HG
SecOps Lead
Accepting applicationsHTC Global Services · Chennai, Tamil Nadu, India
Full-Time Mid_senior Pythoncadence
Estimated market salary
₹14-25 LPA
This is a SiliconBoard market estimate, not an employer-posted salary.
Posted
1d ago
Category
Manufacturing
Experience
Mid_senior
Country
India
Job Description
About the Role:
We are seeking a Systems Engineer to own patch management, configuration automation, and vulnerability remediation across our Linux and Windows server and endpoint fleets. This role combines Puppet/Ansible-based automation for Linux OS patching and configuration enforcement with SCCM/Intune-based endpoint management and PowerShell-driven remediation on Windows, ensuring systems across both platforms stay compliant, secure, and up to date with minimal manual intervention.
Requirements
Key Responsibilities — Linux (Puppet/Ansible)
Manage end-to-end patch lifecycle (assessment, testing, staged rollout, validation) across RHEL servers.
Develop, maintain, and version-control Puppet/Ansible modules and manifests for OS patching, software installation, and configuration enforcement.
Design staged/canary patch rollout groups to minimize production risk.
Automate software installation and configuration across environments to reduce manual provisioning.
Troubleshoot patch failures, configuration drift, and Puppet/Ansible run errors across the fleet.
Lead remediation of End-of-Life (EOL) / End-of-Support (EOS) operating systems and software — upgrading, re platforming, or migrating affected servers ahead of support cutoff dates.
Execute EOL remediation plans in coordination with infrastructure and application owners, escalating and documenting formal risk acceptance only where remediation isn't feasible within the required timeline.
Key Responsibilities — Windows (SCCM / Intune / PowerShell)
Manage and maintain endpoint security configurations using SCCM and Intune.
Develop and implement PowerShell scripts to automate vulnerability remediation, security tasks, and processes.
Create and manage imaging and task sequences in SCCM and Intune.
Package and deploy patches on Windows servers and workstations based on a monthly schedule.
Deploy collections in SCCM and push relevant missing patches to remediate vulnerabilities.
Write PowerShell scripts to fix vulnerabilities based on testing on a few devices and implement them through Qualys or SCCM.
Shared Responsibilities — Vulnerability Management & Compliance
Prioritize and remediate critical/high findings within SLA.
Define and manage maintenance windows, rollback procedures, and exception/risk-acceptance workflows for unpatchable systems.
Collaborate with security and application teams to align patch cadence with compliance requirements (CIS Benchmarks, STIG, PCI, etc.).
Document processes, runbooks, and standard operating procedures for patch, configuration, and remediation management.
Required Qualifications — Linux
Minimum 3+ years of Linux systems administration experience (RHEL).
Hands-on experience with Puppet/Ansible (manifests, modules, Hiera, PuppetDB, r10k or similar control-repo workflow).
Experience with package management (yum/dnf, apt).
Hands-on experience remediating EOL/EOS operating systems and software — performing OS upgrades, migrations, or replat forming to bring systems back into supported status.
Required Qualifications — Windows
Proven experience in vulnerability management and security operations.
Strong knowledge of Qualys, SCCM, and Intune.
Experience with imaging and task sequencing in SCCM and Intune.
Required Qualifications — Shared
Scripting proficiency in Bash and/or Python, and proficiency in PowerShell scripting.
Excellent analytical and problem-solving skills, with strong communication and teamwork abilities.
Preferred Qualifications
Experience with patch orchestration tools (Red Hat Satellite, Spacewalk, or equivalent).
Familiarity with vulnerability management/scanning tools (Qualys or similar).
Understanding of CIS Benchmarks, STIG, or other security hardening standards.
Experience with Git-based version control and CI/CD pipelines (Jenkins, GitLab CI, or similar).
Red Hat Certified System Administrator (RHCSA) or higher; Puppet/Ansible Certified Professional.
Experience in a regulated industry (financial services, healthcare) with formal exception/risk-acceptance processes.
Experience running EOL remediation projects at scale (e.g., fleet-wide OS version upgrades, distro migrations) in coordination with cross-functional teams.
Familiarity with Ansible or other configuration management tools as a secondary skill.
Experience building compliance dashboards (Grafana, Splunk, or similar).
Education
Bachelor’s degree in computer science, IT, or related field — or equivalent practical experience.
