Job Role: Senior Network Patch Management Engineer
Location: Cary NC or Jacksonville FL (Onsite)
Type: Fulltime
ROLE SUMMARY
The L2 Senior Network Patch Management Engineer owns the firmware and software lifecycle across a multi-vendor network estate (LAN, WAN, data centre fabrics, firewalls, load balancers, and wireless). Responsibilities include risk assessment, automated patching workflows, vulnerability-led prioritization, and cross-team co-ordination for zero-disruption maintenance. The role serves as an escalation point for L1 and leads continuous improvement of network patching practices.
KEY RESPONSIBILITIES
- Manage the firmware / software lifecycle for routers, switches, firewalls, load balancers, and wireless controllers across multi-vendor environments (Cisco, Juniper, Aruba, Palo Alto, F5, Fortinet).
- Assess vendor advisories (Cisco PSIRT, Juniper JSA, Palo Alto Security Advisories) and map CVEs to required upgrades; priorities based on business impact and CVSS score.
- Develop and maintain device-specific patching runbooks including pre-check scripts, upgrade procedures, rollback steps, and post-validation checks.
- Automate network patch workflows using Ansible, Netmiko, NAPALM, or vendor APIs (Cisco NSO / DNA Centre).
- Lead maintenance window planning: impact analysis, rollback testing, stakeholder communication, and CAB submission.
- Oversee configuration backup integrity (RANCID / Oxidised / Cisco NSO) before every patching activity.
- Conduct structured rollback for failed upgrades; perform root cause analysis and document findings.
- Integrate network vulnerability data from Qualys / Tenable into the patch prioritisation workflow.
- Monitor network stability post-patching using NMS/IPAM tools (SolarWinds, NetBrain, Infoblox).
- Act as L2 escalation for L1 patch-related issues and routing/connectivity incidents.
- Produce patch compliance reports and present to network management and security teams.
- Drive patching SLA adherence: Critical vulnerabilities within 72 hours, High within 14 days.
TECHNICAL SKILLS & KNOWLEDGE
- Expert-level CLI skills: Cisco IOS / IOS-XE / NX-OS, Juniper JunOS, Aruba AOS, Palo Alto PAN-OS.
- Deep understanding of network protocols: OSPF, BGP, EIGRP, MPLS, VRF, STP, HSRP/VRRP.
- Experience with automated patching toolchains: Ansible, Netmiko, NAPALM, Python (Paramiko).
- Vendor firmware lifecycle knowledge including feature releases, maintenance releases, and ED/MD trains (Cisco SMU, Juniper package management).
- Firewall firmware management: Palo Alto, Fortinet FortiOS, Cisco ASA/FTD upgrade procedures.
- Load balancer firmware: F5 BIG-IP or Citrix ADC upgrade methodology.
- Network management platforms: Cisco DNA Centre, SolarWinds NPM/NCM, NetBrain, Infoblox.
- Vulnerability management: parsing Cisco PSIRT, Juniper JSA, and NVD CVE data.
- ITSM integration: ServiceNow change management, CMDB for network asset tracking.
- SD-WAN patching exposure (Cisco Viptela, VMware VeloCloud) is advantageous.
SOFT SKILLS & COMPETENCIES
- Strong risk assessment skills: balances urgency with network stability.
- Excellent planning skills for complex, multi-device maintenance windows.
- Clear communicator with NOC, application, and security teams.
- Methodical documentation detailed runbooks, RCAs, and change records.
- Proactive stays current with vendor EOL/EOS notices and security advisories.
PREFERRED CERTIFICATIONS
- Cisco Certified Network Professional (CCNP Enterprise or Security)
- Juniper Networks Certified Professional (JNCIP-ENT or JNCIP-SEC)
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- CompTIA Security+ or CySA+
- ITIL 4 Foundation or Managing Professional
Disclaimer
HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to for investigation.
Compensation and Benefits
A candidate s pay within the range will depend on their work location, skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.