About this role
NOC Engineer – Backup, Alerts & Patch Remediation
About the role
This role owns the health of our managed client fleet: backups that run and can be restored, RMM alerts that get fixed rather than ignored, and patches and vulnerabilities that get closed. You'll work a remediation backlog down and keep it down.
Schedule
Business hours ET, an early-morning overnight-jobs check, and an after-hours escalation rotation.
What you'll do
Backups
- Triage failed, missed and warning backup jobs daily across Veeam servers, agents and cloud copies.
- Remote in through NinjaOne/ScreenConnect to fix storage, repository, network, licensing and upgrade issues.
- Run scheduled and on-request restore tests (SureBackup, file/VM) and write audit-ready evidence.
- Enforce the PTG backup standard: 3-2-1 with a cloud copy, minimum retention, encryption, and no synthetic fulls that overrun storage.
- Run the half-yearly backup audit and present the findings.
- Maintain VSPC: onboarding and offboarding, report recipients, and keeping the managed list matched to billing.
RMM alert remediation (NinjaOne)
- Work the open NinjaOne condition-alert queue to zero, fixing the root cause so the same device stops re-alerting.
- Antivirus/EDR health: AV missing, disabled or not updating, and unsupported AV installed.
- Low disk space on workstations and servers: cleanup, profile and temp clearing, and escalating hardware upgrades.
- Server and virtualization alerts: VMware/Hyper-V datastore free space, stale VM checkpoints, hardware sensors, high memory, and critical services down (e.g. ADSync).
- Device-offline alerts: confirm real outages and separate them from platform false positives.
- Tune alert conditions and thresholds so alerts are actionable, not noise.
Patching and vulnerabilities
- Remediate failed patches in NinjaOne: Windows cumulative/security updates and third-party applications, including stuck or half-finished patch runs and pending reboots.
- Install out-of-band updates manually when policy can't approve them.
- Remediate vulnerability-scanner findings: patch, upgrade, reconfigure or remove the affected software, then verify the finding clears.
- Report patch compliance and the open vulnerability backlog weekly.
General
- Own Halo tickets from alert to close, with clear notes.
- Produce the daily, weekly and monthly reports.
- Work CMMC client systems under their access controls.
- Keep credentials and runbooks current in Hudu.
Requirements
What you'll bring
- 3+ years in an MSP or IT ops role.
- Hands-on Veeam B&R: jobs, repositories, backup copy, agents and SureBackup.
- Day-to-day RMM alert remediation (NinjaOne preferred): AV/EDR health, disk space, services, offline devices.
- Windows patch troubleshooting: failed cumulative updates, servicing stack and component store repair (DISM/SFC), WSUS/Windows Update logs, and third-party patching.
- Vulnerability remediation from scanner findings, with a record of verifying the fix.
- Windows Server, Hyper-V/VMware, storage (NAS, iSCSI) and basic networking.
- Experience with object storage targets (Backblaze, Azure Blob, Cloud Connect), including immutability and quotas.
- Clear writing for both tickets and client reports.
- Disciplined credential handling. Must be able to pass a background check for CMMC access.
Nice to have
- VMCE; VSPC.
- Huntress or another EDR/ITDR platform.
- Veeam for M365 and Azure backup.
- CMMC / NIST 800-171.
- PowerShell for remediation scripts.
Tools
Veeam B&R and agents, VSPC, NinjaOne (alerting, conditions, patch management), ScreenConnect, Huntress, Hyper-V/VMware, object storage targets, Halo, Hudu.
Benefits
- (For full-time employees)
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Parental leave
- Professional development assistance
- Referral program
- Vision insurance
