JOBSEARCHER

Windows Engineer

CBTSDenver, COL6 LeadAugust 14th, 2026
Windows Vulnerability Remediation Engineer (Server Infrastructure – Windows Server 2016/2019/2022)Job SummaryThe Windows Vulnerability Remediation Engineer is responsible for accelerating vulnerability remediation and patching activities across server infrastructure. This role focuses on Microsoft Windows Server 2016/2019/2022 and leverages existing automation and scanning technologies (e.g., Qualys, Chef, Ansible, PowerShell/shell scripting, Ruby) to identify, prioritize, implement, validate, and close vulnerabilities in alignment with internal compliance requirements (e.g., Meridian requirements). The engineer partners closely with Operations, Engineering teams, application owners, and support teams to deliver timely fixes while maintaining server stability and change discipline.Key ResponsibilitiesVulnerability Remediation & Patch ManagementOwn and execute end-to-end remediation for vulnerabilities identified on Windows servers (2016/2019/2022), including OS patching and configuration hardening.Fast-track and manage all Meridian-related remediation requirements as they are received, ensuring adherence to defined SLAs and audit expectations.Triage vulnerability findings (primarily from Qualys) and translate them into actionable remediation plans, considering exploitability, criticality, asset tiering, and operational risk.Coordinate remediation activities for:Microsoft security updates (monthly/Out-of-Band as needed) and required reboots where applicable.Configuration hardening aligned to organizational standards and security baselines (as applicable in the environment).Mitigations/compensating controls when immediate patching is not feasible (documented and approved per process).Automation, Configuration Management & EngineeringDevelop, enhance, and maintain remediation automation using:Chef (cookbooks/recipes, attributes, templates, policy files as applicable)Ansible (playbooks, roles, inventories, modules—Windows modules/WinRM-based execution as applicable)PowerShell and scripting (server-side automation and custom remediation logic)Ruby for maintaining/extending Chef-based remediation code and custom logicConvert recurring manual remediation steps into repeatable automated solutions and standardized runbooks.Ensure code follows internal engineering standards: version control, peer review, testing, documentation, and change management.Validation, Closure & ReportingValidate remediation effectiveness by re-scanning and verifying closure in Qualys (and/or approved internal validation methods).Confirm fixes did not introduce regressions; coordinate with application and platform teams for post-change verification.Maintain accurate documentation of remediation actions, approvals, exceptions, and closure evidence to support audit and compliance needs.Provide progress updates, metrics, and risk status to stakeholders (e.g., open critical/high items, aging items, SLA adherence).Cross-Team Coordination & Operational ExecutionSchedule and lead remediation calls with infrastructure support teams, application owners, and other stakeholders to drive timely execution.Work within change management processes: create/execute change plans, develop rollback steps, and coordinate maintenance windows.Partner with platform engineering to improve standard server baselines and prevent vulnerability recurrence.Vendor & Release Coordination (as needed)Follow up with vendors (Microsoft and/or third-party software providers installed on servers) for patch availability, release schedules, and remediation guidance when vulnerabilities require vendor action.Track Microsoft security advisories and coordinate planned rollout timelines where applicable.Scope (In-Scope / Out-of-Scope)In-ScopeServer infrastructure running Windows Server 2016, 2019, 2022Vulnerability remediation, hardening, and patching activities related to server OS and server-installed software/packagesAutomation for server remediation workflowsOut-of-ScopeEnd-user computing (desktops/laptops)Network/security appliances, storage appliances, or specialized non-server devicesRequired Qualifications6–10 years of strong hands-on experience with Windows Server 2016/2019/2022 in enterprise environments.Proven experience driving vulnerability remediation and patch management for Windows servers.Expertise with Qualys (or equivalent vulnerability scanners) including interpreting findings, false-positive validation, and closure verification.Automation experience with Chef and/or Ansible in production Windows server environments.Strong scripting skills (PowerShell; plus ability to use/maintain shell scripting where applicable in the environment).Working proficiency in Ruby (or ability to maintain/extend existing Ruby codebases used for Chef remediation).Strong understanding of Windows security fundamentals (patching, services, permissions, registry, authentication, TLS/cipher considerations as applicable).Experience working with change management, incident/problem management, and coordinating across multiple support teams.Preferred QualificationsFamiliarity with compliance/security frameworks and server hardening concepts (e.g., Microsoft Security Baselines, CIS benchmarks, STIG concepts) as applied to Windows Server.Experience with CI/CD or automated testing for infrastructure code (linting, unit/integration testing where applicable).Experience operating in large-scale environments (hundreds/thousands of servers) with tiered production controls.Exposure to enterprise patch orchestration tooling/processes used in Windows server environments (where applicable).Key Skills & CompetenciesRemediation prioritization and risk-based decision makingStrong troubleshooting and root-cause analysis (patch failures, dependency/application impact, service restart/reboot coordination)Clear communication and ability to drive closure across stakeholdersDocumentation discipline and audit readiness mindsetAbility to deliver under tight timelines while maintaining system stabilityDeliverables / Success MeasuresReduction in open Patch NOW/Critical/High vulnerabilities and improved SLA compliance.Consistent, repeatable remediation through Chef/Ansible automation.Verified closures in Qualys with clear evidence and minimal re-open rates.Improved remediation cycle time for Meridian requirements and other prioritized findings.Fewer recurring vulnerability patterns through baseline improvements and preventive controls.