Patch & Security Engineer
Location: Detroit, MI
Pay Rate: $50–$52/hour
Work Arrangement: Onsite
Contract position
Position Overview
We are seeking an experienced Patch & Security Engineer to support cybersecurity and system reliability across operational technology (OT) environments. This role will be responsible for planning, coordinating, executing, and validating patching activities across critical OT infrastructure, including control systems, PI environments, servers, and workstations.
The ideal candidate understands the unique challenges of securing industrial environments where cybersecurity, system availability, and operational continuity must all be carefully balanced. This position will work closely with IT, cybersecurity, engineering, operations, site leadership, and technology vendors to ensure systems remain secure, compliant, and operational.
Key Responsibilities
Patch Planning & Coordination
- Develop and coordinate patching schedules across OT environments.
- Partner with engineering, operations, cybersecurity, IT, and site leadership to plan maintenance activities.
- Coordinate patching activities around production requirements and approved maintenance windows.
- Obtain appropriate approvals and communicate patching plans, risks, and expected impacts before execution.
System Assessment & Patch Evaluation
- Identify applicable security patches and updates for OT systems, servers, and workstations.
- Evaluate patches for system compatibility, cybersecurity impact, and operational risk.
- Review system configurations and perform vulnerability or compliance scans to determine patching requirements.
- Assess potential impacts to control systems and critical infrastructure before deployment.
Patch Deployment & Execution
- Execute approved patching activities across servers, workstations, and applicable OT infrastructure.
- Place systems into maintenance mode when required and follow established deployment procedures.
- Apply security updates in accordance with approved change-management processes.
- Troubleshoot patching issues and coordinate with appropriate technical resources when problems arise.
System Validation & Recovery
- Verify system functionality following patch installation.
- Conduct post-patch validation to confirm systems have returned to a fully operational state.
- Perform follow-up vulnerability and compliance scans.
- Support recovery and remediation activities when patching results in unexpected system behavior.
- Escalate critical issues and coordinate corrective actions with engineering, IT, cybersecurity, and vendors.
Compliance & Documentation
- Maintain accurate patching records, checklists, change documentation, and validation results.
- Ensure patching activities align with applicable cybersecurity policies, standards, and compliance requirements.
- Maintain documentation necessary to support audits and cybersecurity assessments.
- Track outstanding patches, exceptions, remediation activities, and system status.
Asset & Lifecycle Support
- Support system upgrades, operating system updates, and antivirus/endpoint security updates.
- Assist with backup verification and recovery activities before and after maintenance.
- Help maintain accurate asset and system information related to OT infrastructure.
- Support lifecycle activities for servers, workstations, and other connected OT assets.
Cross-Functional Collaboration
- Work closely with IT, cybersecurity, engineering, operations, and site teams.
- Coordinate with third-party vendors and system integrators as needed.
- Support planned outages, maintenance windows, and system recovery activities.
- Communicate technical information and patching impacts clearly to both technical and non-technical stakeholders.
Required Qualifications & Skills
- Experience supporting OT/industrial control environments, preferably involving DCS, SCADA, PI, or similar systems.
- Hands-on experience with patch management and deployment tools.
- Understanding of cybersecurity principles, vulnerability management, and system hardening.
- Experience evaluating patches and assessing operational or compatibility risks.
- Ability to work within formal change-management and maintenance processes.
- Strong troubleshooting and problem-solving skills.
- Strong written and verbal communication skills.
- Excellent documentation and organizational skills.
- Ability to coordinate work across multiple technical and operational teams.
Preferred Qualifications
- Experience working in manufacturing, industrial, energy, automotive, or other critical infrastructure environments.
- Experience with PI infrastructure, DCS, SCADA, or industrial servers/workstations.
- Familiarity with vulnerability scanning and remediation processes.
- Knowledge of OT cybersecurity frameworks, standards, and best practices.
- Experience supporting antivirus/endpoint security solutions in OT environments.
- Experience working with vendors and third-party system integrators.
Key Success Metrics
Success in this role will be measured by:
- Timely patch deployment within established cybersecurity and compliance windows.
- Minimal operational disruption during patching and maintenance activities.
- Successful post-patch validation and system recovery.
- Accurate and complete documentation of patching activities.
- Audit readiness and compliance with cybersecurity requirements.
- Effective communication and coordination across IT, cybersecurity, engineering, and operations teams.
Why This Role Matters
This role plays a critical part in protecting industrial systems from cybersecurity threats while maintaining the reliability and availability of the systems that keep operations running. The successful candidate will bring a security-focused mindset while understanding that OT environments require careful planning, controlled execution, and rigorous validation before, during, and after every change.