Qualys

Patch Research Engineer

Qualys  •  Pune, IN (Onsite)  •  22 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Patch Research Engineer

Apple macOS Patch Catalogue Engineer — Patch Content Development

Location: Pune, India

Experience Required: 3–8 years (Patch Management / Vulnerability Content Development / macOS Systems Administration)


We are seeking a skilled Apple macOS Patch Catalogue Engineer to design, develop, validate, and maintain macOS patch metadata and deployment catalogues in support of enterprise patch management solutions. This role is responsible for building and sustaining an in-house macOS patch content repository covering both Apple OS updates and third-party applications — ensuring accurate detection logic, reliable installation behavior, compliance reporting, and consistent deployment across enterprise environments.


Key Responsibilities

1. Patch Catalogue Development

  • Research and analyze security advisories published by Apple Inc. for macOS and related products.
  • Create structured, schema-compliant macOS patch metadata (version, architecture, detection, installation, and compliance fields).
  • Build and maintain a centralized macOS patch catalogue repository.

2. macOS Update & Security Monitoring

  • Continuously track new releases of macOS and other supported Apple and third-party products.
  • Monitor Apple security bulletins and release notes to identify patch-relevant changes as they are published.

3. Detection & Compliance Logic

  • Develop and validate detection logic using macOS system profiling commands and utilities.
  • Apply working knowledge of OS builds, application bundles (.app), and package receipts (.pkg) to construct accurate version-detection rules.
  • Write and maintain automation scripts in Bash, Zsh, and Python to support content generation and validation.

4. QA & Validation

  • Perform lab-based testing across all supported macOS versions and architectures.
  • Validate installation success, rollback scenarios, dependency handling, and fail-safe behavior for every patch.
  • Ensure patch content is stable and does not introduce regressions or system-level side effects.

5. Third-Party macOS Application Patching

  • Build accurate patch metadata for third-party macOS applications.
  • Develop packaging and deployment workflows for DMG, PKG, and ZIP installer formats.

Required Skills

  • Strong understanding of macOS architecture, filesystem structure, and system internals.
  • Practical experience with:
  • macOS software update mechanisms (Software Update, softwareupdate CLI)
  • PKG/DMG packaging and installer behavior
  • Launch Daemons and macOS system services
  • Mandatory scripting proficiency in Bash and Python (Zsh a plus).
  • Experience with Jamf Pro, Kandji, Intune, Munki, or Google Workspace would be a plus.
  • Experience with Mac vulnerability management and Mac patch management.
  • Solid understanding of CVE/NVD data, vulnerability severity scoring (CVSS), and patch supersedence logic.
  • Experience with enterprise patch management tools is preferred (e.g., Ivanti Patch for Endpoint Manager, ManageEngine Patch Manager Plus, or similar platforms).
  • Familiarity with Apple's MDM (Mobile Device Management) framework and Apple Business Manager.
  • Knowledge of Secure Token and FileVault handling.
  • Clear understanding of the architectural differences between Apple Silicon (ARM64) and Intel-based macOS systems.
Qualys

About Qualys

Qualys, Inc. (NASDAQ: QLYS) is a leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

The Qualys Enterprise TruRisk Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices.

Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Foster City, CA
Year Founded
1999
Social Media