Senior Systems Security Engineering RoleThis is a hands-on, automation-driven senior systems security engineering role responsible for planning, implementing, and driving enterprise technology infrastructure security posture and regulatory compliance readiness across Linux, Windows, cloud, on-prem, and hybrid environments. The engineer serves as a senior technical resource for enterprise infrastructure vulnerability management, overseeing the process from initial alert through remediation and closure verification. The role also develops and improves patch automation using scripting, configuration management, and orchestration, while continuously evaluating tools and processes to adapt to changes in the infrastructure and threat landscape. The engineer applies deep systems engineering and enterprise systems administration expertise to plan and execute security patches, and translates Cybersecurity policy requirements into implemented, auditable controls, establishing KPIs to measure and report progress against security risk remediation goals. The engineer also establishes and maintains Standard Operating Procedures (SOPs) and change management controls to ensure infrastructure security changes are consistently documented and traceable. This provides objective evidence for security and access control audits while maintaining continuous organizational audit readiness. This role serves as a key technical resource and liaison between Cybersecurity, IT business partners, Internal Audit, and Compliance/Quality functions, ensuring that security requirements are operationalized consistently and remediation work is tracked to closure with measurable outcomes.Your Contributions (include, but are not limited to):Security Automation and Vulnerability Management at ScaleLead complex infrastructure vulnerability remediation efforts and continuously improve the tools and automation used to detect, remediate, and verify security findings across Linux, Windows, cloud, network, and hybrid infrastructurePlan and implement security patches across enterprise Linux and Windows server environments, including patch testing, sequencing, rollback planning, and post patch validationLead and coordinate the enterprise vulnerability remediation program across cloud (AWS/Azure), on prem, and hybrid infrastructure, prioritizing based on risk severity, exploitability, and business impactDesign and implement a scalable patch management framework across AWS, Azure, and hybrid infrastructure including Linux and Windows servers, network devices, and platform services, reducing reliance on manual, one-off remediation effortsApply enterprise systems administration expertise (OS hardening, configuration management, service dependencies) to assess patch impact and minimize disruption to production systemsPartner with Cybersecurity to translate vulnerability scan findings and audit action items into clear, actionable remediation plans with committed timelines and ownersExtend vulnerability management support to the application layer, partnering with Business teams and application owners to identify, prioritize, and drive remediation of application vulnerabilities alongside infrastructure remediation effortsAdminister and enhance the organization's automation platforms, including AWS Systems Manager (SSM) Patch Manager, and integrate them with other automation and orchestration tools to scale vulnerability detection, patching, remediation tracking, and closure verification across AWS, Azure, and hybrid environmentsDevelop and maintain KPIs and reporting mechanisms (e.g., patch compliance rate, mean time to remediate, aging of open findings, risk trend over time) to measure and communicate progress of security risk remediation efforts to leadership and governance forumsCoordinate remediation activities across Technology Infrastructure, Network Engineering, Cloud Engineering, and Scientific Systems teams to ensure consistent execution and minimal disruption to operationsContinuously identify opportunities to shift from reactive, one-off patching toward standardized, repeatable, and automated remediation processesChange Management, SOPs, and Audit ReadinessEstablish and maintain security vulnerability management SOPs, work instructions, and documentation standards for infrastructure security changes to ensure consistent, compliant execution across all systemsImplement, maintain and monitor controls designed to ensure infrastructure security changes (network, cloud, compute, storage, identity, and security configuration) are documented, approved, and traceable end to endBuild and maintain a long-term remediation evidence repository (change records, approvals, exceptions, risk acceptance artifacts, testing/validation artifacts, access reviews) that supports objective evidence for internal and external auditsPartner with Quality/Compliance and Cybersecurity to ensure change management and access control processes meet applicable regulatory requirements (e.g., GxP, SOX, data integrity) and industry frameworksLead or support periodic access reviews, control self-assessments, and audit response activities, ensuring evidence is complete, current, and readily