1

Vulnerability Patch Management Engineer Jobs (NOW HIRING)

Security Officer

Scottsdale, AZ · On-site

$16.25 - $19.25/hr

Patch Management Engineer Location : Scottsdale, AZ (Onsite) Contract End Client - Service Base ... Vulnerability Management : Conduct regular vulnerability assessments to identify and prioritize ...

New

Engineer and maintain Windows and macOS workstation configurations * Support device provisioning ... Management & Security * Develop and maintain endpoint patching processes * Support vulnerability ...

New

next page

Showing results 1-20

Vulnerability Patch Management Engineer information

See salary details

$39K

$101.8K

$137.5K

How much do vulnerability patch management engineer jobs pay per year?

As of Jun 5, 2026, the average yearly pay for vulnerability patch management engineer in the United States is $101,752.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Patch Management Engineer, and why are they important?

To thrive as a Vulnerability Patch Management Engineer, you need expertise in IT security, OS and network administration, and a solid understanding of vulnerability assessment processes, often supported by a degree in computer science or related certifications like CompTIA Security+ or CISSP. Familiarity with patch management tools (e.g., Ivanti, SCCM, WSUS), vulnerability scanners (e.g., Nessus, Qualys), and ticketing systems is typically required. Strong analytical skills, attention to detail, and effective communication help coordinate remediation efforts and minimize business disruptions. These skills ensure rapid identification and mitigation of security risks, reducing the organization's exposure to cyber threats.

What are some typical challenges a Vulnerability Patch Management Engineer faces when coordinating patch deployments across multiple departments?

A common challenge for Vulnerability Patch Management Engineers is balancing timely patch deployment with minimizing disruption to business operations. Coordinating with various departments often means navigating different schedules, system dependencies, and risk tolerances. Effective communication and planning are essential, as engineers must align patch cycles with maintenance windows and ensure all stakeholders understand the importance of timely updates. Additionally, there can be technical hurdles with legacy systems or incompatible software, requiring creative problem-solving and sometimes custom remediation strategies.

What is a Vulnerability Patch Management Engineer?

A Vulnerability Patch Management Engineer is a cybersecurity professional responsible for identifying, prioritizing, and applying software patches and updates to address security vulnerabilities within an organization's systems. They work to ensure that all IT assets are protected against known threats by regularly assessing vulnerabilities, testing patches, and coordinating with other teams to deploy updates efficiently. Their role is critical in minimizing the risk of cyberattacks and maintaining compliance with security standards. Additionally, they often document patching processes and provide reports on the status of vulnerabilities and remediation efforts.

What is the difference between Vulnerability Patch Management Engineer vs Security Analyst?

AspectVulnerability Patch Management EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, or equivalentCompTIA Security+, CISSP, or equivalent
Work EnvironmentFocus on patch deployment, vulnerability remediation, and system updatesMonitor security threats, analyze incidents, and develop security strategies
Employer & Industry UsageIT departments, cybersecurity firms, large enterprisesIT security teams, government agencies, financial institutions

While both roles require security certifications and work within cybersecurity environments, the Vulnerability Patch Management Engineer primarily handles patch deployment and vulnerability remediation, whereas the Security Analyst focuses on threat monitoring and incident analysis. The roles complement each other in maintaining organizational security.

Infographic showing various Vulnerability Patch Management Engineer job openings in the United States as of May 2026, with employment types broken down into 100% Full Time. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $101,752 per year, or $48.9 per hour.

