Jobs and Careers
AM

Analyst, AACU Patch and Vulnerability Management

American Airlines
Fort Worth, United Statesfull_timeVerifiedPosted 8 Jul 2026

About the role

Intro

Are you ready to explore a world of possibilities, both at work and during your time off? Join our American Airlines family, and you’ll travel the world, grow your expertise and become the best version of you.  As you embark on a new journey, you’ll tackle challenges with flexibility and grace, learning new skills and advancing your career while having the time of your life.  Feel free to enrich both your personal and work life and hop on board!

Why you'll love this job

This job is within the American Airlines Credit Union.  It supports the patch and vulnerability management (PVM) processes across American Airlines Credit Union’s technology infrastructure. The role is responsible for performing patching activities, analyzing vulnerability data, and assisting in remediation efforts to ensure security, compliance, and operational continuity. Other responsibilities include overseeing the governance and compliance aspects of the Patch and Vulnerability Management (PVM) program, performing tracking, reporting, evaluation and escalation regarding the status of the PVM program, facilitating governance and steering committees, and prioritizing patch risks over time to ensure the organization's security posture remains robust and compliant with industry standards.

What you'll do

  • Execute patch deployment activities across servers, desktops, network devices, and other IT assets under the guidance of the PVM Manager
  • Collaborate with Information Security, Infrastructure, and Application teams to coordinate patching efforts based on risk assessments and criticality
  • Utilize patch management tools (e.g., Microsoft SCCM, WSUS, Ivanti, Tanium) to apply and verify patches in accordance with defined schedules
  • Use vulnerability scanning tools (e.g., Tenable Nessus, Qualys, Rapid7) to assist in identifying and assessing system vulnerabilities
  • Assist in analyzing scan results, tracking remediation progress, and escalating high-risk issues to the manager or relevant teams
  • Monitor and report on the status of the PVM program, including patch compliance metrics, vulnerability remediation timelines, and risk assessments
  • Develop and maintain dashboards and reports to provide visibility into the PVM program's effectiveness and areas for improvement
  • Facilitate governance and steering committee meetings related to vulnerability management, ensuring alignment with organizational objectives and regulatory requirements
  • Track aging vulnerabilities and coordinate with relevant teams to ensure timely remediation, escalating issues as necessary
  • Assist in developing and enforcing policies, standards, and procedures related to patch and vulnerability management
  • Stay informed about emerging threats, vulnerabilities, and regulatory changes that may impact the organization's security posture
  • Support audits and assessments by providing necessary documentation and evidence of compliance with security frameworks such as PCI, NCUA, FFIEC, and others
  • Help develop and maintain compliance reports and dashboards that monitor patch status and adherence to SLAs
  • Participate in planning and execution of maintenance windows and rollback testing
  • Document patching activities, exceptions, and remediation steps for audit and compliance purposes
  • Stay current on relevant threat intelligence, vendor patch releases, and industry best practices
  • Maintain awareness of regulatory standards (e.g., PCI, NCUA, FFIEC) related to patch and vulnerability management
  • Participate in continuous improvement initiatives to enhance automation, accuracy, and efficiency in patching workflows
  • Support after-hours patching and emergency response efforts as needed
  • Perform other duties as assigned
  • The selected candidate will be responsible for ensuring the security and confidentiality of all account and related information which is part of their work and for ensuring that his/her work is in compliance with all applicable laws and regulations including, but not limited to, the Bank Secrecy Act.

All you'll need for success

Minimum Qualifications- Education & Prior Job Experience

  • High school diploma or GED
  • Four or more years of technology work experience directly relevant to the listed duties; college coursework in Computer Science, Information Security or a related field may be considered to offset a portion of the required work experience
  • Hands-on experience with patch deployment and/or vulnerability management tools
  • Basic knowledge of operating systems (Windows/Linux) and networking concepts

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

American Airlines

View company profile →