Senior Patch Research Engineer

Posted 11 Hours Ago
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Senior level
Information Technology • Security • Cybersecurity
The Role
Own and drive the Windows patch catalog: research and publish patch metadata, design detection logic and supersedence chains, lead Python automation for metadata pipelines, validate installers and patch behavior, mentor junior researchers, and collaborate with Engineering, QA, and Product to maintain high catalog quality and coverage.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

About the Role

Qualys is seeking an experienced Senior Windows Patch Management Catalog Researcher to take ownership of the patch catalog for the Patch Management team. In this senior role, you will not only research and author high-quality patch metadata for a broad range of third-party Windows applications but will also drive catalog strategy, define quality standards, mentor junior researchers, and lead automation initiatives. Your expertise will directly influence the reliability and breadth of Qualys Patch Management.

Key Responsibilities

Patch Catalog Ownership and Strategy

  • Own end-to-end delivery of patch metadata for assigned software families - from initial research to production publishing.
  • Define and maintain catalog standards: field derivation rules, naming conventions, supersedence logic, and schema versioning.
  • Proactively identify coverage gaps and prioritise onboarding based on customer demand and vulnerability risk.
  • Build and maintain supersedence chains across software versions and architectures (x86, x64, ARM64).
  • Track software End-of-Life (EOL) dates and manage timely catalog updates as support windows close.

Windows Patching - Advanced Expertise

  • Serve as subject matter expert on Windows installer technologies: MSI/WiX, NSIS, InnoSetup, Squirrel, MSIX, and vendor-specific custom installers.
  • Research, document, and validate silent installation parameters, exit codes, and reboot behaviors for complex installer types.
  • Design and maintain test procedures for patch validation across multiple Windows OS versions.
  • Troubleshoot installation failures, detection mismatches, and edge-case patching behaviours.

Detection Logic and Registry Expertise

  • Architect robust, version-specific detection logic using registry keys, file attributes, and hybrid (Registry_and_File) detection methods.
  • Define team detection standards - documenting which detection approach is preferred per installer type and why.
  • Validate detection logic across 32-bit/64-bit registry views (WOW6432Node) and post-upgrade scenarios.
  • Review and approve detection logic authored by junior researchers before catalog publishing.

Backend Patch Tool Architecture

  • Deep understanding of how enterprise patch platforms (Qualys, SCCM, Ivanti, Adaptiva) discover, deploy, and verify patches at agent level.
  • Understand the full agent-side workflow: download, hash verification, installer invocation, detection, reboot handling, and reporting.
  • Provide technical input to Engineering on catalog schema design, detection engine requirements, and policy edge cases.
  • Stay current on patch platform architecture changes and proactively adapt catalog practices.

Automation and Tooling Leadership

  • Design, build, and own the Python automation pipeline for data collection, metadata generation, hash computation, and schema validation.
  • Establish coding standards, code review practices, and documentation requirements for team scripts.
  • Identify opportunities to reduce manual effort through automation and lead implementation.
  • Evaluate and integrate third-party data sources (NVD API, GitHub Releases API, vendor RSS feeds) into the pipeline.

Mentoring and Team Leadership

  • Mentor and guide junior Catalog Researchers - reviewing work, providing feedback, and building expertise.
  • Conduct peer reviews of catalog entries for schema correctness, detection accuracy, and quality.
  • Collaborate cross-functionally with Qualys VMDR, Engineering, QA, and Product Management teams.

Required Skills and Qualifications

  • 6-8 years of experience in Windows systems administration, patch management, or software packaging.
  • Expert-level knowledge of Windows OS internals - registry architecture, file system, WOW6432Node, user vs. system scope.
  • Deep hands-on experience with 2+ enterprise patch platforms (Qualys, SCCM, Ivanti, Adaptiva, WSUS, or equivalent).
  • Strong experience with manual patch installation - troubleshooting and repackaging MSI/EXE installers across diverse environments.
  • Demonstrated ability to design and validate detection logic using registry keys, file attributes, and hybrid strategies.
  • Proven track record of producing high-quality, schema-compliant technical documentation and metadata at scale.
  • Strong communication skills - ability to articulate complex topics to both technical and non-technical stakeholders.

Nice to Have

  • Prior experience building or maintaining an enterprise software patch catalog (Chocolatey, Adaptiva, ManageEngine, or similar).
  • Familiarity with OVAL, SCAP, or other standardized patch/vulnerability description formats.
  • Experience with CI/CD pipelines for automated catalog generation and deployment.
  • Understanding of code signing, Authenticode verification, and SHA-256 hash validation workflows.
  • Knowledge of ARM64 Windows platform nuances and multi-architecture software distribution challenges.
  • Deep understanding of Windows Update infrastructure: WUA, WSUS, CBS/SFC, Windows Update for Business.
  • PowerShell scripting for on-system detection validation and registry inspection.
  • Exposure to Linux/macOS patching as secondary cross-platform awareness.
  • Prior experience in a technical lead, catalog owner, or senior individual contributor role.

Skills Required

  • 6-8 years experience in Windows systems administration, patch management, or software packaging.
  • Expert-level knowledge of Windows OS internals (registry architecture, file system, WOW6432Node, user vs system scope).
  • Deep hands-on experience with 2+ enterprise patch platforms (Qualys, SCCM, Ivanti, Adaptiva, WSUS, or equivalent).
  • Strong experience with manual patch installation, troubleshooting, and repackaging MSI/EXE installers across diverse environments.
  • Demonstrated ability to design and validate detection logic using registry keys, file attributes, and hybrid strategies.
  • Proven track record producing high-quality, schema-compliant technical documentation and metadata at scale.
  • Ability to define catalog standards, supersedence logic, and manage EOL-driven catalog updates.
  • Design, build, and own Python automation pipeline for data collection, metadata generation, hash computation, and schema validation.
  • Subject-matter expertise with Windows installer technologies: MSI/WiX, NSIS, InnoSetup, Squirrel, MSIX, and vendor-specific installers.
  • Strong communication skills and ability to mentor junior researchers and conduct peer reviews.
  • Prior experience building or maintaining an enterprise software patch catalog (Chocolatey, Adaptiva, ManageEngine, or similar).
  • Familiarity with OVAL, SCAP, CI/CD pipelines for automated catalog generation, code signing/Authenticode, and SHA-256 validation workflows.
  • Knowledge of ARM64 Windows platform nuances and Windows Update infrastructure (WUA, WSUS, CBS/SFC, Windows Update for Business).
  • PowerShell scripting for on-system detection validation and registry inspection; exposure to Linux/macOS patching.
  • Prior experience in a technical lead, catalog owner, or senior individual contributor role.

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Zocdoc Logo Zocdoc

Staff SDET

Healthtech • Information Technology • Software • Telehealth
Easy Apply
Hybrid
Pune, Mahārāshtra, IND
900 Employees

TransUnion Logo TransUnion

Automation Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Pune, Mahārāshtra, IND
13000 Employees

TransUnion Logo TransUnion

Senior Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
2 Locations
13000 Employees

Capco Logo Capco

Full-stack Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account