The Role
We are seeking an experienced Patch Management Specialist – Senior/Platform Lead to lead the implementation, optimisation and operationalisation of a strategic patch management programme within a highly regulated financial services environment.
This role will be responsible for deploying and configuring the patch management platform, designing the operating model, driving remediation of an existing patch backlog, and establishing a robust, risk‑based patching capability across a complex server and endpoint estate.
The successful candidate will combine strong technical expertise with operational leadership, ensuring patch compliance, vulnerability reduction and service stability within an environment where change control and uptime are critical.
Reports to: Cyber Practice Lead
Key Responsibilities
- Deploy and configure the patch platform (Tanium Core, Endpoint Management/Patch, Deploy, Comply/Exposure) across the endpoint and server estate.
- Design the tiered, ring‑based deployment model (canary → pilot → broad → critical) with soak periods, health gates and tested rollback.
- Establish the operating model, SLAs and reporting (patch compliance %, vulnerability burn‑down, exceptions register).
- Integrate patching with the client change‑management process and trading‑calendar‑aware windows.
- Lead remediation of the existing backlog to target state ahead of the external assessment.
- Define the snapshot‑before‑change control jointly with the backup specialist.
- Mentor and direct the patch operations engineers.
Essential Skills
- Deep enterprise patch experience on Tanium or a strong comparable (Ivanti Neurons, BigFix, SCCM/MECM, Qualys Patch).
- Hands‑on Windows Server and Linux (RHEL) patching at scale.
- Risk‑based prioritisation (CVE severity, CISA KEV, EPSS, exposure).
- Automation/packaging (PowerShell, custom sensors/packages).
- Rigorous change discipline; comfortable operating where downtime on a critical host is unacceptable.
Desirable Skills
Desirable: Financial‑services or other regulated/high‑assurance environment; vulnerability management tooling (Tenable/Qualys/Rapid7); CrowdStrike or Intune awareness for overlap mapping.
Certifications
Certifications: Tanium Certified Operator/Administrator; ITIL; relevant OS certs (MCSE/RHCE‑level).
#J-18808-Ljbffr…
