We are looking for a Windows platform expert with deep, hands-on scripting skills (PowerShell preferred) to own the security hardening, imaging, and deployment automation of the Windows environment underlying our FFRangio system.
You'll work at the intersection of low-level Windows internals (boot security, disk encryption, image management) and modern Windows virtualization and DevOps practices (CI/CD pipelines), helping us build a secure, locked down, and reliably reproducible Windows environment for a regulated medical device product.
You should be comfortable going deep - from BIOS settings and TPM chains up through image-building and pipeline automation - and who treats scripting as the primary tool for making security and deployment repeatable, auditable, and reliable, in service of a real clinical product used in the Cath lab.
Responsibilities may include the following and other duties may be assigned:
Design, implement, and maintain PowerShell-based automation for system configuration, hardening, and deployment of FFRangio Windows workstations.
Define and enforce BIOS/UEFI security settings and TPM-based trust chains (Secure Boot, measured boot, TPM attestation).
Implement and manage BitLocker and other Windows encryption mechanisms, including key management and recovery strategies.
Build and maintain Windows hardening baselines using Group Policy, AppLocker, custom Shell/UI restrictions, and Kiosk (Assigned Access) mode suited to a clinical, cath-lab environment.
Manage user/account permission models and least-privilege access schemes across managed devices.
Create, manipulate, and maintain VHD/VHDX-based images for deployment, recovery, and testing workflows.
Build and maintain CI/CD pipelines in Azure DevOps for automated build, test, and deployment of Windows images and configurations.
Collaborate with software, QA, and regulatory/quality teams to ensure hardening and deployment practices.
Document configurations, scripts, and processes for reproducibility and audit purposes, consistent with medical device quality system requirements.
Requirements: Required Knowledge and Experience:
B.Sc. in Computer Science, Software Engineering, Computer Engineering, Mathematics, or a related field
4+ years of relevant experience in Windows systems engineering, software engineering, security, or automation
Strong, demonstrable PowerShell scripting skills
Solid understanding of BIOS/UEFI security concepts and TPM (Trusted Platform Module) architecture
Experience with BitLocker and Windows encryption/hardening tools: Group Policy design and management AppLocker rule creation and enforcement Kiosk mode / Assigned Access / custom shell configuration Windows account, group, and permission management
Experience creating and manipulating VHD/VHDX virtual disks (mounting, provisioning, offline servicing, diskpart/DISM)
Strong troubleshooting skills across the Windows boot chain, OS internals, and security stack
This position is open to all candidates.