About the Role:
We are seeking a Systems Engineer to own patch management, configuration automation, and vulnerability remediation across our Linux and Windows server and endpoint fleets. This role combines Puppet/Ansible-based automation for Linux OS patching and configuration enforcement with SCCM/Intune-based endpoint management and PowerShell-driven remediation on Windows, ensuring systems across both platforms stay compliant, secure, and up to date with minimal manual intervention.
Requirements:
Key Responsibilities — Linux (Puppet/Ansible)
- Manage end-to-end patch lifecycle (assessment, testing, staged rollout, validation) across RHEL servers.
- Develop, maintain, and version-control Puppet/Ansible modules and manifests for OS patching, software installation, and configuration enforcement.
- Design staged/canary patch rollout groups to minimize production risk.
- Automate software installation and configuration across environments to reduce manual provisioning.
- Troubleshoot patch failures, configuration drift, and Puppet/Ansible run errors across the fleet.
- Lead remediation of End-of-Life (EOL) / End-of-Support (EOS) operating systems and software — upgrading, re platforming, or migrating affected servers ahead of support cutoff dates.
- Execute EOL remediation plans in coordination with infrastructure and application owners, escalating and documenting formal risk acceptance only where remediation isn't feasible within the required timeline.
Key Responsibilities — Windows (SCCM / Intune / PowerShell)
- Manage and maintain endpoint security configurations using SCCM and Intune.
- Develop and implement PowerShell scripts to automate vulnerability remediation, security tasks, and processes.
- Create and manage imaging and task sequences in SCCM and Intune.
- Package and deploy patches on Windows servers and workstations based on a monthly schedule.
- Deploy collections in SCCM and push relevant missing patches to remediate vulnerabilities.
- Write PowerShell scripts to fix vulnerabilities based on testing on a few devices and implement them through Qualys or SCCM.
Shared Responsibilities — Vulnerability Management & Compliance
- Prioritize and remediate critical/high findings within SLA.
- Define and manage maintenance windows, rollback procedures, and exception/risk-acceptance workflows for unpatchable systems.
- Collaborate with security and application teams to align patch cadence with compliance requirements (CIS Benchmarks, STIG, PCI, etc.).
- Document processes, runbooks, and standard operating procedures for patch, configuration, and remediation management.
Required Qualifications — Linux
- Minimum 3+ years of Linux systems administration experience (RHEL).
- Hands-on experience with Puppet/Ansible (manifests, modules, Hiera, PuppetDB, r10k or similar control-repo workflow).
- Experience with package management (yum/dnf, apt).
- Hands-on experience remediating EOL/EOS operating systems and software — performing OS upgrades, migrations, or replat forming to bring systems back into supported status.
Required Qualifications — Windows
- Proven experience in vulnerability management and security operations.
- Strong knowledge of Qualys, SCCM, and Intune.
- Experience with imaging and task sequencing in SCCM and Intune.
Required Qualifications — Shared
- Scripting proficiency in Bash and/or Python, and proficiency in PowerShell scripting.
- Excellent analytical and problem-solving skills, with strong communication and teamwork abilities.
Preferred Qualifications
- Experience with patch orchestration tools (Red Hat Satellite, Spacewalk, or equivalent).
- Familiarity with vulnerability management/scanning tools (Qualys or similar).
- Understanding of CIS Benchmarks, STIG, or other security hardening standards.
- Experience with Git-based version control and CI/CD pipelines (Jenkins, GitLab CI, or similar).
- Red Hat Certified System Administrator (RHCSA) or higher; Puppet/Ansible Certified Professional.
- Experience in a regulated industry (financial services, healthcare) with formal exception/risk-acceptance processes.
- Experience running EOL remediation projects at scale (e.g., fleet-wide OS version upgrades, distro migrations) in coordination with cross-functional teams.
- Familiarity with Ansible or other configuration management tools as a secondary skill.
- Experience building compliance dashboards (Grafana, Splunk, or similar).
Education
- Bachelor’s degree in computer science, IT, or related field — or equivalent practical experience.
#LI- Onsite #LI-SS1