Requirements
• Demonstrated enterprise vulnerability management experience, including IBM BigFix patch and remediation deployment; fixlet authoring, Relevance language, baseline management, and reporting
• Microsoft Intune (Endpoint Manager) experience; device configuration, update rings, compliance policies, and application deployment
• Enterprise patch lifecycle experience; testing, phased deployment, and rollback procedures
• Windows 11 and Windows Server (2016–2022+) patching and hardening
• WSUS / SCCM / MECM experience
• Group Policy (GPO) configuration and remediation
• Familiarity with DISA STIGs / CIS Benchmarks
• Third-party application patching (Adobe, Java, browsers, runtime libraries)
• Software inventory and version management
• Ability to interpret vulnerability scanner output (Tenable/Nessus, Qualys) and map findings to remediation actions
• Experience with the ServiceNow ITSM platform, including incident, problem, and change management workflows
• U.S. citizenship required (direct access to sensitive system configurations) and ability to obtain and maintain a federal suitability determination (background investigation required)
• On-site in downtown Washington, DC five days per week for the first two months; limited telework may be authorized afterward at the government's discretion. Subject to occasional off-hours or on-call work for maintenance and incident management
• Preferred: Linux patching (RHEL/CentOS/Ubuntu; yum/dnf/apt), kernel and package management, and service hardening; Bash scripting, with Ansible automation strongly preferred; Tenable.sc/.io proficiency; understanding of CVSS scoring and the CISA KEV catalog; SQL skills for identifying affected systems and validating remediation status; Security+, CySA+, RHCSA, or Microsoft certifications
• BigFix experience is a MUST
Benefits
We offer a comprehensive benefits package designed to support you and your family:
• Medical (HSA-qualified UnitedHealthcare plan), dental, and vision coverage; company pays 75% of employee premiums
• $100,000 company-paid life & AD&D insurance, with optional voluntary buy-up coverage for you and your family
• Short-term and long-term disability insurance, 100% company paid
• 401(k) with an automatic 3% company contribution; immediately vested, yours whether or not you contribute
• 11 paid federal holidays, 10 vacation days (growing to 20 with tenure), and 10 sick days per year
• Company-paid certification exams and renewals
• Tuition reimbursement up to $5,000 per year
Job description
We are seeking a BigFix Administrator to join a three-person vulnerability remediation surge team supporting a federal agency headquarters in downtown Washington, DC.
This is hands-on patching work at enterprise scale: authoring BigFix fixlets and baselines, driving Intune update rings and compliance policies, validating every fix, and documenting it to federal audit standards.
On a typical day you will:
• Deploy, test, and validate patches across all impacted environments using IBM BigFix and Microsoft Intune, following the full patch lifecycle; testing, phased deployment, and rollback procedures
• Author BigFix fixlets and manage baselines, using the Relevance language, and produce remediation reporting
• Analyze assigned vulnerabilities to assess risk and potential business impact, and map scanner findings (Tenable/Nessus, Qualys) to specific remediation actions
• Coordinate with the federal vulnerability lead on assignment, tracking, prioritization, and remediation sequencing
• Partner with the customer experience team to remediate third-party software vulnerabilities (Adobe, Java, browsers, runtime libraries)
• Develop compensating controls or temporary mitigations when immediate patching poses operational risk
• Document all remediation actions in ServiceNow to audit and compliance standards, and produce technical validation evidence packages (rescans, test results) confirming closure
• Support follow-up vulnerability scans with the agency's cybersecurity office to confirm patching resolved the identified gaps
• Follow the agency's change-control process for every change, and contribute to weekly status reports on progress, blockers, and completion metrics
Performance targets are explicit: 100% of assigned vulnerabilities remediated, ≥90% of scheduled remediation activities completed on time, and ≤10% of remediated findings reopened for rework.
• Demonstrated enterprise vulnerability management experience, including IBM BigFix patch and remediation deployment; fixlet authoring, Relevance language, baseline management, and reporting
• Microsoft Intune (Endpoint Manager) experience; device configuration, update rings, compliance policies, and application deployment
• Enterprise patch lifecycle experience; testing, phased deployment, and rollback procedures
• Windows 11 and Windows Server (2016–2022+) patching and hardening
• WSUS / SCCM / MECM experience
• Group Policy (GPO) configuration and remediation
• Familiarity with DISA STIGs / CIS Benchmarks
• Third-party application patching (Adobe, Java, browsers, runtime libraries)
• Software inventory and version management
• Ability to interpret vulnerability scanner output (Tenable/Nessus, Qualys) and map findings to remediation actions
• Experience with the ServiceNow ITSM platform, including incident, problem, and change management workflows
• U.S. citizenship required (direct access to sensitive system configurations) and ability to obtain and maintain a federal suitability determination (background investigation required)
• On-site in downtown Washington, DC five days per week for the first two months; limited telework may be authorized afterward at the government's discretion. Subject to occasional off-hours or on-call work for maintenance and incident management
• Preferred: Linux patching (RHEL/CentOS/Ubuntu; yum/dnf/apt), kernel and package management, and service hardening; Bash scripting, with Ansible automation strongly preferred; Tenable.sc/.io proficiency; understanding of CVSS scoring and the CISA KEV catalog; SQL skills for identifying affected systems and validating remediation status; Security+, CySA+, RHCSA, or Microsoft certifications
• BigFix experience is a MUST
We offer a comprehensive benefits package designed to support you and your family:
• Medical (HSA-qualified UnitedHealthcare plan), dental, and vision coverage; company pays 75% of employee premiums
• $100,000 company-paid life & AD&D insurance, with optional voluntary buy-up coverage for you and your family
• Short-term and long-term disability insurance, 100% company paid
• 401(k) with an automatic 3% company contribution; immediately vested, yours whether or not you contribute
• 11 paid federal holidays, 10 vacation days (growing to 20 with tenure), and 10 sick days per year
• Company-paid certification exams and renewals
• Tuition reimbursement up to $5,000 per year
GetGlobalJob is not the employer or a recruiting agency. You apply on the original publisher's site: always check the posting before sharing your details, and never pay for a job.