Qualys Security Techservices Private Limited

Senior Windows Patch Management Research Engineer

Qualys Security Techservices Private Limited
Pune
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 6 yearsMin. 6 years

Job Description

Senior Patch Research Engineer

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

About the Role

Qualys is seeking an experienced Senior Windows Patch Management Catalog Researcher to take ownership of the patch catalog for the Patch Management team. In this senior role, you will not only research and author high-quality patch metadata for a broad range of third-party Windows applications but will also drive catalog strategy, define quality standards, mentor junior researchers, and lead automation initiatives. Your expertise will directly influence the reliability and breadth of Qualys Patch Management.

Key Responsibilities

Patch Catalog Ownership and Strategy

  • Own end-to-end delivery of patch metadata for assigned software families - from initial research to production publishing.
  • Define and maintain catalog standards: field derivation rules, naming conventions, supersedence logic, and schema versioning.
  • Proactively identify coverage gaps and prioritise onboarding based on customer demand and vulnerability risk.
  • Build and maintain supersedence chains across software versions and architectures (x86, x64, ARM64).
  • Track software End-of-Life (EOL) dates and manage timely catalog updates as support windows close.

Windows Patching - Advanced Expertise

  • Serve as subject matter expert on Windows installer technologies: MSI/WiX, NSIS, InnoSetup, Squirrel, MSIX, and vendor-specific custom installers.
  • Research, document, and validate silent installation parameters, exit codes, and reboot behaviors for complex installer types.
  • Design and maintain test procedures for patch validation across multiple Windows OS versions.
  • Troubleshoot installation failures, detection mismatches, and edge-case patching behaviours.

Detection Logic and Registry Expertise

  • Architect robust, version-specific detection logic using registry keys, file attributes, and hybrid (Registry_and_File) detection methods.
  • Define team detection standards - documenting which detection approach is preferred per installer type and why.
  • Validate detection logic across 32-bit/64-bit registry views (WOW6432Node) and post-upgrade scenarios.
  • Review and approve detection logic authored by junior researchers before catalog publishing.

Backend Patch Tool Architecture

  • Deep understanding of how enterprise patch platforms (Qualys, SCCM, Ivanti, Adaptiva) discover, deploy, and verify patches at agent level.
  • Understand the full agent-side workflow: download, hash verification, installer invocation, detection, reboot handling, and reporting.
  • Provide technical input to Engineering on catalog schema design, detection engine requirements, and policy edge cases.
  • Stay current on patch platform architecture changes and proactively adapt catalog practices.

Automation and Tooling Leadership

  • Design, build, and own the Python automation pipeline for data collection, metadata generation, hash computation, and schema validation.
  • Establish coding standards, code review practices, and documentation requirements for team scripts.
  • Identify opportunities to reduce manual effort through automation and lead implementation.
  • Evaluate and integrate third-party data sources (NVD API, GitHub Releases API, vendor RSS feeds) into the pipeline.

Mentoring and Team Leadership

  • Mentor and guide junior Catalog Researchers - reviewing work, providing feedback, and building expertise.
  • Conduct peer reviews of catalog entries for schema correctness, detection accuracy, and quality.
  • Collaborate cross-functionally with Qualys VMDR, Engineering, QA, and Product Management teams.

Required Skills and Qualifications

  • 6-8 years of experience in Windows systems administration, patch management, or software packaging.
  • Expert-level knowledge of Windows OS internals - registry architecture, file system, WOW6432Node, user vs. system scope.
  • Deep hands-on experience with 2+ enterprise patch platforms (Qualys, SCCM, Ivanti, Adaptiva, WSUS, or equivalent).
  • Strong experience with manual patch installation - troubleshooting and repackaging MSI/EXE installers across diverse environments.
  • Demonstrated ability to design and validate detection logic using registry keys, file attributes, and hybrid strategies.
  • Proven track record of producing high-quality, schema-compliant technical documentation and metadata at scale.
  • Strong communication skills - ability to articulate complex topics to both technical and non-technical stakeholders.

Nice to Have

  • Prior experience building or maintaining an enterprise software patch catalog (Chocolatey, Adaptiva, ManageEngine, or similar).
  • Familiarity with OVAL, SCAP, or other standardized patch/vulnerability description formats.
  • Experience with CI/CD pipelines for automated catalog generation and deployment.
  • Understanding of code signing, Authenticode verification, and SHA-256 hash validation workflows.
  • Knowledge of ARM64 Windows platform nuances and multi-architecture software distribution challenges.
  • Deep understanding of Windows Update infrastructure: WUA, WSUS, CBS/SFC, Windows Update for Business.
  • PowerShell scripting for on-system detection validation and registry inspection.
  • Exposure to Linux/macOS patching as secondary cross-platform awareness.
  • Prior experience in a technical lead, catalog owner, or senior individual contributor role.

Experience Level

Senior Level

Job role

Work location
Work locationPune, India
Department
DepartmentSoftware Engineering
Role / Category
Role / CategorySoftware Development
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 6 years

About company

Name
NameQualys Security Techservices Private Limited
Job posted by Qualys Security Techservices Private Limited

Similar jobs you can apply for

Software / Web Developer
Kahani Technologies Private Limited

ASP.NET Developer

Kahani Technologies Private Limited
Lulla Nagar, Pune
₹24,000 - ₹30,000
Work from Office
Full Time
Min. 6 months
Good (Intermediate / Advanced) English

Testing Engineer

Higher Orbit Agritech Private Limited
Pune
₹18,000 - ₹25,000
Field Job
Full Time
Min. 6 months
No English Required
Arronics Infotech Pvt Ltd

ERP Developer

Arronics Infotech Pvt Ltd
Baner, Pune
₹20,000 - ₹25,000
Work from Office
Full Time
Min. 2 years
Basic English
Altroz Technologies

Flutter Developer

Altroz Technologies
Hinjewadi, Pune
₹10,000 - ₹20,000
Work from Office
Full Time
Min. 6 months
Basic English
Ws Foods Private Limited

QA / QC Executive

Ws Foods Private Limited
Wagholi, Pune
₹12,000 - ₹15,000
Work from Office
Full Time
Min. 2 years
Basic English
Eco Tech Engineers

Quality Engineer

Eco Tech Engineers
Pune
₹20,000 - ₹35,000
Work from Office
Full Time
Freshers only
Basic English

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 6 to 8 years are eligible to apply for this job. You can apply for more jobs in Pune to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Pune at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Pune . Through apna, you can find jobs in 64 cities across India. Join NOW!