Patch Research Engineer

Posted 11 Hours Ago
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Mid level
Information Technology • Security • Cybersecurity
The Role
Build and maintain a comprehensive Windows third-party patch catalog: research vendor releases and CVEs, author metadata, validate silent install parameters and detection logic, test patches in sandboxes, track EOL, and understand enterprise patch tools and patch-engine consumption.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

About the Role

Qualys is looking for a detail-oriented Windows Patch Management Catalog Researcher to join the Patch Management product team. In this role, you will be responsible for building and maintaining a comprehensive, accurate patch catalog covering a wide range of third-party Windows software.
 

Key Responsibilities

Patch Catalog Research & Authoring

  • Research, author, and maintain patch metadata for third-party Windows applications across a broad software catalog.
  • Identify new software releases, security updates, and version changes from vendor sources, changelogs, and security advisories (CVE/NVD).
  • Map vendor releases to structured metadata schemas, including version strings, download URLs, detection logic, and installation parameters.
  • Track software End-of-Life (EOL) dates and update catalog entries accordingly.

Windows Patching & Installation Knowledge

  • Document and validate silent installation parameters for diverse installer types (MSI, NSIS EXE, InnoSetup, WiX, etc.).
  • Research and verify correct msiexec.exe flags, NSIS /S switches, and equivalent silent/unattended arguments per software.
  • Determine accurate reboot behavior (Yes / No / Maybe) per installer type and document exit codes (success, reboot-required).
  • Manually test patch installation in sandbox environments and verify detection logic post-install.

Detection Logic & Registry Research

  • Research and validate Windows registry keys used to detect installed software versions (Uninstall hive, vendor-specific keys, DisplayVersion, etc.).
  • Identify and document file-based detection paths (FileVersion, ProductVersion attributes on key executables).
  • Understand the difference between 32-bit and 64-bit registry views (WOW6432Node) and apply correct detection architecture per installer variant.
  • Validate detection logic against fresh installs and upgrades across supported Windows versions.

Backend Patch Tool Understanding

  • Understand how enterprise patch management platforms (e.g., Qualys Patch Management, SCCM, Ivanti, Adaptiva) discover, deploy, and verify patches.
  • Familiarity with how catalogs are consumed by patch engines — detection-before-install logic, supersedence evaluation, and deployment policy enforcement.

Required Skills & Qualifications

  • 4-5 years of experience in Windows systems administration, patch management, or software packaging.
  • Strong understanding of Windows OS internals — registry structure, file system, user vs. system installation scopes, environment variables, and PATH management.
  • Hands-on experience with Windows patching tools (WSUS, SCCM/ConfigMgr, Ivanti, Qualys, Chocolatey, or equivalent).
  • Experience with manual patch installation — running MSI/EXE installers, using msiexec.exe with switches, repackaging software.
  • Solid understanding of installer technologies: MSI/WiX, NSIS, InnoSetup, Squirrel, and their silent install mechanisms.
  • Familiarity with the Windows registry and the ability to trace installation artifacts to their registry keys.

Nice to Have

  • Experience building or maintaining a software patch catalog (Adaptiva, Chocolatey, ManageEngine, or similar).
  • Experience with Windows Installer (MSI) internals — product codes, upgrade codes, component tables.
  • Knowledge of ARM64 Windows platform nuances and multi-architecture software distribution.
  • Good understanding of Windows Update infrastructure (WUA, WSUS, CBS/SFC).
  • Scripting experience in Python or PowerShell.

Skills Required

  • 4-5 years of experience in Windows systems administration, patch management, or software packaging
  • Strong understanding of Windows OS internals (registry, file system, installation scopes, environment variables, PATH)
  • Hands-on experience with Windows patching tools (WSUS, SCCM/ConfigMgr, Ivanti, Qualys, Chocolatey, or equivalent)
  • Experience with manual patch installation and using msiexec.exe with switches; repackaging software
  • Solid understanding of installer technologies: MSI/WiX, NSIS, InnoSetup, Squirrel, and their silent install mechanisms
  • Familiarity with the Windows registry and ability to trace installation artifacts to registry keys
  • Experience building or maintaining a software patch catalog (Adaptiva, Chocolatey, ManageEngine, or similar)
  • Experience with Windows Installer (MSI) internals: product codes, upgrade codes, component tables
  • Knowledge of ARM64 Windows platform nuances and multi-architecture distribution
  • Good understanding of Windows Update infrastructure (WUA, WSUS, CBS/SFC)
  • Scripting experience in Python or PowerShell

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Qualys Logo Qualys

Senior Patch Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Qualys Logo Qualys

Patch Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Zocdoc Logo Zocdoc

Staff SDET

Healthtech • Information Technology • Software • Telehealth
Easy Apply
Hybrid
Pune, Mahārāshtra, IND
900 Employees

TransUnion Logo TransUnion

Automation Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Pune, Mahārāshtra, IND
13000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account