
Substrate PAVC Engineer
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Colombia.
• Assist with the monthly rollout of Windows security patches, which includes both official and prerelease updates, Defender updates, .NET updates, as well as associated security and compliance components.
• Utilize PowerShell scripts and automation to facilitate patch deployment, investigation, remediation, and reporting workflows.
• Employ KQL in Kusto to analyze deployment outcomes, detect patterns and failures, and monitor compliance related to patches and vulnerabilities.
• Diagnose failed Windows updates and MSU installations by utilizing Event Viewer, CBS logs, installer logs, error codes, and other diagnostic data.
• Identify installed patches and assess operating system status using tools like Get-HotFix, Get-WindowsPackage, DISM, Get-ComputerInfo, and Windows Update history.
• Develop, validate, and publish patching components and packages in accordance with Safe Deployment Practices across various deployment rings and environments.
• Investigate and resolve deployment delays caused by installation issues, machine states, capacity limitations, network problems, or environment-specific obstacles.
• Maintain dashboards, monitoring systems, compliance reports, and status updates for stakeholders in engineering, security, and compliance.
• Collaborate with partner teams to address exceptions, blockers, manual interventions, and specific patching needs related to the environment.
• Provide support for a Microsoft engagement through Blueprint, anticipated to last for 18 months.
• Practical experience with PowerShell scripting and automation, including knowledge of PowerShell’s object-based pipeline and filtering techniques such as Where-Object.
• Proven experience using KQL to query and troubleshoot data within Kusto.
• Familiarity with Windows servicing and enterprise update methods, including Windows Update or Microsoft Update, WSUS, and manual MSU installations.
• Strong troubleshooting capabilities related to Windows updates, patch installations, and deployment failures.
• Ability to review pertinent logs, investigate error codes, and determine the appropriate subsequent actions.
• Experience in identifying installed patches, packages, runtime versions, and operating system status using PowerShell, DISM, or similar tools.
• Excellent communication skills and the ability to work collaboratively with engineering, security, and compliance teams.
• Preferred: experience with Azure DevOps build or deployment pipelines.
• Preferred: background in .NET tooling and recognizing installed .NET Core runtimes.
• Preferred: knowledge of Defender servicing and vulnerability scanning systems such as Qualys or AzSecPack.
• Preferred: understanding of mapping CVEs to patch or vulnerability remediation processes.
• Preferred: knowledge of Windows Server 2025 hotpatching, operating system baselines, STIGs, WinPE, or Safe Deployment Practices.
• Preferred: experience supporting patch compliance or troubleshooting in a large, distributed server environment.
• Medical, dental, and vision coverage.
• Flexible Spending Account (FSA).
• 401(k) retirement plan.
• Competitive paid time off.
• Parental leave.
• Opportunities for professional growth and development.
• Statutory benefits and additional payments mandated by Colombian law.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.