retrievableIdentify and close gaps between current operational practices and documented SOPs; drive continuous improvement of change and compliance processes as environments evolveServe as a key point of contact during internal and external audits related to security and access controls, coordinating evidence gathering and responses across infrastructure teamsCross-Functional Collaboration and GovernanceServe as a senior technical liaison among Cybersecurity, Enterprise Technology Infrastructure, and IT business partners to translate security and compliance requirements into practical technical controls while supporting clear ownership, accountability, and operational executionProvide technical input on cybersecurity policies and controls, assessing whether requirements are proportionate to business risk, technically sustainable at scale, and balanced against user experience and operational efficiency. Recommend practical, risk-based alternatives where controls introduce unnecessary friction or complexityParticipate in architecture and change advisory reviews to ensure security and compliance requirements are addressed early in design rather than retrofitted after implementationSupport the definition of RACI models and outcome-based security requirements so that policy ownership (Cyber) and implementation ownership (Infrastructure) remain clearContribute to the enterprise system security control baseline, including closing or formally risk accepting legacy assessment action itemsMentor and provide guidance to engineers on secure configuration standards, patching best practices, and documentation disciplineOther duties as assignedRequirements:Bachelor's degree in computer science, Information Technology, Systems Engineering, or a related technical field and 4+ years of relevant systems engineering or systems administration experience, ORMaster's degree in computer science/engineering or a related technical field and 2+ years of experience as listed above, OR8+ years of a relevant combination of technical education, certifications, training and systems engineering experienceRelevant experience should include enterprise Linux and/or Windows server environments and security patching, vulnerability remediation, automation, or IT compliance. Demonstrated hands-on experience administering and patching enterprise systems and developing automation for patch deployment or remediation (scripting or configuration management tooling) is requiredRelevant certifications such as CISSP, CISM, CompTIA Security+, RHCE, Microsoft Certified: Windows Server, or ITIL Foundation are preferred but not requiredHands-on technical expertise planning and implementing security patches in both Linux and Windows enterprise server environments, including patch testing, staging, deployment sequencing, and rollback proceduresDemonstrated experience working as a Systems Engineer or Systems Administrator, with strong working knowledge of enterprise system administration: OS configuration, hardening, service and dependency management, and performance/stability considerations during patch cyclesStrong understanding of the vulnerability management lifecycle: identification, prioritization, remediation, and verification across AWS, Azure, and hybrid infrastructureWorking knowledge of application-layer vulnerability management sufficient to partner effectively with Business teams and application owners on remediation prioritization and timelines, complementing infrastructure-focused remediation workExperience with cloud and hybrid patch/automation tooling particularly AWS Systems Manager (SSM) Patch Manager and Azure equivalents alongside Windows (e.g., WSUS, SCCM/Intune) and Linux (e.g., package management, Ansible, Satellite/Landscape or equivalent) tooling and network devicesDemonstrated experience administering and continuously improving automation platforms such as AWS Systems Manager (SSM) Patch Manager integrated with other automation and orchestration tools (scripting in Python/Bash/PowerShell, configuration management tools) to scale vulnerability management, patching, and remediation across AWS, Azure, and hybrid server fleetsWorking knowledge of change management frameworks (ITIL or similar) and experience operating within ITSM platforms such as ServiceNowFamiliarity with regulatory and compliance frameworks relevant to a regulated environment (e.g., GxP, SOX, data integrity requirements, 21 CFR Part 11 concepts) and their translation into technical and procedural controlsExperience developing SOPs, work instructions, and audit-ready documentation for technology operationsUnderstanding of identity and access management principles, access certification processes, and least privilege conceptsFamiliarity with cloud and network security tooling (e.g., Cisco Catalyst Center, vulnerability scanners, cloud security posture management tools)Ability to define measurable KPIs and turn remediation data into clear progress reporting for technical and leadership audiencesExperience supporting or leading audit response activities, including evidence collection and remediation trackingStrong organizational and documentation discipline, with attention to
Apply Now