
Substrate PAVC Engineer
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in Argentina.
• Assist with the monthly rollout of Windows security patches, which encompasses both official and prerelease updates, Defender updates, .NET updates, and associated security and compliance components.
• Utilize PowerShell scripts and automation to facilitate patch deployment, investigation, remediation, and reporting workflows.
• Employ KQL in Kusto to analyze deployment outcomes, detect patterns and failures, and oversee patch and vulnerability compliance.
• Diagnose unsuccessful Windows updates and MSU installations using Event Viewer, CBS and installer logs, error codes, and other diagnostic data.
• Determine installed patches and the operating system's status utilizing Get-HotFix, Get-WindowsPackage, DISM, Get-ComputerInfo, and Windows Update history.
• Create, validate, and publish patching components and packages while adhering to Safe Deployment Practices across various deployment rings and environments.
• Examine and resolve deployment delays caused by installation errors, machine conditions, capacity limitations, network problems, or environment-specific obstacles.
• Manage dashboards, monitoring, compliance reporting, and status updates for engineering, security, and compliance stakeholders.
• Collaborate with partner teams to address exceptions, blockers, manual interventions, and specific patching needs related to the environment.
• Practical experience with PowerShell scripting and automation, including PowerShell’s object-based pipeline and filtering techniques like Where-Object.
• Practical experience utilizing KQL to query and troubleshoot data in Kusto.
• Familiarity with Windows servicing and enterprise update methods, including Windows Update or Microsoft Update, WSUS, and manual MSU installation.
• Excellent troubleshooting capabilities concerning Windows updates, patch installations, and deployment failures.
• Proficiency in reviewing relevant logs, investigating error codes, and determining suitable next steps.
• Experience in identifying installed patches, packages, runtime versions, and operating system status using PowerShell, DISM, or similar tools.
• Strong communication abilities and capacity to collaborate with engineering, security, and compliance teams.
• Preferred: Familiarity with Azure DevOps build or deployment pipelines.
• Preferred: Experience with .NET tooling and identifying installed .NET Core runtimes.
• Preferred: Knowledge of Defender servicing and vulnerability scanning systems such as Qualys or AzSecPack.
• Preferred: Understanding of mapping CVEs to patch or vulnerability remediation workflows.
• Preferred: Awareness of Windows Server 2025 hotpatching, operating system baselines, STIGs, WinPE, or Safe Deployment Practices.
• Preferred: Experience in supporting patch compliance or troubleshooting within a large, distributed server environment.
• Medical, dental, and vision insurance.
• Flexible Spending Account (FSA).
• 401(k) retirement plan.
• Competitive paid time off.
• Parental leave.
• Opportunities for professional growth and development.
• Statutory benefits and additional payments mandated under Argentine law.
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.