{"schemaVersion":"jobsearcher.job.v1","id":"2404d64122a1ac6fbd456b0c","url":"https://jobsearcher.com/jobs/2404d64122a1ac6fbd456b0c","canonicalUrl":"https://jobsearcher.com/jobs/2404d64122a1ac6fbd456b0c","title":"Network Infrastructure Patch Management Engineer","description":"Network Patching SpecialistExpert-level CLI skills: Cisco IOS / IOS-XE / NX-OS, Juniper JunOS, Aruba AOS, Palo Alto PAN-OS.Deep understanding of network protocols: OSPF, BGP, EIGRP, MPLS, VRF, STP, HSRP/VRRP.Experience with automated patching toolchains: Ansible, Netmiko, NAPALM, Python (Paramiko).Vendor firmware lifecycle knowledge including feature releases, maintenance releases, and ED/MD trains (Cisco SMU, Juniper package management).Firewall firmware management: Palo Alto, Fortinet FortiOS, Cisco ASA/FTD upgrade procedures.Load balancer firmware: F5 BIG-IP or Citrix ADC upgrade methodology.Network management platforms: Cisco DNA Centre, SolarWinds NPM/NCM, NetBrain, Infoblox.Vulnerability management: parsing Cisco PSIRT, Juniper JSA, and NVD CVE integration: ServiceNow change management, CMDB for network asset tracking.Strong risk assessment skills: balances urgency with network stability.Excellent planning skills for complex, multi-device maintenance windows.Strong verbal and written communication skills.Methodical documentation – detailed runbooks, RCAs, and change records.Proactive – stays current with vendor EOL/EOS notices and security advisories.Manage the firmware / software lifecycle for routers, switches, firewalls, load balancers, and wireless controllers across multi-vendor environments (Cisco, Juniper, Aruba, Palo Alto, F5, Fortinet).Assess vendor advisories (Cisco PSIRT, Juniper JSA, Palo Alto Security Advisories) and map CVEs to required upgrades; prioritise based on business impact and CVSS score.Develop and maintain device-specific patching runbooks including pre-check scripts, upgrade procedures, rollback steps, and post-validation checks.Automate network patch workflows using Ansible, Netmiko, NAPALM, or vendor APIs (Cisco NSO / DNA Centre).Lead maintenance window planning: impact analysis, rollback testing, stakeholder communication, and CAB submission.Oversee configuration backup integrity (RANCID / Oxidised / Cisco NSO) before every patching activity.Conduct structured rollback for failed upgrades; perform root cause analysis and document findings.Integrate network vulnerability data from Qualys / Tenable into the patch prioritisation workflow.Monitor network stability post-patching using NMS/IPAM tools (SolarWinds, NetBrain, Infoblox).Act as L2 escalation for L1 patch-related issues and routing/connectivity incidents.Produce patch compliance reports and present to network management and security teams.Drive patching SLA adherence: Critical vulnerabilities within 72 hours, High within 14 days.SD-WAN patching exposure (Cisco Viptela, VMware VeloCloud) is advantageous.Cisco IOS.IOS-XE.NX-OS.Juniper JunOS.Aruba AOS.Palo Alto PAN-OS.OSPF.BGP.EIGRP.MPLS.VRF.STP.HSRP/VRRP.Ansible.Netmiko.NAPALM.Python.Paramiko.Cisco SMU.Fortinet FortiOS.Cisco ASA/FTD.F5 BIG-IP.Citrix ADC.Cisco DNA Centre.SolarWinds NPM/NCM.NetBrain.Infoblox.ServiceNow.CMDB.Cisco Certified Network Professional (CCNP Enterprise or Security).Juniper Networks Certified Professional (JNCIP-Client or JNCIP-SEC).Palo Alto Networks Certified Network Security Engineer (PCNSE).CompTIA Security+ or CySA+.ITIL 4 Foundation or Managing Professional.","company":"Cynet Systems","rawCompany":"cynet systems","city":"Cary","state":"NC","isRemote":false,"isActive":false,"createdAt":"2026-09-11T03:19:24.272Z","occupations":[{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1231.00","title":"Computer Network Support Specialists","slug":"computer-network-support-specialists"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541513","title":"Computer