Onsite
Show more Show less
About the Role:
We are seeking a Systems Engineer to own patch management, configuration automation, and vulnerability remediation across our Linux and Windows server and endpoint fleets. This role combines Puppet/Ansible-based automation for Linux OS patching and configuration enforcement with SCCM/Intune-based endpoint management and PowerShell-driven remediation on Windows, ensuring systems across both platforms stay compliant, secure, and up to date with minimal manual intervention.
Requirements
Key Responsibilities — Linux (Puppet/Ansible)
Manage end-to-end patch lifecycle (assessment, testing, staged rollout, validation) across RHEL servers.
Develop, maintain, and version-control Puppet/Ansible modules and manifests for OS patching, software installation, and configuration enforcement.
Design staged/canary patch rollout groups to minimize production risk.
Automate software installation and configuration across environments to reduce manual provisioning.
Troubleshoot patch failures, configuration drift, and Puppet/Ansible run errors across the fleet.
Lead remediation of End-of-Life (EOL) / End-of-Support (EOS) operating systems and software — upgrading, re platforming, or migrating affected servers ahead of support cutoff dates.
Execute EOL remediation plans in coordination with infrastructure and application owners, escalating and documenting formal risk acceptance only where remediation isn't feasible within the required timeline.
Key Responsibilities — Windows (SCCM / Intune / PowerShell)
Manage and maintain endpoint security configurations using SCCM and Intune.
Develop and implement PowerShell scripts to automate vulnerability remediation, security tasks, and processes.
Create and manage imaging and task sequences in SCCM and Intune.
Package and deploy patches on Windows servers and workstations based on a monthly schedule.
Deploy collections in SCCM and push relevant missing patches to remediate vulnerabilities.
Write PowerShell scripts to fix vulnerabilities based on testing on a few devices and implement them through Qualys or SCCM.
Shared Responsibilities — Vulnerability Management & Compliance
Prioritize and remediate critical/high findings within SLA.
Define and manage maintenance windows, rollback procedures, and exception/risk-acceptance workflows for unpatchable systems.
Collaborate with security and application teams to align patch cadence with compliance requirements (CIS Benchmarks, STIG, PCI, etc.).
Document processes, runbooks, and standard operating procedures for patch, configuration, and remediation management.
Required Qualifications — Linux
Minimum 3+ years of Linux systems administration experience (RHEL).
Hands-on experience with Puppet/Ansible (manifests, modules, Hiera, PuppetDB, r10k or similar control-repo workflow).
Experience with package management (yum/dnf, apt).
Hands-on experience remediating EOL/EOS operating systems and software — performing OS upgrades, migrations, or replat forming to bring systems back into supported status.
Required Qualifications — Windows
Proven experience in vulnerability management and security operations.
Strong knowledge of Qualys, SCCM, and Intune.
Experience with imaging and task sequencing in SCCM and Intune.
Required Qualifications — Shared
Scripting proficiency in Bash and/or Python, and proficiency in PowerShell scripting.
Excellent analytical and problem-solving skills, with strong communication and teamwork abilities.
Preferred Qualifications
Experience with patch orchestration tools (Red Hat Satellite, Spacewalk, or equivalent).
Familiarity with vulnerability management/scanning tools (Qualys or similar).
Understanding of CIS Benchmarks, STIG, or other security hardening standards.
Experience with Git-based version control and CI/CD pipelines (Jenkins, GitLab CI, or similar).
Red Hat Certified System Administrator (RHCSA) or higher; Puppet/Ansible Certified Professional.
Experience in a regulated industry (financial services, healthcare) with formal exception/risk-acceptance processes.
Experience running EOL remediation projects at scale (e.g., fleet-wide OS version upgrades, distro migrations) in coordination with cross-functional teams.
Familiarity with Ansible or other configuration management tools as a secondary skill.
Experience building compliance dashboards (Grafana, Splunk, or similar).
Education
Bachelor’s degree in computer science, IT, or related field — or equivalent practical experience.
Onsite
Show more Show less
Similar Jobs
CA
Electrical Engineer II - Avionics Digital Hardware Engineer
Collins Aerospace · Melbourne, FL
Q
Machine Learning / Computer Vision Engineer
Qualcomm · San Diego, CA
CA
Electrical Engineer II - Digital Hardware
Collins Aerospace · Cedar Rapids, IA
GV
Senior Embedded Control Engineer (R&D High Voltage)
GE Vernova · Niskayuna, NY