Systems Engineer
Celtic Bank
Apply to this jobCeltic Bank is seeking a Systems Patch Engineer to manage and optimize our enterprise patch management program. This role focuses on operating system and third-party application patching across Windows, Linux, and macOS environments using Tanium.
The Systems Patch Engineer will design, implement, and maintain reliable patch deployment processes; administer Tanium policies and deployment rings; remediate vulnerabilities; and help ensure compliance with applicable IT, security, and regulatory standards. The ideal candidate combines strong Tanium expertise with practical experience in vulnerability remediation, endpoint management, automation, and cross-functional collaboration.
Essential Job Functions
- Administer, configure, and maintain the Tanium platform, including patch modules, action groups, endpoint client health, and patch policy configuration.
- Plan, schedule, and deploy operating system and third-party application patches across all Windows, Linux, and macOS systems using Tanium.
- Design, implement, and maintain patch deployment rings, maintenance windows, and blackout periods that balance risk reduction with business availability.
- Monitor, investigate, and remediate failed or missing patch deployments, partnering with Cybersecurity, Infrastructure, and application owners as needed.
- Tune and refine patch policies to reduce deployment failures and end-user disruption while maintaining timely remediation of critical and high-severity vulnerabilities.
- Track and report patch compliance metrics and SLA attainment for all in-scope systems to IT and security leadership.
- Develop and maintain technical documentation, including patch configurations, operational procedures, and runbooks.
- Collaborate with cross-functional teams to evaluate, recommend, and deploy new technologies that enhance patch and vulnerability management capabilities.
- Provide tier 2/3 support for escalated issues related to Tanium, patch deployment, and endpoint remediation.
- Participate in audits, risk assessments, and remediation activities related to patch and vulnerability management controls.
- Support change management, incident response, and disaster recovery processes for in-scope systems.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field, or equivalent combination of education and experience.
- 3–5 years of hands-on experience administering enterprise IT systems, with a focus on patch and vulnerability management.
- Demonstrated experience administering Tanium, including the Patch, Deploy, and Comply modules, action groups, and endpoint client health management.
- Working knowledge of vulnerability management and remediation practices, including CVE/CVSS prioritization, patch testing, and compliance reporting.
- Proficiency patching Windows Server and desktop operating systems, Linux distributions, and common third-party applications.
- Familiarity with PowerShell and Bash for automation, reporting, and administration of patching workflows.
- Understanding of information security principles, data classification, and regulatory requirements applicable to financial institutions (e.g., GLBA, FFIEC, ISO 27001).
- Strong analytical, troubleshooting, and documentation skills.
- Ability to communicate technical concepts clearly to both technical and non-technical audiences.
Benefits
- Medical, dental, vision
- 401(k) with employer match
- Life and long-term disability coverage
- HSA and FSA plans
- Holidays and paid time off requests
- Robust wellness program (we’re talking catered meals three times a week, lunch and learns, and onsite gym!)
Headquartered in the heart of downtown Salt Lake City, Utah, Celtic Bank was named a top SBA lender in the nation in 2025! Celtic Bank is a leading nationwide lender specializing in SBA 7(a), SBA 504, USDA B&I, express loans, asset-based loans, commercial real estate loans and commercial construction loans.
Celtic Bank is an equal opportunity employer and complies with all applicable federal, state and local fair employment practices laws.
Physical and Other Requirements
This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. The demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
- Stationary Work: The employee is frequently required to stand; walk; use hands to type, handle documents, and perform other office related duties. Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
- Mobility: The employee in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.
- Communicate: The employee is regularly required to talk or hear and will frequently communicate with others. Must be able to read, write and understand fluent English.
- Work Model: The employee in this position will work either a fully Onsite or Hybrid work model. All employees, regardless of location, may be required to travel to the Salt Lake City office for mandatory company meetings, events, or related occasions.
- Utah-based employees: Hybrid work schedule available after initial training period in our Salt Lake City, Utah office – department and job requirements will determine eligibility.
Summary
Manage enterprise patch deployment, optimize vulnerability management, and support IT security.
Job title
Systems Engineer
Experience level
3-5 years
Minimum experience
3+ years exp
Industry
finance
Location requirements
Salt Lake City, US, hybrid/onsite work allowed
Salary
Not specified
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Salt Lake City, UT, USA