We are seeking a Systems Engineer to own patch management, configuration automation, and vulnerability remediation across our Linux and Windows server and endpoint fleets. This role combines Puppet/Ansible-based automation for Linux OS patching and configuration enforcement with SCCM/Intune-based endpoint management and PowerShell-driven remediation on Windows, ensuring systems across both platforms stay compliant, secure, and up to date with minimal manual intervention.
Develop, maintain, and version-control Puppet/Ansible modules and manifests for OS patching, software installation, and configuration enforcement.
Design staged/canary patch rollout groups to minimize production risk.
Automate software installation and configuration across environments to reduce manual provisioning.
Troubleshoot patch failures, configuration drift, and Puppet/Ansible run errors across the fleet.
Lead remediation of End-of-Life (EOL) / End-of-Support (EOS) operating systems and software — upgrading, re platforming, or migrating affected servers ahead of support cutoff dates.
Execute EOL remediation plans in coordination with infrastructure and application owners, escalating and documenting formal risk acceptance only where remediation isn't feasible within the required timeline.
Key Responsibilities — Windows (SCCM / Intune / PowerShell)
Manage and maintain endpoint security configurations using SCCM and Intune.
Develop and implement PowerShell scripts to automate vulnerability remediation, security tasks, and processes.
Create and manage imaging and task sequences in SCCM and Intune.
Package and deploy patches on Windows servers and workstations based on a monthly schedule.
Deploy collections in SCCM and push relevant missing patches to remediate vulnerabilities.
Write PowerShell scripts to fix vulnerabilities based on testing on a few devices and implement them through Qualys or SCCM.
Prioritize and remediate critical/high findings within SLA.
Define and manage maintenance windows, rollback procedures, and exception/risk-acceptance workflows for unpatchable systems.
Collaborate with security and application teams to align patch cadence with compliance requirements (CIS Benchmarks, STIG, PCI, etc.).
Document processes, runbooks, and standard operating procedures for patch, configuration, and remediation management.
Required Qualifications — Linux
Minimum 3+ years of Linux systems administration experience (RHEL).
Hands-on experience with Puppet/Ansible (manifests, modules, Hiera, PuppetDB, r10k or similar control-repo workflow).
Experience with package management (yum/dnf, apt).
Hands-on experience remediating EOL/EOS operating systems and software — performing OS upgrades, migrations, or replat forming to bring systems back into supported status.
Required Qualifications — Windows
Proven experience in vulnerability management and security operations.
Strong knowledge of Qualys, SCCM, and Intune.
Experience with imaging and task sequencing in SCCM and Intune.
Required Qualifications — Shared
Scripting proficiency in Bash and/or Python, and proficiency in PowerShell scripting.
Excellent analytical and problem-solving skills, with strong communication and teamwork abilities.
Preferred Qualifications
Experience with patch orchestration tools (Red Hat Satellite, Spacewalk, or equivalent).
Familiarity with vulnerability management/scanning tools (Qualys or similar).
Understanding of CIS Benchmarks, STIG, or other security hardening standards.
Experience with Git-based version control and CI/CD pipelines (Jenkins, GitLab CI, or similar).
Red Hat Certified System Administrator (RHCSA) or higher; Puppet/Ansible Certified Professional.
Experience in a regulated industry (financial services, healthcare) with formal exception/risk-acceptance processes.
Experience running EOL remediation projects at scale (e.g., fleet-wide OS version upgrades, distro migrations) in coordination with cross-functional teams.
Familiarity with Ansible or other configuration management tools as a secondary skill.
Experience building compliance dashboards (Grafana, Splunk, or similar).
Education
Bachelor’s degree in computer science, IT, or related field — or equivalent practical experience.
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Your application for SecOps Lead
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!