Windows Vulnerability Remediation Engineer
About The Client:
Client is a leading digital transformation solutions provider and IT services company with over 30,000 employees across 30+ countries. Headquartered in Aliso Viejo, California, it helps Fortune 500 and Global 1000 clients with digital, cloud, AI, cybersecurity, and engineering services.
About The Job:
- We are seeking a highly skilled Windows Vulnerability Remediation Engineer to join our Cybersecurity and Infrastructure team.
- In this role, you will be responsible for identifying, analyzing, prioritizing, remediating, and validating security vulnerabilities across enterprise Windows server environments.
- You will work closely with Infrastructure, Security Operations, Endpoint Management, and Application teams to ensure timely remediation of vulnerabilities while maintaining system stability, compliance, and business continuity.
- The ideal candidate will have strong expertise in Windows Server administration, enterprise patch management, vulnerability management platforms, PowerShell automation, and Microsoft security technologies.
Essential Job Functions
Vulnerability Management
- Analyze and remediate vulnerabilities identified through Qualys, Tanium, Microsoft Defender Vulnerability Management (MDVM), or similar vulnerability assessment tools.
-
Prioritize remediation activities based on:
- CVSS Scores
- Exploitability
- Threat Intelligence
- Business Criticality
- Validate vulnerability findings and identify false positives.
- Coordinate with application and infrastructure teams to drive remediation through closure.
- Manage vulnerability exceptions and document risk acceptance where required.
Windows Patch Management
-
Manage patching and remediation across:
- Windows Server 2012 / 2016 / 2019 / 2022
- VMware ESXi Hosts
-
Perform:
- Monthly Patch Tuesday Deployments
- Emergency and Out-of-Band Patching
- Zero-Day Vulnerability Remediation
- Patch Testing and Validation
- Rollback Planning and Execution
- Troubleshoot failed patch deployments and ensure successful remediation.
- Maintain enterprise patch compliance within defined SLAs.
Security Hardening
-
Implement and maintain Windows security configurations aligned with:
- CIS Benchmarks
- Microsoft Security Baselines
-
Perform security hardening activities including:
- Registry Configuration
- Windows Services Optimization
- Local Security Policies
- Protocol Hardening
- Authentication Security Improvements
Vulnerability Remediation
-
Remediate security issues including:
- Missing Microsoft Security Updates
- Unsupported or End-of-Life Software
- TLS/SSL Weak Cipher and Protocol Issues
- SMBv1 Removal and SMB Security Updates
- NTLM Hardening
- Remote Code Execution (RCE) Vulnerabilities
- Privilege Escalation Vulnerabilities
- Registry Misconfigurations
- Windows Authentication Weaknesses
- Configuration Drift
Automation & Scripting
-
Develop PowerShell scripts to automate:
- Patch Deployment
- Vulnerability Remediation
- Compliance Reporting
- System Validation
- Leverage Tanium automation capabilities where applicable.
- Continuously improve remediation efficiency through automation.
Reporting & Compliance
-
Generate dashboards and reports for:
- Patch Compliance
- Vulnerability Aging
- SLA Adherence
- Executive Security Metrics
- Risk Reduction Trends
- Track remediation progress and ensure adherence to security SLAs.
- Support internal and external security audits.
- Maintain remediation documentation and evidence for compliance requirements.
Incident & Security Response
- Support cybersecurity incident response activities.
- Participate in zero-day vulnerability assessments and emergency remediation efforts.
- Assist with vulnerability investigations and security assessments.
- Collaborate with Security Operations during active incidents.
Qualifications:
Required Technical Skills
Operating Systems
- Windows Server 2012, 2016, 2019, 2022
- VMware ESXi
Microsoft Technologies
- Active Directory
- Group Policy (GPO)
- DNS
- DHCP
- IIS
- Failover Clustering
- Hyper-V
- PowerShell
Vulnerability Management
- Qualys
- Tanium
- Microsoft Defender Vulnerability Management (MDVM)
Patch Management
- WSUS
- Azure Update Manager
- Microsoft Endpoint Configuration Manager (MECM/SCCM) (Preferred)
Scripting & Automation
- PowerShell
- Windows Automation
- Tanium Automation (Preferred)
Required Qualifications
- 5–10+ years of experience in Windows Infrastructure, Patch Management, or Vulnerability Remediation.
- Hands-on experience managing enterprise Windows Server environments.
- Strong knowledge of Microsoft security updates, Windows internals, and vulnerability remediation practices.
- Experience implementing CIS Benchmarks and Microsoft Security Baselines.
- Solid understanding of enterprise vulnerability lifecycle management.
- Experience working in ITIL-based environments with change management processes.
How to Apply: Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit Jobs In India – VARITE.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions.
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.