Mid-level Windows Platform Engineer
Join a healthcare technology team responsible for securing, standardizing, and automating the Windows environment supporting a regulated clinical medical device. The role combines Windows internals, PowerShell scripting, image management, and CI/CD automation.
Responsabilidades
- Develop and maintain PowerShell automation for Windows configuration, hardening, and workstation deployment
- Define and enforce BIOS/UEFI security settings and TPM-based trust chains, including Secure Boot, measured boot, and TPM attestation
- Manage BitLocker and other Windows encryption mechanisms, including key recovery strategies
- Create and maintain Windows hardening baselines using Group Policy, AppLocker, shell restrictions, and kiosk mode
- Manage user permissions and least-privilege access across Windows devices
- Create and maintain VHD/VHDX images for deployment, recovery, and testing
- Build and maintain Azure DevOps CI/CD pipelines for automated image and configuration delivery
- Collaborate with software, QA, regulatory, and quality teams
- Document scripts, configurations, and processes for reproducibility and audit readiness
Requisitos
- Bachelor’s degree in Computer Science, Software Engineering, Computer Engineering, Mathematics, or a related field
- At least 4 years of relevant experience in Windows systems engineering, software engineering, security, or automation
- Strong hands-on PowerShell scripting skills
- Knowledge of BIOS/UEFI security and TPM architecture
- Experience with BitLocker, Windows encryption, Group Policy, AppLocker, kiosk mode, Assigned Access, and custom shell configuration
- Experience managing Windows accounts, groups, permissions, and least-privilege access
- Experience creating and maintaining VHD/VHDX virtual disks, including mounting, provisioning, offline servicing, DiskPart, and DISM
- Strong troubleshooting skills across the Windows boot chain, operating system internals, and security stack
Se valora
- Windows imaging tools such as MDT, DISM, Sysprep, and WinPE
- Endpoint security frameworks including CIS benchmarks or DoD STIGs
- Intune or another Windows MDM solution
- Python or C# scripting for tooling integration
- Experience in a medical device organization
- Azure DevOps CI/CD pipelines
- Git and Agile methodologies such as Scrum or Kanban
Beneficios
- Competitive salary and flexible benefits package
- Short-term incentive plan eligibility
- Benefits and resources supporting different career and life stages