
Substrate PAVC Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Peru.
• Assist with the monthly rollout of Windows security patches, which include both official and prerelease updates, Defender updates, .NET updates, and associated security and compliance elements.
• Utilize PowerShell scripts and automation techniques to facilitate patch deployment, investigation, remediation, and reporting processes.
• Employ KQL in Kusto to analyze deployment outcomes, detect patterns and failures, and oversee patch and vulnerability compliance.
• Diagnose unsuccessful Windows updates and MSU installations by using Event Viewer, CBS, installer logs, error codes, and other diagnostic tools.
• Determine installed patches and operating system status through Get-HotFix, Get-WindowsPackage, DISM, Get-ComputerInfo, and Windows Update history.
• Construct, validate, and distribute patching components and packages while adhering to Safe Deployment Practices across various deployment rings and environments.
• Investigate and resolve deployment delays caused by installation errors, machine conditions, capacity limitations, network problems, or environment-specific obstacles.
• Maintain dashboards, monitoring systems, compliance reports, and status updates for engineering, security, and compliance stakeholders.
• Collaborate with partner teams to address exceptions, obstacles, manual interventions, and environment-specific patching needs.
• Practical experience with PowerShell scripting and automation, including PowerShell’s object-based pipeline and filtering techniques such as Where-Object.
• Practical experience with KQL for querying and troubleshooting data in Kusto.
• Familiarity with Windows servicing and enterprise update methodologies, including Windows Update or Microsoft Update, WSUS, and manual MSU installations.
• Strong troubleshooting capabilities concerning Windows updates, patch installations, and deployment issues.
• Ability to analyze relevant logs, investigate error codes, and determine the appropriate next steps.
• Experience in identifying installed patches, packages, runtime versions, and operating system status using PowerShell, DISM, or similar tools.
• Excellent communication skills and the ability to collaborate effectively with engineering, security, and compliance teams.
• Preferred: experience with Azure DevOps build or deployment pipelines.
• Preferred: experience with .NET tooling and identifying installed .NET Core runtimes.
• Preferred: familiarity with Defender servicing and vulnerability scanning systems such as Qualys or AzSecPack.
• Preferred: familiarity with mapping CVEs to patch or vulnerability remediation processes.
• Preferred: understanding of Windows Server 2025 hotpatching, operating system baselines, STIGs, WinPE, or Safe Deployment Practices.
• Preferred: experience in supporting patch compliance or troubleshooting in a large, distributed server environment.
• Engagement is expected to span 18 months.
• Medical, dental, and vision coverage.
• Flexible Spending Account (FSA).
• 401(k) retirement plan.
• Competitive paid time off.
• Parental leave.
• Opportunities for professional growth and development.
• Statutory benefits and additional payments as required by Peruvian law.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.