Haystack
← Back to Jobs
Technology
LE

Senior MECM Systems Administrator with Security Clearance

LeidosArlington, VA🇺🇸United StatesPosted Oct 9, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Arlington, VA, United States
Posted
21 hours ago
PowerShellSQLSQL ServerPower BIActive DirectoryPKI

Job Description

R-00194215 Description 1.

General Overview: The Digital Sector at Leidos is currently seeking a senior, hands-on Microsoft Endpoint Configuration Manager (MECM) Subject Matter Expert and Team Lead to support DISA J-6/J-9 in the Arlington, VA (Pentagon). This position leads enterprise MECM operations and a team of MECM administrators responsible for endpoint imaging, operating system deployment, application packaging, software update management, vulnerability remediation, configuration compliance, and MECM infrastructure sustainment.

The selected candidate will use MECM as a primary enterprise tool to rapidly remediate vulnerabilities and configuration deficiencies across Windows endpoints in OSD forest, OMS, and Platform Management domains operating on NIPRNet, SIPRNet, TS-C, and JWICS networks. The role requires strong technical leadership, extensive hands-on MECM expertise, and the ability to coordinate closely with Cyber Compliance, DCO, infrastructure teams, and government stakeholders to meet DISA STIG, IAVM, CTO, FRAGO, and other cyber-tasking suspense requirements. 2.

Primary Responsibilities: Team Leadership and MECM Operations- • Lead the MECM team, including work assignment, technical oversight, mentoring, quality assurance, and escalation support for MECM Intermediate SMEs and System Administrators. • Serve as the authoritative technical point of contact for MECM operations, enterprise endpoint-management capabilities, and vulnerability-remediation execution. • Establish and maintain standard operating procedures, deployment standards, testing requirements, rollback plans, and change-control documentation for MECM services. • Coordinate with DISA J-6/J-9, Cyber Compliance/IA personnel, DCO, server, network, database, and application teams to resolve endpoint-management issues and execute enterprise remediation initiatives. • Brief MECM operational status, vulnerability-remediation progress, technical risks, and decisions required to DISA J-6/J-9 leadership and the Monthly Integrated Product Review (IPR).

Vulnerability Remediation and Patch Management- • Own an aggressive vulnerability-remediation posture using MECM to package, test, deploy, validate, and report remediation for patches, hotfixes, cumulative updates, third-party software updates, configuration changes, and security baselines. • Drive remediation of DISA Security Technical Implementation Guide (STIG) findings, Information Assurance Vulnerability Management (IAVM) notices, Cyber Tasking Orders (CTOs), FRAGOs, and other cyber tasking within or ahead of established suspense dates. • Use MECM Software Update Management, compliance baselines, configuration items, PowerShell scripts, task sequences, and Group Policy changes to remediate vulnerabilities and configuration deficiencies. • Establish and maintain automated deployment rings, phased rollout strategies, pilot groups, maintenance windows, and emergency-patching procedures that balance remediation speed with operational stability. • Prioritize remediation based on vulnerability severity, exploitability, asset criticality, affected endpoint population, IAVM suspense, mission impact, and available compensating controls. • Correlate MECM deployment and compliance data with ACAS/Tenable scan results, Trellix endpoint-security data, and other cyber-tool outputs to identify remediation gaps and validate closure. • Support POA&M development and updates; provide technical evidence, deployment results, scan validation, and remediation artifacts for CCORI, inspections, audits, and cyber compliance reviews.

Imaging and Operating System Deployment- • Design, develop, maintain, and troubleshoot MECM operating system deployment (OSD) capabilities for enterprise Windows endpoints. • Build and sustain task sequences for new system deployment, hardware refresh, operating system upgrades, break/fix replacement, reimaging, security-tool installation, domain join, baseline configuration, and post-build application deployment. • Manage and maintain operating system images, boot images, driver packages, driver-selection logic, PXE services, boot media, user-state migration processes, and supporting deployment content. • Develop automated endpoint-build processes that reduce technician touch time, improve deployment consistency, and ensure systems are configured to approved security and operational standards. • Troubleshoot OSD failures involving PXE, boot images, task sequences, driver injection, content availability, network connectivity, certificates, domain join, and post-build software installation. • Coordinate imaging and deployment support during hardware lifecycle refreshes, Windows version upgrades, and major enterprise technology transitions.