Facilities Management Services","slug":"computer-facilities-management-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Network Infrastructure Patch Management Engineer","description":"Network Patching SpecialistExpert-level CLI skills: Cisco IOS / IOS-XE / NX-OS, Juniper JunOS, Aruba AOS, Palo Alto PAN-OS.Deep understanding of network protocols: OSPF, BGP, EIGRP, MPLS, VRF, STP, HSRP/VRRP.Experience with automated patching toolchains: Ansible, Netmiko, NAPALM, Python (Paramiko).Vendor firmware lifecycle knowledge including feature releases, maintenance releases, and ED/MD trains (Cisco SMU, Juniper package management).Firewall firmware management: Palo Alto, Fortinet FortiOS, Cisco ASA/FTD upgrade procedures.Load balancer firmware: F5 BIG-IP or Citrix ADC upgrade methodology.Network management platforms: Cisco DNA Centre, SolarWinds NPM/NCM, NetBrain, Infoblox.Vulnerability management: parsing Cisco PSIRT, Juniper JSA, and NVD CVE integration: ServiceNow change management, CMDB for network asset tracking.Strong risk assessment skills: balances urgency with network stability.Excellent planning skills for complex, multi-device maintenance windows.Strong verbal and written communication skills.Methodical documentation – detailed runbooks, RCAs, and change records.Proactive – stays current with vendor EOL/EOS notices and security advisories.Manage the firmware / software lifecycle for routers, switches, firewalls, load balancers, and wireless controllers across multi-vendor environments (Cisco, Juniper, Aruba, Palo Alto, F5, Fortinet).Assess vendor advisories (Cisco PSIRT, Juniper JSA, Palo Alto Security Advisories) and map CVEs to required upgrades; prioritise based on business impact and CVSS score.Develop and maintain device-specific patching runbooks including pre-check scripts, upgrade procedures, rollback steps, and post-validation checks.Automate network patch workflows using Ansible, Netmiko, NAPALM, or vendor APIs (Cisco NSO / DNA Centre).Lead maintenance window planning: impact analysis, rollback testing, stakeholder communication, and CAB submission.Oversee configuration backup integrity (RANCID / Oxidised / Cisco NSO) before every patching activity.Conduct structured rollback for failed upgrades; perform root cause analysis and document findings.Integrate network vulnerability data from Qualys / Tenable into the patch prioritisation workflow.Monitor network stability post-patching using NMS/IPAM tools (SolarWinds, NetBrain, Infoblox).Act as L2 escalation for L1 patch-related issues and routing/connectivity incidents.Produce patch compliance reports and present to network management and security teams.Drive patching SLA adherence: Critical vulnerabilities within 72 hours, High within 14 days.SD-WAN patching exposure (Cisco Viptela, VMware VeloCloud) is advantageous.Cisco IOS.IOS-XE.NX-OS.Juniper JunOS.Aruba AOS.Palo Alto PAN-OS.OSPF.BGP.EIGRP.MPLS.VRF.STP.HSRP/VRRP.Ansible.Netmiko.NAPALM.Python.Paramiko.Cisco SMU.Fortinet FortiOS.Cisco ASA/FTD.F5 BIG-IP.Citrix ADC.Cisco DNA Centre.SolarWinds NPM/NCM.NetBrain.Infoblox.ServiceNow.CMDB.Cisco Certified Network Professional (CCNP Enterprise or Security).Juniper Networks Certified Professional (JNCIP-Client or JNCIP-SEC).Palo Alto Networks Certified Network Security Engineer (PCNSE).CompTIA Security+ or CySA+.ITIL 4 Foundation or Managing Professional.","datePosted":"2026-09-11T03:19:24.272Z","dateModified":"2026-09-11T03:19:24.272Z","hiringOrganization":{"@type":"Organization","name":"Cynet Systems","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Cary","addressRegion":"NC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2404d64122a1ac6fbd456b0c"},"url":"https://jobsearcher.com/jobs/2404d64122a1ac6fbd456b0c"}}