Verified today
Patch Research Engineer
About the role
The Patch Research Engineer role at the Pune, India office focuses on designing, developing, validating, and maintaining macOS patch metadata and deployment catalogues for enterprise patch management solutions. Day-to-day work includes researching Apple security advisories, building a centralized macOS patch content repository, writing detection and compliance logic, scripting in Bash/Python/Zsh, and performing lab-based QA across macOS versions and architectures. The position also covers third-party macOS application patching and packaging workflows for DMG, PKG, and ZIP installers.
What you’ll do
- Research and analyze security advisories published by Apple Inc. for macOS and related products.
- Create structured, schema-compliant macOS patch metadata covering version, architecture, detection, installation, and compliance fields.
- Build and maintain a centralized macOS patch catalogue repository.
- Continuously track new releases of macOS and other supported Apple and third-party products.
- Monitor Apple security bulletins and release notes to identify patch-relevant changes as they are published.
- Develop and validate detection logic using macOS system profiling commands and utilities.
- Apply knowledge of OS builds, application bundles (.app), and package receipts (.pkg) to construct accurate version-detection rules.
- Write and maintain automation scripts in Bash, Zsh, and Python to support content generation and validation.
What you’ll bring
- Strong understanding of macOS architecture, filesystem structure, and system internals.
- Practical experience with macOS software update mechanisms (Software Update, softwareupdate CLI).
- Practical experience with PKG/DMG packaging and installer behavior.
- Practical experience with Launch Daemons and macOS system services.
- Mandatory scripting proficiency in Bash and Python (Zsh a plus).
- Solid understanding of CVE/NVD data, vulnerability severity scoring (CVSS), and patch supersedence logic.
- Experience with Mac vulnerability management and Mac patch management.
- Clear understanding of architectural differences between Apple Silicon (ARM64) and Intel-based macOS systems.
Nice to have
- Experience with Jamf Pro, Kandji, Intune, Munki, or Google Workspace would be a plus.
- Experience with enterprise patch management tools is preferred (e.g., Ivanti Patch for Endpoint Manager, ManageEngine Patch Manager Plus, or similar platforms).
- Familiarity with Apple's MDM (Mobile Device Management) framework and Apple Business Manager.
- Knowledge of Secure Token and FileVault handling.