About the group:
Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about accepting digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the constantly evolving needs of the digital era. Our broad approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to own the business in a secure environment.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Role: Patch Service Lead
Location: Toronto , ON
ROLE SUMMARY
The Linux Patching Tower Lead (Onshore) is the primary Linux interface to client L2/L3 and application owners during Canada hours. This role owns the end-to-end Linux patch lifecycle across a 63,000+ node estate of RHEL, Oracle Linux, and Ubuntu systems — driving Ansible/AAP and Red Hat Satellite-based patch execution, kernel errata management, EOL/EOS tracking, and compliance reporting while coordinating application-owner sign-off and weekend change windows.
ROLE IN THE OPERATING MODEL
▸ Tower/pod lead and SME for Linux patching — primary Linux interface to client L2/L3 and application owners during Canada hours and weekend windows
▸ Owns Linux tower compliance reporting to the Patch Service Lead
▸ Coordinates app-owner sign-off post-patching; manages escalation to client Linux L2/L3 within agreed SLTs
▸ Operates as Linux execution layer under client direction; baseline/image engineering remains client L2/L3 owned
KEY RESPONSIBILITIES
▸ Plan and execute OS patch cycles for RHEL, Oracle Linux, and Ubuntu via Ansible/AAP, Red Hat Satellite, and YUM/DNF
▸ Manage kernel updates, errata and package updates, live patching where applicable, and reboot orchestration with service validation
▸ Run pre-flight readiness checks — disk space, repository connectivity, snapshot/backup validation — and execute Dev→Prod wave progression
▸ Track kernel currency, CVE backlog, and EOL/EOS posture; maintain compliance and update CMDB
▸ Coordinate application-owner sign-off and change-window adherence; manage Tenable/Qualys compliance tracking
▸ Perform first-level remediation, RCA, and rollback (package downgrade/snapshot revert); maintain KEDB
▸ Own Linux tower compliance reporting and present KPIs to the Patch Service Lead for governance reviews
▸ Coordinate with client NOC during weekend change windows; escalate to Linux L2/L3 within agreed SLTs
TECHNICAL ACTIVITIES FOR THE SCOPE
▸ Execute OS patch cycles for RHEL, Oracle Linux, and Ubuntu via Ansible/AAP, Red Hat Satellite, and YUM/DNF
▸ Manage kernel and errata updates, live patching where applicable, and service-validated reboot orchestration
▸ Run pre-flight readiness (disk, repo connectivity, snapshots/backups) and wave execution Dev→Prod
▸ Track kernel currency, CVE backlog, and EOL/EOS; update CMDB compliance posture
▸ Perform RCA and rollback — package downgrade or snapshot revert; maintain KEDB entries
▸ Author and submit RFC/CAB documentation for Linux patch waves; coordinate maintenance window scheduling
▸ Generate Linux tower compliance reports for cycle governance; coordinate app-owner sign-off
SKILLS, TOOLS & COMPETENCIES
Primary Skills
OS Expertise RHEL 7/8/9, Oracle Linux, Ubuntu LTS, Kernel/errata management, systemd, YUM/DNF
Patch Tools Ansible/Ansible Automation Platform (AAP), Red Hat Satellite (Foreman/Spacewalk), YUM/DNF, Live patching (kpatch)
Automation Ansible playbook authoring, Bash/Shell scripting, Python scripting, Cron/at scheduling
ITSM & Vuln ServiceNow (Change/CMDB), Tenable, Qualys, RFC/CAB lifecycle, KEDB management
Observability Splunk, Dynatrace, Moogsoft, PagerDuty
Secondary Skills
▸ Container/host patching awareness and configuration management (Ansible roles, Puppet/Chef awareness)
▸ Cloud Linux fundamentals — Azure Linux VMs, AWS EC2 (RHEL/Ubuntu)
▸ Shell and Python scripting for patch automation
CERTIFICATIONS
Mandatory
▸ ITIL 4 Foundation
Preferred (one or more)
▸ Red Hat Certified Engineer (RHCE) or Red Hat Certified System Administrator (RHCSA) — mandatory preference
▸ Red Hat Certified Specialist in Ansible Automation (EX407/EX374)
▸ Red Hat Certified Specialist in Satellite/Patch Management — strong plus
▸ Oracle Linux or CompTIA Linux+ acceptable
NICE TO HAVE
▸ Experience patching large Linux estates (30,000+ nodes) using Satellite/Foreman
▸ Live kernel patching (kpatch/ksplice) operational experience
▸ Financial services Linux patching experience with regulatory compliance requirements
WORK MODEL & COMMITMENT
Hours Canada business hours + weekend change window coverage
Shift Model Hybrid onshore; scheduled maintenance and weekend patch windows
On-Call Yes — weekend patch cycles and zero-day CVE response
Language English (mandatory)
Compensation: We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in US without requiring employer sponsorship, now or at any time in the future.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Über Cognizant
Cognizant (NASDAQ: CTSH) i ist ein Technologiedienstleister und Entwickler von KI-Lösungen. Wir schlagen die Brücke zwischen KI-Investitionen und echtem unternehmerischem Mehrwert, indem wir ganzheitliche Full-Stack-KI-Lösungen für unsere Kunden entwickeln. Mit unserer fundierten Branchen-, Prozess- und Engineering-Expertise integrieren wir die spezifischen Anforderungen von Unternehmen passgenau in Technologiesysteme. So entfalten wir das menschliche Potenzial, erzielen greifbare Ergebnisse und sichern globalen Unternehmen in einer sich rasant wandelnden Welt den entscheidenden Vorsprung. Erfahren Sie mehr unter cognizant.ai oder @cognizant.
Zusätzliche Informationen zur Beschäftigung
Die Vergütungsinformationen sind zum Zeitpunkt der Veröffentlichung dieser Stellenausschreibung korrekt. Cognizant behält sich das Recht vor, diese Informationen jederzeit unter Beachtung der geltenden gesetzlichen Bestimmungen zu ändern.
Bewerberinnen und Bewerber können verpflichtet sein, an Vorstellungsgesprächen persönlich oder per Videokonferenz teilzunehmen. Darüber hinaus kann es erforderlich sein, bei jedem Gespräch einen gültigen staatlichen Lichtbildausweis vorzulegen.
Cognizant ist ein Arbeitgeber mit Chancengleichheit. Ihre Bewerbung und Kandidatur werden nicht aufgrund von Rasse, Hautfarbe, Geschlecht, Religion, Glaubensbekenntnis, sexueller Orientierung, Geschlechtsidentität, nationaler Herkunft, Behinderung, genetischen Informationen, Schwangerschaft, Veteranenstatus oder sonstiger durch bundes‑, landes‑ oder kommunalrechtliche Vorschriften geschützter Merkmale berücksichtigt oder abgelehnt.







