Gruve

Network & Systems Engineer (Vulnerability Management)

Gruve Dubai, Dubai, United Arab Emirates

IT Services and IT Consulting · 501-1,000 employees

5 h ago
Mid (2-5 yrs) Full-time United Arab Emirates
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The engineer will manage the end-to-end vulnerability remediation cycle, including running scans, prioritizing findings, and applying patches to various enterprise assets. They will also act as the primary onsite point of contact for security audits, evidence requests, and operational meetings.

What they look for

Vulnerability Management Qualys VMDR Patch Management Windows Server Linux Network Security Splunk Active Directory Microsoft Exchange VMware Hyper-V ITIL Change Management Cybersecurity Firewalls Scripting

Requirements

Candidates must have 3-6 years of experience in network and systems engineering with hands-on expertise in patching and vulnerability management. Proficiency with Qualys VMDR, Windows/Linux server administration, and ITIL change management processes is required.

Full description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position Summary

The onsite engineer is Gruve's day-to-day presence at the customer site and the hands-on owner of the remediation cycle on the client's premises. Working from the client's own environment, the engineer runs Qualys VMDR scans, obtains vulnerability details, prioritises findings with the system owners face to face, and fixes and patches the affected end devices under formal change management with tested rollback. The role also covers physical and locally restricted assets that cannot be reached remotely, performs the daily client upload during business hours, and represents the service in the client's operational and change meetings

Key Responsibilities

  • Run Qualys VMDR scans from the client environment and extract vulnerability details, severities, affected assets, and remediation guidance.
  • Prioritise findings with the client's infrastructure, application, and security owners in person, aligned to ALKASHIF threat context and asset criticality.
  • Fix vulnerabilities and apply patches across in-scope end devices — Windows and Linux servers, Microsoft Exchange, Active Directory, enterprise applications and databases, network devices (routers/switches), security devices (firewalls/NAC/IPS/IDS), cloud workloads, and virtualization (VMware/Hyper-V).
  • Remediate assets that require onsite or locally-restricted access — isolated/air-gapped segments, out-of-band and console access, jump hosts, appliances and physical devices not reachable from outside the client network.
  • Raise and execute Change Requests for each patching activity — impact, risk classification, schedule, and tested rollback — and attend the client's CAB and operational meetings onsite.
  • Execute patching within approved maintenance windows using staggered rollout, with the ability to intervene physically if a change fails.
  • Perform post-remediation verification re-scans and keep the vulnerability register and aging report current to verified closure.
  • Perform the daily Client upload via the Qualys Splunk Add-on during business hours; monitor upload health and troubleshoot the Add-on so Availability stays compliant.
  • Coordinate handover to the offsite engineer (Engineer 2) for after-hours and weekend continuation of open remediation activity.
  • Act as the customer-facing point of contact onsite for VM queries, evidence requests, audits, and site walkthroughs.
  • Contribute findings, patch-time, coverage, and availability data to the weekly and monthly reporting pack.

Basic Qualifications

  • 3–6 years in network/systems engineering with hands-on patching and vulnerability remediation.
  • Familiar with Qualys (VMDR) to run scans and obtain vulnerability details and reports; Qualys Splunk Add-on familiarity strongly preferred.
  • Strong hands-on patching of Windows Server and Linux (WSUS/SCCM, package managers), including Microsoft Exchange and Active Directory.
  • Able to patch/upgrade network devices (routers/switches), security devices (firewalls/NAC/IPS/IDS), virtualization hosts (VMware/Hyper-V), and cloud workloads.
  • Comfortable working in a data centre / server-room environment, including console, out-of-band, and physical device access.
  • Understanding of CVSS/CVE, the vulnerability management lifecycle, and ITIL change management / CR processes with rollback.
  • Familiarity with Splunk/SIEM; scripting (PowerShell / Bash) an advantage.
  • Strong customer-facing communication, documentation, coordination, and written-English skills — this role sits with the client every day.
  • Must be able to work onsite in Dubai full time and pass the client's security screening / site access requirements.

Preferred Qualifications

  • Preferred the certifications in Qualys VMDR; MCSA / RHCSA (Windows / Linux); CompTIA Security+ / Network+; CCNA; Azure Administrator; ITIL Foundation
  • Presentable and confident in front of stakeholders;
  • Disciplined about daily cadence and SLAs
  • Comfortable performing production changes within maintenance windows with rollback discipline in a governed,
  • Audit-Ready Environment

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.