-hour interview with VP-level team member (virtual)\nReferences - 3 professional references at least one direct supervisor \nYou are welcome to request additional conversations with team members you didn’t get to meet during the process \nNexusTek provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws\nNexusTek participates in E-Verify for all US Employees\nPlease be aware of potential recruitment fraud and fake social media pages. NexusTek will never ask you to pay a fee as part of the interview process. Additionally, we will not ask for your personal banking information until you have signed an employment offer and completed virtual onboarding training and paperwork provided by our HR team. \nAll communications with NexusTek professionals will only be sent from an @nexustek.com or ADP email address and never originate from gmail.com, yahoo.com, or other commercial email services. If you are viewing this job post outside of our website and interested in exploring opportunities, please go directly to our Careers Page: https://www.nexustek.com/nexustek-careers/ or https://workforcenow.adp.com/mascsr/default/mdf/recruitment/recruitment.html?cid=567e686e-7575-49d9-b29f-985e7365f987&ccId=19000101_000001&type=MP&lang=en_US","description_format":"text","description_chars":9001,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["401k plan","Life insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Technology","Information Security"],"lifecycle":[{"event":"open","at":"2026-10-02T10:47:35Z"},{"event":"close","at":"2026-10-05T16:45:47Z"}],"visa":[],"liveness":null,"pay":{"stated_usd_annual":120000,"is_top_pay":false},"html_url":"https://alion.io/job/nexustek-patch-engineering-lead","json_url":"https://alion.io/job/nexustek-patch-engineering-lead.json","meta":{"generated_at":"2026-10-08T00:32:06Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":746,"day_limit":5000,"remaining_today":4254,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2054979},"rest":"https://alion.io/mcp/rest/get_company?id=2054979"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fnexustek-patch-engineering-lead"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fnexustek-patch-engineering-lead"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fnexustek-patch-engineering-lead"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/nexustek-patch-engineering-lead\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fnexustek-patch-engineering-lead"}]}