Patch Management Engineer
Cary, NC · On-site
Qualys, Tenable Nessus, or Rapid7 InsightVM. * Knowledge of Windows OS lifecycle, patch Tuesday ... Endpoint Administrator Associate (MD-102) * Microsoft Certified: Azure Administrator Associate (AZ ...
Cary, NC · On-site
Qualys, Tenable Nessus, or Rapid7 InsightVM. * Knowledge of Windows OS lifecycle, patch Tuesday ... Endpoint Administrator Associate (MD-102) * Microsoft Certified: Azure Administrator Associate (AZ ...
Cary, NC · On-site
Qualys, Tenable Nessus, or Rapid7 InsightVM. * Knowledge of Windows OS lifecycle, patch Tuesday ... Endpoint Administrator Associate (MD-102) * Microsoft Certified: Azure Administrator Associate (AZ ...
Cary, NC · On-site
$65K - $70K/yr
Qualys, Tenable Nessus, or Rapid7 InsightVM. * Knowledge of Windows OS lifecycle, patch Tuesday ... Azure Administrator Associate (AZ-104). * CompTIA Security+ or CySA+. * ITIL 4 Managing ...
Quick apply
Cary, NC · On-site
$65K - $70K/yr
Qualys, Tenable Nessus, or Rapid7 InsightVM. * Knowledge of Windows OS lifecycle, patch Tuesday ... Azure Administrator Associate (AZ-104). * CompTIA Security+ or CySA+. * ITIL 4 Managing ...
$43.2K is the 25th percentile. Wages below this are outliers.
$26.2K - $51.3K
37% of jobs
$51.3K - $76.4K
6% of jobs
$76.4K - $101.4K
4% of jobs
The median wage is $117.1K / yr.
$101.4K - $126.5K
4% of jobs
$126.5K - $151.5K
9% of jobs
$151.5K - $176.6K
6% of jobs
$194.7K is the 75th percentile. Wages above this are outliers.
$176.6K - $201.6K
11% of jobs
$201.6K - $226.7K
7% of jobs
$226.7K - $251.7K
6% of jobs
$251.7K - $276.8K
4% of jobs
$276.8K - $301.8K
4% of jobs
$26.2K
$137.3K
$301.8K
| Aspect | Associate Rapid7 | Security Analyst |
|---|---|---|
| Required Certifications | CompTIA Security+, Cisco CCNA, or similar | CompTIA Security+, CISSP, CEH often preferred |
| Work Environment | Entry-level, team-based cybersecurity or IT support | Mid-level, analyzing security threats and incident response |
| Employer & Industry Usage | IT firms, cybersecurity companies, tech departments | Financial, healthcare, government, and enterprise sectors |
The Associate Rapid7 role typically involves supporting security tools and monitoring, serving as an entry point into cybersecurity. Security Analysts focus on analyzing threats, investigating incidents, and implementing security measures. While both roles require similar certifications and work in related environments, Security Analysts usually have more experience and responsibilities in threat analysis and response.
The most popular types of Rapid7 jobs in Raleigh, NC are:
For Associate Rapid7 jobs in Raleigh, NC, the most frequently searched job titles are:
The top searched job categories for Associate Rapid7 jobs in Raleigh, NC are:
ROLE SUMMARY
The L2 Senior Patch Management Engineer owns the end-to-end patch lifecycle for the end-user computing environment. Responsibilities include designing and maintaining patching baselines, automating patch workflows, resolving complex deployment failures, and acting as an escalation point for L1 analysts. The role also involves continuous improvement of patch tooling and processes.
KEY RESPONSIBILITIES
Own the patch management lifecycle: assessment, testing, approval, deployment, validation, and reporting for all EUC endpoints.
Design and maintain software update groups, collections, and deployment rules in SCCM/MECM and Microsoft Intune.
Develop and maintain PowerShell / WMI scripts to automate patch compliance checks, remediation, and reporting.
Act as L2 escalation for patch deployment failures, application compatibility issues, and non-compliant device investigations.
Conduct patch testing in pilot/UAT rings before production rollout; document test results and obtain change approval.
Integrate Qualys / Tenable vulnerability scan data to drive patch prioritisation based on CVSS scores.
Define and enforce patching SLAs for Critical, High, Medium, and Low severity patches per security policy.
Maintain and improve the patch management runbook, SOPs, and exception handling process.
Collaborate with security operations (SOC) to address zero-day threats and emergency patch deployments.
Produce monthly patch compliance reports and trend analysis for management review.
Mentor and guide L1 analysts; review their tickets and provide technical feedback.
TECHNICAL SKILLS & KNOWLEDGE
Deep expertise in SCCM/MECM – software update point, ADRs, deployment rings, client health.
Hands-on experience with Microsoft Intune / Autopilot / Windows Update for Business.
Advanced PowerShell scripting for automation (compliance remediation, report extraction, deployment triggers).
Experience with vulnerability management tools: Qualys, Tenable Nessus, or Rapid7 InsightVM.
Knowledge of Windows OS lifecycle, patch Tuesday cycle, CBS, WUA, and WinSxS.
Familiarity with macOS patch management (Jamf Pro / Munki) is an advantage.
Understanding of BitLocker, Windows Defender, and endpoint security baselines (CIS / STIG).
Experience integrating patch workflows with ServiceNow ITSM and CMDB.
Working knowledge of Azure AD, Entra ID, and Conditional Access policies.
SOFT SKILLS & COMPETENCIES
Strong analytical and troubleshooting skills for complex patch failures.
Excellent documentation skills – able to produce clear SOPs, RCAs, and change records.
Effective communicator across technical and non-technical stakeholders.
Proactive mindset – identifies process gaps and proposes improvements.
Ability to manage concurrent workstreams under deadline pressure.
PREFERRED CERTIFICATIONS
Microsoft 365 Certified: Endpoint Administrator Associate (MD-102)
Microsoft Certified: Azure Administrator Associate (AZ-104)
CompTIA Security+ or CySA+
ITIL 4 Managing Professional (or Foundation)
Sourced by ZipRecruiter
It services
10,000+ Employees
Sunnyvale, CA, US