Substrate PAVC Engineer
About Blueprint
Blueprint is a technology solutions firm headquartered in Bellevue, Washington, with teams across the United States. We help organizations turn complex challenges into meaningful outcomes by connecting strategy and execution across AI, cloud, data, product development, and emerging technology.
Our culture is built by people who care deeply about doing exceptional work. We set high standards, take ownership, and continually challenge ourselves and one another to be better. We work hard, support each other, and take genuine pride in what we deliver for our clients, partners, and teams.
At Blueprint, you’ll work alongside talented people with different experiences, expertise, and perspectives. You’ll have opportunities to take on meaningful challenges, expand your skills, and see the impact of what you build.
Bring your perspective. Raise the standard. Build what matters.
About the Role
The Substrate PAVC Engineer supports patching, antivirus, and vulnerability compliance across Microsoft Substrate environments. This role focuses on Windows servicing, PowerShell automation, Kusto Query Language analysis, and troubleshooting patch deployment failures across a large server fleet.
You’ll help deliver Windows security patches, Defender platform and signature updates, .NET updates, and vulnerability remediation activities safely and consistently. You’ll collaborate with engineering, security, and compliance teams to investigate deployment issues, maintain compliance, and resolve technical blockers.
What You'll Do
- Support monthly Windows security patch rollouts, including official and prerelease updates, Defender updates, .NET updates, and related security and compliance components.
- Use PowerShell scripts and automation to support patch deployment, investigation, remediation, and reporting workflows.
- Use KQL in Kusto to investigate deployment results, identify patterns and failures, and monitor patch and vulnerability compliance.
- Troubleshoot failed Windows updates and MSU installations using Event Viewer, CBS and installer logs, error codes, and other relevant diagnostic information.
- Identify installed patches and operating system status using tools such as Get-HotFix, Get-WindowsPackage, DISM, Get-ComputerInfo, and Windows Update history.
- Build, validate, and publish patching components and packages while following Safe Deployment Practices across deployment rings and environments.
- Investigate and remediate deployment stragglers caused by installation failures, machine states, capacity constraints, network issues, or environment-specific blockers.
- Maintain dashboards, monitoring, compliance reporting, and status updates for engineering, security, and compliance stakeholders.
- Coordinate with partner teams to resolve exceptions, blockers, manual interventions, and environment-specific patching requirements.
What You'll Bring
- Hands-on experience with PowerShell scripting and automation, including familiarity with PowerShell’s object-based pipeline and filtering methods such as Where-Object.
- Hands-on experience using KQL to query and troubleshoot data in Kusto.
- Working knowledge of Windows servicing and enterprise update methods, including Windows Update or Microsoft Update, WSUS, and manual MSU installation.
- Strong troubleshooting skills related to Windows updates, patch installations, and deployment failures.
- Ability to review relevant logs, investigate error codes, and determine appropriate next steps.
- Experience identifying installed patches, packages, runtime versions, and operating system status using PowerShell, DISM, or equivalent tools.
- Strong communication skills and the ability to collaborate with engineering, security, and compliance teams throughout an investigation.
Preferred Qualifications
- Experience with Azure DevOps build or deployment pipelines.
- Experience with .NET tooling and identifying installed .NET Core runtimes.
- Familiarity with Defender servicing and vulnerability scanning systems such as Qualys or AzSecPack.
- Familiarity with mapping CVEs to patch or vulnerability remediation workflows.
- Knowledge of Windows Server 2025 hotpatching, operating system baselines, STIGs, WinPE, or Safe Deployment Practices.
- Experience supporting patch compliance or troubleshooting across a large, distributed server environment.
Compensation
At Blueprint, we strive to offer competitive pay that reflects the value of our team members. Compensation for this role is influenced by a variety of factors, including skills, education, responsibilities, experience, and geographic market.
For candidates based in Colombia, the anticipated gross monthly compensation range is COP 7,200,000 to COP 8,400,000. Please note that we typically do not hire new employees at the top of the posted range. Actual starting pay will be determined based on experience, skills, and internal equity. The final compensation and job title may vary depending on the selected candidate’s qualifications.
Location and Employment Structure
This is a remote position open to candidates based in Colombia.
The selected candidate will be employed through Remote People, Blueprint’s local Professional Employer Organization partner, and assigned to support a Microsoft engagement through Blueprint. The engagement is expected to last 18 months.
Compensation will be paid in Colombian pesos. The employee will also receive statutory benefits and additional payments required under Colombian law.
Benefits
Blueprint believes that healthy, supported employees do their best work. Eligible employees have access to a comprehensive benefits package that may include:
- Medical, dental, and vision coverage
- Flexible Spending Account (FSA)
- 401(k) retirement plan
- Competitive paid time off
- Parental leave
- Professional growth and development opportunities
Benefits and eligibility may vary based on role, employment status, and location.
Equal Employment Opportunity
Blueprint Technologies, LLC is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, pregnancy, childbirth or related medical conditions, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital or familial status, military or veteran status, citizenship status, or any other characteristic protected by applicable law.
Applicant Accommodations
If you need a reasonable accommodation to participate in any part of the application or interview process, please contact recruiting@bpcs.com.
Apply for this job
*
indicates a required field
