
Substrate PAVC Engineer
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in Argentina.
β’ Assist in the monthly rollout of Windows security patches, which includes both official and prerelease updates, Defender updates, .NET updates, and associated security and compliance components.
β’ Utilize PowerShell scripts and automation tools to facilitate patch deployment, investigation, remediation, and reporting processes.
β’ Employ KQL in Kusto to analyze deployment results, detect patterns and failures, and oversee patch and vulnerability compliance.
β’ Diagnose issues related to failed Windows updates and MSU installations through Event Viewer, CBS and installer logs, error codes, and other diagnostic data.
β’ Determine installed patches and operating system status using Get-HotFix, Get-WindowsPackage, DISM, Get-ComputerInfo, and Windows Update history.
β’ Develop, validate, and distribute patching components and packages while adhering to Safe Deployment Practices across various deployment rings and environments.
β’ Investigate and resolve deployment delays caused by installation failures, machine states, capacity limitations, network challenges, or environment-specific obstacles.
β’ Maintain dashboards, monitoring systems, compliance reports, and status updates for engineering, security, and compliance stakeholders.
β’ Collaborate with partner teams to address exceptions, blockers, manual interventions, and environment-specific patching needs.
β’ Practical experience with PowerShell scripting and automation, including a solid understanding of PowerShellβs object-based pipeline and Where-Object filtering.
β’ Practical experience using KQL to query and troubleshoot data within Kusto.
β’ Knowledge of Windows servicing and enterprise update strategies, including Windows Update or Microsoft Update, WSUS, and manual MSU installations.
β’ Strong troubleshooting abilities related to Windows updates, patch installations, and deployment issues.
β’ Capability to review pertinent logs, investigate error codes, and establish suitable next steps.
β’ Experience in identifying installed patches, packages, runtime versions, and operating system status using PowerShell, DISM, or equivalent tools.
β’ Excellent communication skills and the ability to work collaboratively with engineering, security, and compliance teams.
β’ Preferred: experience with Azure DevOps build or deployment pipelines.
β’ Preferred: experience with .NET tooling and identifying installed .NET Core runtimes.
β’ Preferred: familiarity with Defender servicing and vulnerability scanning tools such as Qualys or AzSecPack.
β’ Preferred: knowledge of mapping CVEs to patch or vulnerability remediation workflows.
β’ Preferred: understanding of Windows Server 2025 hotpatching, operating system baselines, STIGs, WinPE, or Safe Deployment Practices.
β’ Preferred: experience in supporting patch compliance or troubleshooting in a large, distributed server environment.
β’ Medical, dental, and vision coverage.
β’ Flexible Spending Account (FSA).
β’ 401(k) retirement plan.
β’ Competitive paid time off.
β’ Parental leave.
β’ Opportunities for professional growth and development.
β’ Statutory benefits and additional payments as required by Brazilian law.
DigitalOcean
DigitalOcean
Meade
Get handpicked remote jobs straight to your inbox weekly.