We are seeking a Systems Engineer specializing in Windows Administration and Vulnerability & Patch Management to support a Server, Storage, and Database environment. This individual will play a leading role in the patch management of physical and virtual servers, as well as the identification, remediation, and ongoing management of security vulnerabilities.
The Systems Engineer will work closely with senior Server Administrators, Vulnerability & Patch Management (VPM) leadership, IT Security, and global technology teams to support VPM-related initiatives and projects. The ideal candidate will have strong technical expertise in Windows Administration, virtual infrastructure, server patching, vulnerability remediation, and security best practices.
The successful candidate must also be able to communicate complex technical issues, designs, and solutions clearly to both technical and non-technical audiences.
Key Responsibilities
Server Patching & Vulnerability Management
- Monitor and manage automated Windows server patching processes and coordinate troubleshooting with enterprise MECM engineering teams.
- Manage and test MECM/SCCM application packages in collaboration with application packaging and VPM teams.
- Identify and remediate software vulnerabilities across Windows and Linux servers through on-demand patching, software removal, or other remediation techniques.
- Develop and deploy Active Directory Group Policies to remediate vulnerabilities and strengthen the security posture of Windows servers.
- Harden third-party applications and services in accordance with security requirements and industry best practices.
- Monitor and report vulnerabilities across Server, Storage, and Database environments, including Windows, Linux/Unix, VMware hosts, appliances, and virtual machines.
- Coordinate and upscale vulnerability remediation efforts across local and global technology teams.
Vulnerability Detection & Monitoring
- Perform in-depth analysis of vulnerability and security data from tools such as Splunk and Qualys.
- Develop reconciliation processes between multiple vulnerability data sources and collaborate with enterprise teams to resolve discrepancies and remediation issues.
- Monitor vulnerability trends and proactively identify areas requiring remediation or additional security controls.
- Follow established policies, procedures, and best practices for vulnerability and patch management.
- Ensure systems are properly patched, configured, monitored, and maintained in accordance with security standards.
- Collaborate with local and global IT teams to accomplish short- and long-term technology and security objectives.
- Develop and manage project plans related to local server patching and vulnerability remediation processes.
- Participate throughout all phases of technology and security projects, including planning, testing, implementation, and post-implementation support.
- Work closely with senior Server Administrators, VPM leadership, IT Security, and other infrastructure teams.
- Take ownership of assigned projects and responsibilities through successful completion.
- Provide clear and timely updates regarding project status, issues, risks, and remediation activities to management and technical teams.
Required Qualifications
- Strong experience in Windows Server Administration in an enterprise environment.
- In-depth understanding of server patching, vulnerability management, system hardening, and security best practices.
- Experience working with enterprise vulnerability and patch management tools.
- Ability to independently troubleshoot complex infrastructure and security issues.
- Strong understanding of virtual infrastructure and server environments.
- Excellent written and verbal communication skills.
- Ability to translate complex technical concepts into clear, non-technical explanations.
- Strong organizational skills with the ability to manage multiple priorities and projects simultaneously.
- Self-starter who can work independently with minimal supervision and take full ownership of assigned responsibilities.
Preferred Technical Experience
- Senior-level Windows Server Administration
- MECM/SCCM
- Qualys
- Splunk
- Linux Administration, particularly RHEL and Linux package management tools
- VMware engineering and administration
- Networking and infrastructure administration concepts
- Scripting and automation
- Security vulnerability remediation and system hardening
- Active Directory and Group Policy
- Enterprise patch management processes
Required Soft Skills
- Excellent oral and written communication and documentation skills
- Strong organizational and coordination abilities
- Flexible and adaptable approach to changing priorities
- Ability to manage multiple projects and competing priorities
- Results-oriented with strong attention to detail
- Ability to work effectively in a dynamic, team-oriented environment
- Ability to communicate complex technical problems and designs to non-technical stakeholders
- Strong ownership, accountability, and follow-through
Ideal Candidate
The ideal candidate is a senior infrastructure professional with a strong Windows Administration background and hands-on experience in vulnerability and patch management. They should be comfortable working across Windows, Linux, VMware, security, and enterprise infrastructure environments while collaborating with both local and global teams.
The candidate should be proactive, technically capable, highly organized, and comfortable taking ownership of vulnerability remediation and patch management initiatives from identification through resolution.