BigFix Administrator

Cyber Shell, LLC

Washington (District of Columbia)

On-site

USD 120,000 - 150,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health benefits
Life & AD&D insurance
Disability insurance
401(k) plan
Holidays and leave
Certification exams
Tuition reimbursement

Job summary

Cyber Shell, LLC seeks a BigFix Administrator to join a three-person vulnerability remediation surge team supporting a federal agency in downtown Washington, DC. The role focuses on enterprise patching, fixlet authoring, baselines, and remediation reporting to federal audit standards.

On-site in DC five days a week for the first two months, with potential limited telework thereafter. You will deploy patches with BigFix and Intune, coordinate with the vulnerability lead, and document actions in

Qualifications

  • Hands-on enterprise patching across environments using BigFix and Intune.
  • Author BigFix fixlets and baselines using Relevance language and produce remediation reporting.
  • Analyze vulnerabilities and map findings to remediation actions (Tenable/Nessus, Qualys).
  • Coordinate with federal vulnerability lead on assignment, tracking, prioritization, and sequencing.
  • Remediate third-party software vulnerabilities (Adobe, Java, browsers).
  • Document remediation actions in ServiceNow to audit standards.
  • On-site in Washington, DC five days per week for the first two months.

Responsibilities

  • Develop compensating controls or temporary mitigations when immediate patching poses operational risk.
  • Document remediation actions and evidence packages for audits.
  • Support follow-up vulnerability scans to verify patching.
  • Follow agency change-control processes and contribute to weekly status reports.

Skills

BigFix patching
Intune management
Vulnerability management
Relevance language
Baseline management
Reporting
GPO
DISA STIGs
Third-party patching
Incident/change coordination
Ansible (preferred)

Tools

IBM BigFix
Microsoft Intune
Tenable Nessus
Qualys
ServiceNow ITSM
WSUS/SCCM

Job description

We are seeking a BigFix Administrator to join a three-person vulnerability remediation surge team supporting a federal agency headquarters in downtown Washington, DC.

This is hands-on patching work at enterprise scale: authoring BigFix fixlets and baselines, driving Intune update rings and compliance policies, validating every fix, and documenting it to federal audit standards.

On a typical day you will:

  • Deploy, test, and validate patches across all impacted environments using IBM BigFix and Microsoft Intune, following the full patch lifecycle; testing, phased deployment, and rollback procedures
  • Author BigFix fixlets and manage baselines, using the Relevance language, and produce remediation reporting
  • Analyze assigned vulnerabilities to assess risk and potential business impact, and map scanner findings (Tenable/Nessus, Qualys) to specific remediation actions
  • Coordinate with the federal vulnerability lead on assignment, tracking, prioritization, and remediation sequencing
  • Partner with the customer experience team to remediate third-party software vulnerabilities (Adobe, Java, browsers, runtime libraries)
  • Develop compensating controls or temporary mitigations when immediate patching poses operational risk
  • Document all remediation actions in ServiceNow to audit and compliance standards, and produce technical validation evidence packages (rescans, test results) confirming closure
  • Support follow-up vulnerability scans with the agency's cybersecurity office to confirm patching resolved the identified gaps
  • Follow the agency's change-control process for every change, and contribute to weekly status reports on progress, blockers, and completion metrics

Performance targets are explicit: 100% of assigned vulnerabilities remediated, ≥90% of scheduled remediation activities completed on time, and ≤10% of remediated findings reopened for rework.

  • Demonstrated enterprise vulnerability management experience, including IBM BigFix patch and remediation deployment; fixlet authoring, Relevance language, baseline management, and reporting
  • Microsoft Intune (Endpoint Manager) experience; device configuration, update rings, compliance policies, and application deployment
  • Enterprise patch lifecycle experience; testing, phased deployment, and rollback procedures
  • Windows 11 and Windows Server (2016–2022+) patching and hardening
  • WSUS / SCCM / MECM experience
  • Group Policy (GPO) configuration and remediation
  • Familiarity with DISA STIGs / CIS Benchmarks
  • Third-party application patching (Adobe, Java, browsers, runtime libraries)
  • Software inventory and version management
  • Ability to interpret vulnerability scanner output (Tenable/Nessus, Qualys) and map findings to remediation actions
  • Experience with the ServiceNow ITSM platform, including incident, problem, and change management workflows
  • U.S. citizenship required (direct access to sensitive system configurations) and ability to obtain and maintain a federal suitability determination (background investigation required)
  • On-site in downtown Washington, DC five days per week for the first two months; limited telework may be authorized afterward at the government's discretion. Subject to occasional off-hours or on-call work for maintenance and incident management
  • Preferred: Linux patching (RHEL/CentOS/Ubuntu; yum/dnf/apt), kernel and package management, and service hardening; Bash scripting, with Ansible automation strongly preferred; Tenable.sc/.io proficiency; understanding of CVSS scoring and the CISA KEV catalog; SQL skills for identifying affected systems and validating remediation status; Security+, CySA+, RHCSA, or Microsoft certifications
  • BigFix experience is a MUST

We offer a comprehensive benefits package designed to support you and your family:

  • Medical (HSA-qualified UnitedHealthcare plan), dental, and vision coverage; company pays 75% of employee premiums
  • $100,000 company-paid life & AD&D insurance, with optional voluntary buy-up coverage for you and your family
  • Short-term and long-term disability insurance, 100% company paid
  • 401(k) with an automatic 3% company contribution; immediately vested, yours whether or not you contribute
  • 11 paid federal holidays, 10 vacation days (growing to 20 with tenure), and 10 sick days per year
  • Company-paid certification exams and renewals
  • Tuition reimbursement up to $5,000 per year
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Management Engineer
Vulnerability Management Engineer

IntelliDyne, LLC • Washington

On-site
USD 120,000 - 180,000
Medical, dental, vision
401(K) with company match
Flexible Paid Time Off
+7
BigFix Patch Lead – Enterprise Vulnerability Remediation
BigFix Patch Lead – Enterprise Vulnerability Remediation

Cyber Shell, LLC • Washington

On-site
USD 120,000 - 150,000
Health benefits
Life & AD&D insurance
Disability insurance
+4
Vulnerability Management Lead
Vulnerability Management Lead

ECS Corporate Services • Fairfax (VA)

Remote
USD 115,000 - 135,000
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

On-site
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability Management Manager
Vulnerability Management Manager

Considine Search • New York (NY)

On-site
USD 200,000 - 215,000
BigFix Engineer
BigFix Engineer

Four Inc. • Herndon (VA)

On-site
USD 110,000 - 140,000
Hybrid work environment
Vulnerability remediation (Patch Management) Engineer
Vulnerability remediation (Patch Management) Engineer

BuzzClan LLC • New York (NY)

Hybrid
USD 110,000 - 165,000
Vulnerability Management Lead
Vulnerability Management Lead

ecsfederal • Virginia (MN)

Hybrid
USD 115,000 - 135,000
System / Cloud Administrator
System / Cloud Administrator

Integral Consulting Services, Inc. • Fort Meade (MD), Northern (KY)

On-site
USD 120,000 - 140,000
VULNERABILITY MGMT ANALYST
VULNERABILITY MGMT ANALYST

Arete Associates • Falls Church (VA)

On-site
USD 110,000 - 150,000
Flextime Scheduling
Bereavement
PTO
+8