About this role
Salary: £30,000 - 50,000 per year
Requirements: 3–6 years in network engineering / operationsB.Tech (Electronics & Communication / Computer Science) or equivalentExpert-level CLI skills: Cisco IOS / IOS-XE / NX-OS, Juniper JunOS, Aruba AOS, Palo Alto PAN-OSDeep understanding of network protocols: OSPF, BGP, EIGRP, MPLS, VRF, STP, HSRP/VRRPExperience with automated patching toolchains: Ansible, Netmiko, NAPALM, Python (Paramiko)Vendor firmware lifecycle knowledge including feature releases, maintenance releases, and ED/MD trains (Cisco SMU, Juniper package management)Firewall firmware management: Palo Alto, Fortinet FortiOS, Cisco ASA/FTD upgrade proceduresLoad balancer firmware: F5 BIG-IP or Citrix ADC upgrade methodologyNetwork management platforms: Cisco DNA Centre, SolarWinds NPM/NCM, NetBrain, InfobloxVulnerability management: parsing Cisco PSIRT, Juniper JSA, and NVD CVE dataITSM integration: ServiceNow change management, CMDB for network asset trackingSD-WAN patching exposure (Cisco Viptela, VMware VeloCloud) is advantageousStrong risk assessment skills: balances urgency with network stabilityExcellent planning skills for complex, multi-device maintenance windowsClear communicator with NOC, application, and security teamsMethodical documentation – detailed runbooks, RCAs, and change recordsProactive – stays current with vendor EOL/EOS notices and security advisoriesPreferred certifications: CCNP Enterprise or Security, JNCIP-ENT or JNCIP-SEC, PCNSE, CompTIA Security+ or CySA+, ITIL 4 Foundation or Managing Professional Responsibilities: Manage the firmware / software lifecycle for routers, switches, firewalls, load balancers, and wireless controllers across multi-vendor environments (Cisco, Juniper, Aruba, Palo Alto, F5, Fortinet)Assess vendor advisories (Cisco PSIRT, Juniper JSA, Palo Alto Security Advisories) and map CVEs to required upgrades; prioritise based on business impact and CVSS scoreDevelop and maintain device-specific patching runbooks including pre-check scripts, upgrade procedures, rollback steps, and post-validation checksAutomate network patch workflows using Ansible, Netmiko, NAPALM, or vendor APIs (Cisco NSO / DNA Centre)Lead maintenance window planning: impact analysis, rollback testing, stakeholder communication, and CAB submissionOversee configuration backup integrity (RANCID / Oxidised / Cisco NSO) before every patching activityConduct structured rollback for failed upgrades; perform root cause analysis and document findingsIntegrate network vulnerability data from Qualys / Tenable into the patch prioritisation workflowMonitor network stability post-patching using NMS/IPAM tools (SolarWinds, NetBrain, Infoblox)Act as L2 escalation for L1 patch-related issues and routing/connectivity incidentsProduce patch compliance reports and present to network management and security teamsDrive patching SLA adherence: Critical vulnerabilities within 72 hours, High within 14 days Technologies: AIAnsibleArubaCitrixCloudCMDBCiscoFirewallFirmwareITILITSMMPLSNetworkNPMNxPythonSecurityServiceNowVMwareWindowsiOSLANSpark More:
We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products. We are a globally recognized leader in the Tech and IT industry, with an idea-first attitude and a startup mindset that shapes how we work. The role is for a Senior Network Patch Management Engineer based in London / Birmingham, working 5 days in the office on a fixed-term contract.
last updated 34 week of 2026