Application Packaging and Software Deployment- • Package, test, deploy, and maintain enterprise applications using MECM application-management capabilities, MSI, EXE, PowerShell, scripts, and other approved installation methods. • Develop application detection methods, requirement rules, dependencies, relationships, return-code handling, uninstall procedures, and user-experience settings. • Maintain application deployment standards and packaging documentation to ensure consistent, reliable, and auditable software delivery. • Coordinate with application owners, cybersecurity personnel, and system stakeholders to deploy application upgrades, emergency patches, vulnerable-software removals, and security configuration changes. • Validate applications in pilot and phased-deployment rings before broad enterprise release; monitor deployments and rapidly address failures or unintended operational impacts. • Maintain software catalog accuracy, deployment content, and distribution-point availability to support timely enterprise application delivery.

MECM Infrastructure and Platform Sustainment- • Administer, maintain, and modernize enterprise MECM infrastructure, including site servers, management points, distribution points, software update points, WSUS integration, SQL Server back-end components, reporting services, and associated Windows Server infrastructure. • Ensure MECM infrastructure remains healthy, secure, patched, backed up, recoverable, and capable of meeting Group 1 restoration timelines. • Monitor and troubleshoot MECM site health, component status, client communication, content distribution, replication, software update synchronization, database performance, certificate status, and endpoint-management service availability. • Lead root-cause analysis and service restoration for MECM outages and performance issues, including failures related to SQL Server, WSUS, site components, distribution points, boundary groups, PKI, Active Directory, Group Policy, and client communication. • Maintain MECM current branch releases, hotfixes, cumulative updates, management packs, supporting Windows Server updates, and required security configurations. • Manage MECM backup, recovery, and restoration processes, ensuring backups are retained and stored away from the physical system in accordance with applicable policy and continuity requirements. • Plan, coordinate, test, and execute MECM upgrades, server refreshes, distribution-point migrations, and infrastructure lifecycle activities through the DISA J-6/J-9 Enterprise Change Management framework.

Automation, Reporting, and Compliance Metrics- • Develop and maintain PowerShell automation for patch deployment, vulnerability remediation, client-health correction, application deployment, inventory collection, reporting, and administrative tasks. • Create and sustain MECM task sequences, compliance baselines, configuration items, collections, queries, and deployment workflows that automate endpoint remediation at scale. • Produce weekly Microsoft Endpoint Operational Status and vulnerability-remediation metrics, including client health, software update compliance, deployment success rates, imaging status, application deployment status, and aging vulnerabilities. • Develop and maintain reports and dashboards using MECM reporting, SQL Server Reporting Services (SSRS), SQL queries, and/or Power BI. • Analyze remediation trends and recurring deployment failures; recommend process, automation, infrastructure, or policy improvements to improve compliance and reduce vulnerability aging 3.

Basic Qualifications: • Bachelor’s degree in Computer Engineering, Computer Information Systems, Telecommunications, Management Information Systems, Cybersecurity, or a related field; 8 – 12 years of prior relevant experience or Masters with 6 – 10 years of prior relevant experience. Specific experience, education and training may be considered in lieu of degree. • U.S.

Citizenship is a must. • Active Top Secret clearance or higher at time of consideration. • Must have a current DoD 8570.01-M / DoD 8140 IAT Level II baseline certification requirements before start date, such as Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent. • Computing Environment certification appropriate to the role, such as a current Microsoft endpoint-management or Windows Server certification, is required. • 100% onsite at a government facility within the National Capital Region, primarily at the Pentagon, Crystal Gateway, Taylor Building, Mark Center, or another DISA J-6/J-9-designated alternate site. • Candidate must reside in the DC Metro Area and have reliable transportation. • Must comply with all DoD, DISA, and DISA J-6/J-9 security and access protocols, including the ability to access NIPRNet and SIPRNet environments. • Seven (7) or more years of hands-on experience administering MECM/SCCM at enterprise scale, including experience serving as a senior technical authority, technical lead, or team lead. • Demonstrated experience leading or mentoring systems administrators, endpoint-management personnel, or technical teams. • Demonstrated experience using MECM to execute vulnerability remediation and improve patch compliance against DoW STIGs, IAVMs, DTO

Similar jobs