Patch Management & Automation Consultant
Position Overview
MetroSys is seeking an experienced Patch Management & Automation Consultant to support a regional credit union organization in assessing, improving, and modernizing its enterprise patch management program.
The consultant will evaluate the client's existing patching processes, technology, policies, and compliance posture, with a primary focus on Microsoft SCCM / Microsoft Configuration Manager. The environment is predominantly Microsoft-based but also includes Linux systems and infrastructure supporting banking and security operations.
This is not strictly an SCCM administration position. The consultant will be expected to take a broader look at the organization's patch and vulnerability management lifecycle, identify gaps and manual processes, recommend best practices, and determine where automation and AI-assisted capabilities can improve efficiency, visibility, compliance, and risk reduction.
The initial engagement is expected to last approximately three months, with the potential for an extended engagement and/or permanent employment based on project needs.
Key Responsibilities
- Perform a comprehensive assessment of the organization's existing patch management program, including processes, policies, tools, workflows, reporting, and governance.
- Review the current SCCM / Microsoft Configuration Manager environment and evaluate its configuration, collections, deployment rings, maintenance windows, Software Update Groups, ADRs, compliance reporting, and overall effectiveness.
- Assess patching processes across a primarily Microsoft environment, while also reviewing requirements and processes for Linux and other supported infrastructure.
- Review the existing asset and system inventory and determine whether all applicable infrastructure is properly incorporated into patch management and compliance reporting.
- Identify gaps in patch coverage, automation, testing, deployment, exception management, remediation, and reporting.
- Evaluate opportunities to automate manual patch-management activities, including patch identification, prioritization, testing, approvals, deployments, compliance validation, remediation, and reporting.
- Identify practical opportunities to incorporate AI and AI-assisted operations into the patch and vulnerability management lifecycle without introducing unnecessary security or operational risk.
- Develop recommendations for improving patch prioritization based on vulnerability severity, exploitability, business criticality, and infrastructure risk.
- Review patching practices for systems supporting banking, security, and regulated workloads, considering applicable PCI and financial-services security requirements.
- Establish or improve patching standards, deployment rings, maintenance windows, emergency/zero-day patching procedures, rollback procedures, and exception-management processes.
- Develop dashboards, reports, and measurable KPIs for patch compliance, outstanding vulnerabilities, failed deployments, exceptions, and remediation timelines.
- Work with infrastructure, security, compliance, and business stakeholders to ensure patch-management processes align with organizational requirements.
- Recommend a future-state patch-management architecture and create a prioritized roadmap for remediation, automation, and modernization.
- Where appropriate, assist with implementing approved improvements during the initial engagement rather than limiting the project to assessment and recommendations.
- Provide documentation and knowledge transfer to internal IT and security teams.
Expected Initial Engagement
During the initial three-month engagement, the consultant will be expected to deliver:
- Current-State Assessment: Document the existing patch-management environment, processes, technologies, risks, and gaps.
- SCCM Health & Configuration Review: Evaluate the current SCCM patching architecture and identify configuration and operational improvements.
- Patch Coverage Assessment: Validate coverage across Microsoft, Linux, cloud, infrastructure, and other applicable systems.
- Risk & Compliance Gap Analysis: Identify patching practices that may create security, operational, PCI, or financial-services compliance concerns.
- Automation & AI Assessment: Identify manual activities that can be safely automated and practical areas where AI-assisted capabilities could provide value.
- Future-State Roadmap: Develop prioritized recommendations for improving patch management, including quick wins and longer-term initiatives.
- Implementation Support: Begin implementing approved improvements, automation, reporting, and process changes as time permits.
- Documentation & Knowledge Transfer: Establish repeatable processes that can be managed by the internal team after the engagement.
Required Qualifications
- 5+ years of experience supporting enterprise infrastructure, patch management, endpoint management, vulnerability management, or related disciplines.
- Strong hands-on experience with Microsoft SCCM / Microsoft Configuration Manager and enterprise software update management.
- Experience designing and managing patch deployment strategies, including testing groups, deployment rings, maintenance windows, automated deployment rules, and production rollouts.
- Strong understanding of Windows Server and Microsoft enterprise environments.
- Working knowledge of Linux patching and lifecycle management.
- Experience assessing existing IT environments and developing actionable remediation and modernization plans.
- Experience with scripting and automation technologies such as PowerShell, APIs, Power Automate, Azure Automation, or similar tools.
- Understanding of vulnerability management and risk-based patch prioritization.
- Experience producing patch-compliance reporting, dashboards, KPIs, and audit evidence.
- Strong understanding of change management, testing, rollback, exception management, and emergency patching procedures.
- Ability to communicate effectively with infrastructure engineers, security teams, compliance personnel, and IT leadership.
Preferred Qualifications
- Previous experience within a credit union, bank, financial institution, or other highly regulated environment.
- Understanding of PCI DSS and financial-services security and compliance requirements.
- Familiarity with Microsoft cloud technologies such as Azure, Intune, Entra ID, Azure Automation, and Microsoft security platforms.
- Experience integrating SCCM with vulnerability-management, ITSM, security, or reporting platforms.
- Experience implementing automation within infrastructure or security operations.
- Familiarity with AI-assisted IT operations, Microsoft Copilot capabilities, or the application of AI to vulnerability and patch-management workflows.
- Experience developing patch-management SOPs, governance standards, and audit-ready documentation.
- Consulting experience and the ability to independently lead discovery sessions, assessments, recommendations, and implementation activities.