Patch Management & Automation Consultant

Posted Yesterday
Be an Early Applicant
Phoenix, AZ, USA
In-Office
Senior level
Information Technology
The Role
Assess and modernize an enterprise patch-management program centered on Microsoft SCCM. Evaluate patching processes, coverage, compliance, vulnerability prioritization, automation, AI-assisted operations, reporting, and governance across Microsoft, Linux, cloud, and regulated infrastructure. Develop a future-state architecture and remediation roadmap, establish standards and KPIs, support approved implementations, and provide documentation and knowledge transfer to internal IT and security teams.
Summary Generated by Built In
Position Overview

MetroSys is seeking an experienced Patch Management & Automation Consultant to support a regional credit union organization in assessing, improving, and modernizing its enterprise patch management program.

The consultant will evaluate the client's existing patching processes, technology, policies, and compliance posture, with a primary focus on Microsoft SCCM / Microsoft Configuration Manager. The environment is predominantly Microsoft-based but also includes Linux systems and infrastructure supporting banking and security operations.

This is not strictly an SCCM administration position. The consultant will be expected to take a broader look at the organization's patch and vulnerability management lifecycle, identify gaps and manual processes, recommend best practices, and determine where automation and AI-assisted capabilities can improve efficiency, visibility, compliance, and risk reduction.

The initial engagement is expected to last approximately three months, with the potential for an extended engagement and/or permanent employment based on project needs.

Key Responsibilities
  • Perform a comprehensive assessment of the organization's existing patch management program, including processes, policies, tools, workflows, reporting, and governance.
  • Review the current SCCM / Microsoft Configuration Manager environment and evaluate its configuration, collections, deployment rings, maintenance windows, Software Update Groups, ADRs, compliance reporting, and overall effectiveness.
  • Assess patching processes across a primarily Microsoft environment, while also reviewing requirements and processes for Linux and other supported infrastructure.
  • Review the existing asset and system inventory and determine whether all applicable infrastructure is properly incorporated into patch management and compliance reporting.
  • Identify gaps in patch coverage, automation, testing, deployment, exception management, remediation, and reporting.
  • Evaluate opportunities to automate manual patch-management activities, including patch identification, prioritization, testing, approvals, deployments, compliance validation, remediation, and reporting.
  • Identify practical opportunities to incorporate AI and AI-assisted operations into the patch and vulnerability management lifecycle without introducing unnecessary security or operational risk.
  • Develop recommendations for improving patch prioritization based on vulnerability severity, exploitability, business criticality, and infrastructure risk.
  • Review patching practices for systems supporting banking, security, and regulated workloads, considering applicable PCI and financial-services security requirements.
  • Establish or improve patching standards, deployment rings, maintenance windows, emergency/zero-day patching procedures, rollback procedures, and exception-management processes.
  • Develop dashboards, reports, and measurable KPIs for patch compliance, outstanding vulnerabilities, failed deployments, exceptions, and remediation timelines.
  • Work with infrastructure, security, compliance, and business stakeholders to ensure patch-management processes align with organizational requirements.
  • Recommend a future-state patch-management architecture and create a prioritized roadmap for remediation, automation, and modernization.
  • Where appropriate, assist with implementing approved improvements during the initial engagement rather than limiting the project to assessment and recommendations.
  • Provide documentation and knowledge transfer to internal IT and security teams.
Expected Initial Engagement

During the initial three-month engagement, the consultant will be expected to deliver:

  • Current-State Assessment: Document the existing patch-management environment, processes, technologies, risks, and gaps.
  • SCCM Health & Configuration Review: Evaluate the current SCCM patching architecture and identify configuration and operational improvements.
  • Patch Coverage Assessment: Validate coverage across Microsoft, Linux, cloud, infrastructure, and other applicable systems.
  • Risk & Compliance Gap Analysis: Identify patching practices that may create security, operational, PCI, or financial-services compliance concerns.
  • Automation & AI Assessment: Identify manual activities that can be safely automated and practical areas where AI-assisted capabilities could provide value.
  • Future-State Roadmap: Develop prioritized recommendations for improving patch management, including quick wins and longer-term initiatives.
  • Implementation Support: Begin implementing approved improvements, automation, reporting, and process changes as time permits.
  • Documentation & Knowledge Transfer: Establish repeatable processes that can be managed by the internal team after the engagement.
Required Qualifications
  • 5+ years of experience supporting enterprise infrastructure, patch management, endpoint management, vulnerability management, or related disciplines.
  • Strong hands-on experience with Microsoft SCCM / Microsoft Configuration Manager and enterprise software update management.
  • Experience designing and managing patch deployment strategies, including testing groups, deployment rings, maintenance windows, automated deployment rules, and production rollouts.
  • Strong understanding of Windows Server and Microsoft enterprise environments.
  • Working knowledge of Linux patching and lifecycle management.
  • Experience assessing existing IT environments and developing actionable remediation and modernization plans.
  • Experience with scripting and automation technologies such as PowerShell, APIs, Power Automate, Azure Automation, or similar tools.
  • Understanding of vulnerability management and risk-based patch prioritization.
  • Experience producing patch-compliance reporting, dashboards, KPIs, and audit evidence.
  • Strong understanding of change management, testing, rollback, exception management, and emergency patching procedures.
  • Ability to communicate effectively with infrastructure engineers, security teams, compliance personnel, and IT leadership.
Preferred Qualifications
  • Previous experience within a credit union, bank, financial institution, or other highly regulated environment.
  • Understanding of PCI DSS and financial-services security and compliance requirements.
  • Familiarity with Microsoft cloud technologies such as Azure, Intune, Entra ID, Azure Automation, and Microsoft security platforms.
  • Experience integrating SCCM with vulnerability-management, ITSM, security, or reporting platforms.
  • Experience implementing automation within infrastructure or security operations.
  • Familiarity with AI-assisted IT operations, Microsoft Copilot capabilities, or the application of AI to vulnerability and patch-management workflows.
  • Experience developing patch-management SOPs, governance standards, and audit-ready documentation.
  • Consulting experience and the ability to independently lead discovery sessions, assessments, recommendations, and implementation activities.

