Senior Associate - Endpoint Patching SRE
Listed on 2026-08-06
-
IT/Tech
Cybersecurity, Systems Engineer, IT Support, Network Security
Endpoint Patching Specialist
Own endpoint patch execution reliability, deployment waves, endpoint compliance, rollback controls, and evidence capture for workstations and user devices. This role ensures endpoint patches are deployed through controlled rings, validated for user impact, monitored for failures, and closed with evidence while supporting accelerated remediation for Critical VITs, High priority patches, and zero-day events.
Execute endpoint patching through approved endpoint management and orchestration platforms. Manage pilot rings, broad deployment waves, rollback groups, exception handling, and endpoint maintenance schedules. Monitor patch success, failed installs, reboot compliance, endpoint health, and user-impacting defects. Support 24-hour Critical VIT, 3-day High, and 6-day priority patching cycles for endpoint vulnerabilities.
Validate VPN, EDR, authentication, security agents, productivity tools, and endpoint performance after patching. Coordinate rollback, pause, retry, workaround, or escalation decisions when endpoint instability occurs. Partner with Service Desk, Endpoint Engineering, Security, and application teams to resolve user-impacting incidents. Document known issues, failed device follow-up, compensating controls, and closure evidence.
Improve endpoint patch automation, deployment reporting, reboot compliance, health checks, and evidence capture. Create dashboards for endpoint compliance, failed devices, overdue patches, exceptions, and closure readiness. Partner with Patch & Vulnerability Ops to ensure endpoint vulnerability records remain open until validated or exceptioned.
Pause or slow endpoint deployment waves when impact thresholds are breached. Recommend rollback, workaround, retry, or escalation paths for endpoint patch issues. Require failed-device follow-up and evidence before endpoint remediation records are closed.
Endpoint patch compliance improves across in-scope device populations. Failed installs, reboot exceptions, and repeat endpoint issues are reduced. Endpoint patch rollouts complete within defined severity lanes. User-impacting incidents are quickly contained and documented. Closure evidence is consistently captured for endpoint remediation.
5+ years in endpoint engineering, endpoint operations, SRE, or enterprise patching. Experience with Tanium, Microsoft Intune, SCCM/MECM, endpoint security agents, endpoint compliance reporting, or similar platforms. Strong understanding of endpoint operating systems, reboot compliance, EDR, VPN, authentication, and productivity-tool impacts. Strong troubleshooting, incident triage, and cross-team coordination skills.
Hybrid operations role with occasional off-hours support during major endpoint patch deployments, zero-day events, Critical VIT response, or widespread endpoint-impacting incidents.
Salary Range: $111,500-$159,000
Overtime eligible:
Exempt
Discretionary bonus eligible:
Yes
Sales bonus eligible:
No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).