
Substrate PAVC Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Ecuador.
• Assist with the monthly rollout of Windows security patches, encompassing both official and prerelease updates, Microsoft Defender updates, .NET updates, and associated security and compliance components.
• Utilize PowerShell scripts and automation to facilitate patch deployment, investigation, remediation, and reporting processes.
• Employ KQL in Kusto to analyze deployment outcomes, detect patterns and failures, and track patch and vulnerability compliance.
• Diagnose issues with failed Windows updates and MSU installations by leveraging Event Viewer, CBS and installer logs, error codes, and other diagnostic data.
• Recognize installed patches and assess operating system status using Get-HotFix, Get-WindowsPackage, DISM, Get-ComputerInfo, and Windows Update history.
• Create, validate, and distribute patching components and packages while adhering to Safe Deployment Practices across various deployment rings and environments.
• Investigate and resolve deployment delays caused by installation errors, machine conditions, capacity limitations, network challenges, or environment-specific obstacles.
• Maintain dashboards, monitoring systems, compliance reports, and status updates for engineering, security, and compliance stakeholders.
• Collaborate with partner teams to address exceptions, blockers, manual interventions, and environment-specific patching requirements.
• Proficient in PowerShell scripting and automation, including PowerShell’s object-based pipeline and filtering techniques like Where-Object.
• Hands-on experience with KQL to query and troubleshoot information in Kusto.
• Familiarity with Windows servicing and enterprise update methodologies, including Windows Update or Microsoft Update, WSUS, and manual MSU installations.
• Strong diagnostic skills related to Windows updates, patch installations, and deployment issues.
• Capability to review relevant logs, investigate error codes, and identify appropriate next steps.
• Experience in identifying installed patches, packages, runtime versions, and operating system status using PowerShell, DISM, or similar tools.
• Excellent communication skills with the ability to work collaboratively with engineering, security, and compliance teams.
• Preferred: experience with Azure DevOps build or deployment pipelines.
• Preferred: experience with .NET tooling and recognizing installed .NET Core runtimes.
• Preferred: knowledge of Defender servicing and vulnerability scanning systems such as Qualys or AzSecPack.
• Preferred: awareness of mapping CVEs to patch or vulnerability remediation workflows.
• Preferred: understanding of Windows Server 2025 hotpatching, operating system baselines, STIGs, WinPE, or Safe Deployment Practices.
• Preferred: experience in supporting patch compliance or troubleshooting within a large, distributed server environment.
• Medical, dental, and vision coverage
• Flexible Spending Account (FSA)
• 401(k) retirement plan
• Competitive paid time off
• Parental leave
• Professional growth and development opportunities
• Statutory benefits and additional payments mandated by Ecuadorian law
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.