Locuz
Website:
locuz.com
Job details:
Patch Management Lead
Exp : 6+ Yrs
Level : L3
Location : Hyderabad
US Shift Timings: 5:30PM to 2:30AM
Job Summary:
The Patch Management Lead will own enterprise patch management operations, including patch planning, prioritization, deployment governance, maintenance-window coordination, patch compliance reporting, and remediation alignment with vulnerability management.
The role requires strong hands-on and leadership experience with Tanium, Automox-to-Tanium transition, Tenable, Rapid7, TruOps, CrowdStrike, SentinelOne, CyberArk, Okta, and related infrastructure/security platforms. Tanium Patch is positioned for patching and monitoring patch status across Windows, Linux, and Mac environments, while Rapid7 InsightVM and Tenable One Vulnerability Management provide vulnerability context for remediation prioritization.
OPERATIONAL RESPONSIBILITIES
- Lead enterprise patch management operations across Windows, Linux, macOS, servers, workstations, and endpoint environments.
- Own patch planning, prioritization, deployment schedules, maintenance windows, change coordination, and patch compliance reporting.
- Manage and support transition from Automox to Tanium, including process alignment, operational handover, reporting changes, and patch workflow stabilization.
- Use vulnerability data from Tenable and Rapid7 to prioritize high-risk patching activities.
- Coordinate with endpoint, infrastructure, application, IAM, and business teams to plan patch deployments with minimal operational disruption.
- Track critical and high-risk patches, zero-day response items, emergency patching, and out-of-band patch requirements.
- Review patch success/failure reports, troubleshoot deployment gaps, and drive remediation for failed or pending patches.
- Use Tanium dashboards and reporting to monitor patch applicability, deployment status, reboot status, and compliance.
- Coordinate with CyberArk and Okta teams where patching activities affect privileged access, identity services, access controls, or administrative accounts.
- Work with endpoint security teams using CrowdStrike and SentinelOne to understand endpoint health and risk exposure.
- Track risk acceptance and patch exceptions using TruOps or Cyberfusion-related workflows.
- Define patch management SOPs, runbooks, maintenance-window calendars, escalation paths, and reporting templates.
- Lead patch review meetings, stakeholder updates, and client-facing operational calls during USA hours.
- Mentor engineers and review patch execution quality, documentation, reporting, and escalation handling.
- Track risk acceptance and patch exceptions using TruOps or Cyberfusion-related workflows.
- Define patch management SOPs, runbooks, maintenance-window calendars, escalation paths, and reporting templates.
- Lead patch review meetings, stakeholder updates, and client-facing operational calls during USA hours.
- Mentor engineers and review patch execution quality, documentation, reporting, and escalation handling.
Experience:
- 6-10 years in infrastructure operations, endpoint management, patch management, vulnerability remediation, or cybersecurity operations.
- At least 2 years in a lead or senior engineer role.
- Experience with enterprise patching tools, change management, and US client-support model preferred.
Tools & Technologies:
- Primary Patch Tool: Tanium,Tanium
- VM Input Tools: Tenable, Rapid7
- Endpoint Security: CrowdStrike, SentinelOne
- Risk / GRC: TruOps, Cyberfusion
- Identity / PAM: Okta, CyberArk
- Other: ITSM/ticketing tools, Excel, dashboards, reporting platforms
Certifications: ITIL Foundation, Security+, Microsoft/Azure certifications, Tanium certification, CEH, CySA+, or equivalent.
please share your CV to annapurna.t@locuz.com
Click on Apply to know more.