Quick Overview
Job Description
We are seeking a BigFix Administrator to join a three-person vulnerability remediation surge team supporting a federal agency headquarters in downtown Washington, DC.
This is hands-on patching work at enterprise scale: authoring BigFix fixlets and baselines, driving Intune update rings and compliance policies, validating every fix, and documenting it to federal audit standards.
On a typical day you will:
- Deploy, test, and validate patches across all impacted environments using IBM BigFix and Microsoft Intune, following the full patch lifecycle; testing, phased deployment, and rollback procedures
- Author BigFix fixlets and manage baselines, using the Relevance language, and produce remediation reporting
- Analyze assigned vulnerabilities to assess risk and potential business impact, and map scanner findings (Tenable/Nessus, Qualys) to specific remediation actions
- Coordinate with the federal vulnerability lead on assignment, tracking, prioritization, and remediation sequencing
- Partner with the customer experience team to remediate third-party software vulnerabilities (Adobe, Java, browsers, runtime libraries)
- Develop compensating controls or temporary mitigations when immediate patching poses operational risk
- Document all remediation actions in ServiceNow to audit and compliance standards, and produce technical validation evidence packages (rescans, test results) confirming closure
- Support follow-up vulnerability scans with the agency's cybersecurity office to confirm patching resolved the identified gaps
- Follow the agency's change-control process for every change, and contribute to weekly status reports on progress, blockers, and completion metrics
Performance targets are explicit: 100% of assigned vulnerabilities remediated, ≥90% of scheduled remediation activities completed on time, and ≤10% of remediated findings reopened for rework.
- Demonstrated enterprise vulnerability management experience, including IBM BigFix patch and remediation deployment; fixlet authoring, Relevance language, baseline management, and reporting
- Microsoft Intune (Endpoint Manager) experience; device configuration, update rings, compliance policies, and application deployment
- Enterprise patch lifecycle experience; testing, phased deployment, and rollback procedures
- Windows 11 and Windows Server (2016–2022+) patching and hardening
- WSUS / SCCM / MECM experience
- Group Policy (GPO) configuration and remediation
- Familiarity with DISA STIGs / CIS Benchmarks
- Third-party application patching (Adobe, Java, browsers, runtime libraries)
- Software inventory and version management
- Ability to interpret vulnerability scanner output (Tenable/Nessus, Qualys) and map findings to remediation actions
- Experience with the ServiceNow ITSM platform, including incident, problem, and change management workflows
- U.S. citizenship required (direct access to sensitive system configurations) and ability to obtain and maintain a federal suitability determination (background investigation required)
- On-site in downtown Washington, DC five days per week for the first two months; limited telework may be authorized afterward at the government's discretion. Subject to occasional off-hours or on-call work for maintenance and incident management
- Preferred: Linux patching (RHEL/CentOS/Ubuntu; yum/dnf/apt), kernel and package management, and service hardening; Bash scripting, with Ansible automation strongly preferred; Tenable.sc/.io proficiency; understanding of CVSS scoring and the CISA KEV catalog; SQL skills for identifying affected systems and validating remediation status; Security+, CySA+, RHCSA, or Microsoft certifications
- BigFix experience is a MUST
We offer a comprehensive benefits package designed to support you and your family:
- Medical (HSA-qualified UnitedHealthcare plan), dental, and vision coverage; company pays 75% of employee premiums
- $100,000 company-paid life & AD&D insurance, with optional voluntary buy-up coverage for you and your family
- Short-term and long-term disability insurance, 100% company paid
- 401(k) with an automatic 3% company contribution; immediately vested, yours whether or not you contribute
- 11 paid federal holidays, 10 vacation days (growing to 20 with tenure), and 10 sick days per year
- Company-paid certification exams and renewals
- Tuition reimbursement up to $5,000 per year
Similar jobs
- GI
Systems Administrator Senior, Advanced Concepts and Technologies with Security Clearance
NewGemini Industries Inc.
Fort Washington, MD🇺🇸$120k - $130k/yrHybridYesterdayAgileGenerative AIUnityTechnology - ER
Systems Administrator with Security Clearance
NewEpiphany Resource Group
Springfield, VA🇺🇸HybridYesterdayTechnology - MT
Senior System Administrator with Security Clearance
NewMissionEdge Technologies, LLC
Fort Meade, MD🇺🇸$173.4k/yrHybridYesterdayEncryptionTechnology - AS
System Administrator with Security Clearance
NewASEC, Inc
Fallon, NV🇺🇸On-siteYesterdayActive DirectoryLESSTechnology - BO
Systems Engineer (Experienced or Lead)
NewBoeing
Saint Charles, Missouri🇺🇸$112.2k - $151.8k/yrOn-site26 minutes agoAzureC#C+++3Technology - GD
IT Systems Administrator (TS/SCI with Full Scope Polygraph Clear with Security Clearance
NewGeneral Dynamics Mission Systems
Scottsdale, AZ🇺🇸$111.9k - $124.1k/yrHybridYesterdayBlockchainAR/VRTechnology