Network & Systems Engineer (Vulnerability Management)
Summary
Delivers remote vulnerability management and patching for a client environment from Gruve's Dubai office: running Qualys VMDR scans, remediating vulnerabilities across Windows/Linux servers, Exchange, Active Directory, network/security devices, and cloud workloads, while owning a 24x7 on-call rotation and after-hours maintenance windows. Core stack includes Qualys VMDR, PowerShell/Bash automation,
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
Position Summary
The offsite engineer delivers the same remediation cycle from the Gruve UAE office, working remotely into the client environment over the approved VPN / jump-host path. This role carries the out-of-hours side of the service: it owns the 24x7 on-call rotation, executes patching in overnight, weekend, and public-holiday maintenance windows when production impact must be avoided, and drives the scan scheduling, automation, upload monitoring, and reporting production that keep the SLA/KPI framework compliant. The engineer is also the trained backup for the onsite engineer during leave and absence.
Key Responsibilities
- Own the scheduled Qualys VMDR scan calendar — configure scans, authentication records, asset groups, and tags; extract vulnerability details, severities, and remediation guidance.
- Fix vulnerabilities and apply patches remotely across in-scope end devices — Windows and Linux servers, Microsoft Exchange, Active Directory, enterprise applications and databases, network devices (routers/switches), security devices (firewalls/NAC/IPS/IDS), cloud workloads, and virtualization (VMware/Hyper-V).
- Hold the 24x7 on-call rotation: respond to critical/zero-day findings, emergency patch directives, and failed-change escalations outside business hours.
- Plan and execute after-hours, weekend, and public-holiday maintenance windows with staggered rollout and tested rollback, keeping availability within SLA.
- Raise and execute Change Requests for remote patching activity — impact, risk classification, schedule, and rollback — and join the client's CAB remotely.
- Monitor the daily ALKASHIF upload and the Qualys Splunk Add-on outside business hours; troubleshoot failed uploads so Availability stays compliant.
- Automate recurring remediation and reporting tasks using PowerShell / Bash / Qualys APIs to reduce manual patch effort.
- Perform post-remediation verification re-scans and maintain the vulnerability register, aging report, and evidence pack.
- Produce the weekly report (findings, patch-time by severity, coverage %, availability, after-hours SLA, risks/escalations) and support the monthly reporting pack.
- Provide full backup coverage for the onsite engineer during leave, absence, and peak remediation drives.
- Take clean handover from the onsite engineer at end of business hours and hand back open items each morning.
Basic Qualifications
- 3–6 years in network/systems engineering with hands-on patching and vulnerability remediation.
- Familiar with Qualys (VMDR) to run scans and obtain vulnerability details and reports; Qualys Splunk Add-on familiarity strongly preferred.
- Strong hands-on patching of Windows Server and Linux (WSUS/SCCM, package managers), including Microsoft Exchange and Active Directory.
- Able to patch/upgrade network devices (routers/switches), security devices (firewalls/NAC/IPS/IDS), virtualization hosts (VMware/Hyper-V), and cloud workloads.
- Proven experience delivering remote support into a customer environment via VPN / jump host / bastion access, including remote console tooling.
- Scripting and automation (PowerShell / Bash; Qualys or Splunk APIs an advantage) — this role is expected to automate repetitive remediation and reporting.
- Understanding of CVSS/CVE, the vulnerability management lifecycle, and ITIL change management / CR processes with rollback.
- Demonstrated willingness and availability to work a 24x7 on-call rotation, including weekends and public holidays.
- Strong written-English, documentation, and remote-coordination skills — most client interaction is by ticket, email, and call.
Preferred Qualifications
- Preferred the certifications Qualys VMDR; MCSA / RHCSA (Windows / Linux); CompTIA Security+ / Network+; CCNA; Azure Administrator; ITIL Foundation.
- Self-managing and reliable without direct supervision
- Calm under out-of-hours pressure
- Automation-minded and precise in documentation
Why Gruve
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
Skills
As published by greenhouse · 19 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (8)
- Preferred First Name optional
- LinkedIn Profile optional
- Website optional
- What is your current notice period?
- What is your current CTC in AED?
- What are your salary expectations for this role? (Please specify in AED only)
- Do you have hands-on experience patching Windows and Linux servers, including Exchange and Active Directory?
- Have you patched network/security devices such as routers, switches, firewalls, NAC, IPS/IDS, or virtualization platforms?
Pick from a list (11)
- This position is a contract role. Are you open proceeding under this engagement model?
- Are you currently based in Dubai and do you hold a valid UAE visa?
- Do you have 3–6 years of experience in network/systems engineering with hands-on vulnerability remediation and patching?
- Do you have hands-on experience using Qualys VMDR for vulnerability scanning and reporting?
- Have you configured Qualys VMDR scans, authentication records, asset groups, and tags?
- Do you have experience with PowerShell/Bash scripting or Qualys/Splunk APIs for automation?
- Are you familiar with CVE/CVSS, vulnerability management lifecycle, and ITIL Change Request processes with rollback planning?
- Are you willing and available to work in a 24x7 on-call rotation, including weekends and public holidays?
- I acknowledge my right to refrain from disclosing any confidential or proprietary information during the interview and understand that the company will not solicit such information, in accordance with the Non-Disclosure Agreement
- I consent to the use of AI-powered note-taking tools during the interview process and acknowledge that the interview may be recorded and stored for evaluation purposes.
- I hereby provide my consent to share my professional referees with Gruve and authorize Gruve, or its designated third-party representative, to contact them for the purpose of conducting business reference checks as part of the hiring process.