# BigFix Administrator

**Company:** [Cyber Shell, LLC](https://jobs.workable.com/companies/opzBXLwdBAb7Hh58qC7Bxr.md)
**Location:** Washington, United States
**Workplace:** on site
**Employment type:** Full-time

[Apply for this job](https://jobs.workable.com/view/ae6d6258-7b2c-48e5-8bd1-6c74f36ec8fe)

## Description

We are seeking a BigFix Administrator to join a three-person vulnerability remediation surge team supporting a federal agency headquarters in downtown Washington, DC.

This is hands-on patching work at enterprise scale: authoring BigFix fixlets and baselines, driving Intune update rings and compliance policies, validating every fix, and documenting it to federal audit standards.

On a typical day you will:

-   Deploy, test, and validate patches across all impacted environments using IBM BigFix and Microsoft Intune, following the full patch lifecycle; testing, phased deployment, and rollback procedures
-   Author BigFix fixlets and manage baselines, using the Relevance language, and produce remediation reporting
-   Analyze assigned vulnerabilities to assess risk and potential business impact, and map scanner findings (Tenable/Nessus, Qualys) to specific remediation actions
-   Coordinate with the federal vulnerability lead on assignment, tracking, prioritization, and remediation sequencing
-   Partner with the customer experience team to remediate third-party software vulnerabilities (Adobe, Java, browsers, runtime libraries)
-   Develop compensating controls or temporary mitigations when immediate patching poses operational risk
-   Document all remediation actions in ServiceNow to audit and compliance standards, and produce technical validation evidence packages (rescans, test results) confirming closure
-   Support follow-up vulnerability scans with the agency's cybersecurity office to confirm patching resolved the identified gaps
-   Follow the agency's change-control process for every change, and contribute to weekly status reports on progress, blockers, and completion metrics

Performance targets are explicit: 100% of assigned vulnerabilities remediated, ≥90% of scheduled remediation activities completed on time, and ≤10% of remediated findings reopened for rework.

## Requirements

-   Demonstrated enterprise vulnerability management experience, including IBM BigFix patch and remediation deployment; fixlet authoring, Relevance language, baseline management, and reporting
-   Microsoft Intune (Endpoint Manager) experience; device configuration, update rings, compliance policies, and application deployment
-   Enterprise patch lifecycle experience; testing, phased deployment, and rollback procedures
-   Windows 11 and Windows Server (2016–2022+) patching and hardening
-   WSUS / SCCM / MECM experience
-   Group Policy (GPO) configuration and remediation
-   Familiarity with DISA STIGs / CIS Benchmarks
-   Third-party application patching (Adobe, Java, browsers, runtime libraries)
-   Software inventory and version management
-   Ability to interpret vulnerability scanner output (Tenable/Nessus, Qualys) and map findings to remediation actions
-   Experience with the ServiceNow ITSM platform, including incident, problem, and change management workflows
-   U.S. citizenship required (direct access to sensitive system configurations) and ability to obtain and maintain a federal suitability determination (background investigation required)
-   On-site in downtown Washington, DC five days per week for the first two months; limited telework may be authorized afterward at the government's discretion. Subject to occasional off-hours or on-call work for maintenance and incident management
-   Preferred: Linux patching (RHEL/CentOS/Ubuntu; yum/dnf/apt), kernel and package management, and service hardening; Bash scripting, with Ansible automation strongly preferred; Tenable.sc/.io proficiency; understanding of CVSS scoring and the CISA KEV catalog; SQL skills for identifying affected systems and validating remediation status; Security+, CySA+, RHCSA, or Microsoft certifications
-   BigFix experience is a MUST

## Benefits

We offer a comprehensive benefits package designed to support you and your family:

-   Medical (HSA-qualified UnitedHealthcare plan), dental, and vision coverage; company pays 75% of employee premiums
-   $100,000 company-paid life & AD&D insurance, with optional voluntary buy-up coverage for you and your family
-   Short-term and long-term disability insurance, 100% company paid
-   401(k) with an automatic 3% company contribution; immediately vested, yours whether or not you contribute
-   11 paid federal holidays, 10 vacation days (growing to 20 with tenure), and 10 sick days per year
-   Company-paid certification exams and renewals
-   Tuition reimbursement up to $5,000 per year