$88K - $117K/yr

Full-time

Posted 13 days ago


Job description

At ERCOT, our diverse and dynamic work environment provides a platform on which employees can work together to build the future of the Texas power grid and wholesale market utilizing the latest technologies and resources. We encourage you to join our talented, dedicated workforce to develop world-class solutions for today and tomorrow's energy challenges while learning new skills and growing your career.
ERCOT is committed to fostering inclusion at all levels of our company. It is the cornerstone of our corporate values of accountability, leadership, innovation, trust, and expertise. We know that individuals with a wide variety of talents, ideas, and experiences propel the innovation that drives our success. An inclusive and diverse workforce strengthens us and allows for a collaborative environment to solve the challenges that face our industry today and in the future.
JOB SUMMARY
Governs patch management processes and improve reporting efficiency through independent oversight and planning for the defined set of onboarded CI types within the Patch Management scope. Responsible for the content, publication, communication, and clarification of Patch Management standards, policies, procedures, Knowledge-Base Articles (KBAs) and related SharePoint resources. Servers at the point of contact for internal and external questionnaires and regulatory queries related to Patch Management.
JOB DUTIES
  • Understands and applies principles, theories and concepts related to the profession and ERCOT's culture.
  • Exercises judgment within defined procedures and practices to determine appropriate action.
  • Impact is generally limited to specific assignments or projects.
  • May respond to inquiries and/or provide assistance and/or guidance to lower level workers.

ADDITIONAL JOB DUTIES
  • Serves as a subject matter expert (SME) for Patch Management processes and procedures, maintaining its accuracy, completeness and integrity.
  • Develops and maintains patch management policies, procedures, and schedules that align with security requirements and minimize operational impact.
  • Leads the onboarding, updating and decommissioning of Patch Management CIs.
  • Leads the planning, monitoring and deployment of security patches and updates to servers, workstations, and applications.
  • Facilitates and collaborates with Cybersecurity and other IT organizations to evaluate vulnerabilities, prioritize remediation efforts, and ensure timely patching of critical systems.
  • Generates comprehensive dashboards and reports on patch compliance, system status, and vulnerabilities, and communicate findings to stakeholders.
  • Provides guidance and mentorship to other team members on patch management with best practices and tools.
  • Ensures all patching activities comply with organizational security policies, industry standards, and relevant regulations.

EXPERIENCE
  • Requires minimum 5 years job related work experience in excess of degree requirements
  • Requires minimum 5 years progressively responsible experience in an IT role, cybersecurity with a focus on patch management and configuration management
  • Experience with vulnerability scanning tools and security frameworks
  • Exposure to Service Now Vulnerability Management processes and data model
  • Exposure to OpenText CMDB (or similar) is required.
  • Strong analytical, problem-solving, and risk assessment skills
  • Ability to write SQL statements
  • ServiceNow uCMDB experience is a plus.
  • Proven ability to lead projects, mentor junior staff, and communicate technical information effectively to both technical and non-technical audiences.

EDUCATION
  • Bachelor's Degree: Business, Computer Science, Data Science, Information Systems or related field (Required)
  • or a combination of education and experience that provides equivalent knowledge to a major in such fields is required

CERTIFICATION
  • ITIL Foundation (Preferred)
  • CMDB Fundamentals (Preferred)
  • CompTIA Security+, ISC2 Certified in Cybersecurity (Bonus)

WORK LOCATION - Taylor, TX:
  • Employees will be required to be on-site in Taylor, TX at minimum 2 days per week, or more, as needed based on the business needs as determined by management
  • On-site schedules are flexible or may be rotated based on business needs as determined by the Manager
  • Remote work is required to be performed from your Texas residence.
  • Employees may opt to work on-site more than required or 100% of the time

The foregoing description reflects the minimum qualifications and the essential functions of the position that must be performed proficiently with or without reasonable accommodation for individuals with disabilities. It is not an exhaustive list of the duties expected to be performed, and management may, at its discretion, revise or require that other or different tasks be performed as assigned. This job description is not intended to create a contract of employment with ERCOT. Both ERCOT and the employee may exercise their employment-at-will rights at any time. #LI-DN
ERCOT is firmly committed to equal employment for all qualified persons without regard to race, sex, medical condition, religion, age, creed, national origin, citizenship status, marital status, sexual orientation, physical or mental disability, ancestry, veteran status, genetic information or any other protected category under federal, state or local law.
Expected Salary Range:
$120,000 - $165,000