Skills Required

  • 5+ years of experience supporting enterprise infrastructure, patch management, endpoint management, vulnerability management, or related disciplines.
  • Strong hands-on experience with Microsoft SCCM or Microsoft Configuration Manager and enterprise software update management.
  • Experience designing and managing patch deployment strategies, including testing groups, deployment rings, maintenance windows, automated deployment rules, and production rollouts.
  • Strong understanding of Windows Server and Microsoft enterprise environments.
  • Working knowledge of Linux patching and lifecycle management.
  • Experience assessing IT environments and developing actionable remediation and modernization plans.
  • Experience with scripting and automation technologies such as PowerShell, APIs, Power Automate, Azure Automation, or similar tools.
  • Understanding of vulnerability management and risk-based patch prioritization.
  • Experience producing patch-compliance reporting, dashboards, KPIs, and audit evidence.
  • Strong understanding of change management, testing, rollback, exception management, and emergency patching procedures.
  • Ability to communicate effectively with infrastructure engineers, security teams, compliance personnel, and IT leadership.
  • Experience in a credit union, bank, financial institution, or other highly regulated environment.
  • Understanding of PCI DSS and financial-services security and compliance requirements.
  • Familiarity with Azure, Intune, Entra ID, Azure Automation, and Microsoft security platforms.
  • Experience integrating SCCM with vulnerability-management, ITSM, security, or reporting platforms.
  • Experience implementing automation within infrastructure or security operations.
  • Familiarity with AI-assisted IT operations, Microsoft Copilot, or applying AI to vulnerability and patch-management workflows.
  • Experience developing patch-management SOPs, governance standards, and audit-ready documentation.
  • Consulting experience and ability to independently lead discovery sessions, assessments, recommendations, and implementation activities.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Diego, CA
Year Founded: 2006

What We Do

MetroSys is a I.T. Professional Services company based in sunny San Diego, CA. Established in 2006, MetroSys has technical talent supporting the Americas. Our Mission Statement; To simplify our customers’ business solutions while having fun with what we do. Our creative geniuses have been pioneering data solutions for our valued customers and partners in the following areas: Data Mobility: Enterprise Storage, Cloud Migrations, Systems Integration & Installation: Storage, Networking, Virtualization, Database, Messaging Flexible Workforce: Recruiting, Staffing, Direct Placement Assessment Services: Storage, Networking, Performance, Periodic, Get Healthy ingenuity. Agility. Speed. These are key ingredients to our success. Navigating the world of I.T. Professional Services can pose many challenges. We help customers, channel partners, resellers & manufacturers deliver! Our team of highly experienced professionals can help bridge any gap for your I.T. requirements. Whether assistance with pre-sales or post-sales services, recruiting, or assisting with the launch of emerging technologies, We CAN Help! Great people. Great Company. MetroSys has carefully crafted its team of highly skilled talent by not only hiring industry experts, but by selecting people that share our view on company culture. Our core values include teamwork, integrity, accountability, & embracing diversity. Our customer first approach builds strong relationships as a trusted advisor and technology partner. Our team integrates with your business and maximizes efficiency. Simply put, we make it easy.

Similar Jobs

Achieve Logo Achieve

Solutions Engineer

Fintech • Professional Services • Sales • Financial Services
Hybrid
Tempe, AZ, USA
2231 Employees

Achieve Logo Achieve

Functional ERP Engineer

Fintech • Professional Services • Sales • Financial Services
Hybrid
Tempe, AZ, USA
2231 Employees

Wipfli Logo Wipfli

Director - Transaction Advisory Services

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
142K-212K Annually

Wipfli Logo Wipfli

Audit Manager, Technology Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
97K-145K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account