BigFix Engineer, Associate
Listed on 2025-12-31
-
IT/Tech
Cybersecurity, IT Support, Network Security, Systems Administrator
Location: Rockville, MD
Required Clearance: Public Trust
Onsite
:
Hybrid Work (Minimum 1 Day Onsite - minimum)
Job Title
:
Big Fix Engineer, Associate
Job Overview: The Big Fix Engineer, Associate responsible for operational cybersecurity support in a federal IT environment, with a primary emphasis on enterprise endpoint patching and compliance using IBM Big Fix. The specialist will manage and execute security patching, endpoint inventory validation, and compliance reporting across laptops and desktops, ensuring systems meet federal security and continuous monitoring requirements.
This role performs technical security tasks independently or under supervision of System Engineers, the Lead Computer Security System Specialist, the Information Systems Security Officer (ISSO), and/or the Contracting Officer’s Representative (COR). The position supports compliance with federal mandates including FISMA, and aligns to NIST, HHS, and NIH security policies and directives.
Key Responsibilities
Big Fix responsibilities include (but are not limited to):
- Lead and execute monthly enterprise patch deployments using IBM Big Fix for:
- Operating Systems
- Microsoft Office applications
- Microsoft security updates and supporting Microsoft products
- Maintain and validate Big Fix endpoint coverage:
- Ensure Big Fix agents are installed, properly configured, and consistently reporting
- Perform agent troubleshooting (connectivity, relay issues, policy failures, outdated agents, etc.)
- Support mandatory twice-yearly endpoint inventory verification, ensuring:
- All laptops/desktops are accounted for
- Security patches are up-to-date and verified
- Big Fix compliance data supports audit and reporting requirements
- Reports are produced confirming endpoint validation and remediation actions
- Create and deliver Big Fix compliance reports and metrics, including:
- Patch compliance baselines
- Deployment success/failure reporting
- Exception handling and remediation tracking
- Endpoint verification summaries for stakeholders
- Research, test, and recommend enhancements to:
- Patch deployment strategies
- Patch monitoring approaches
- Anti-virus and endpoint security enforcement
- Coordinate with security, desktop support, and system owners to remediate patch failures, non-compliance, and high severity vulnerabilities.
Security Desktop Support & Endpoint Security Operations
- Provide Security Desktop Support to ensure endpoint hardening, patch compliance, and continuous monitoring requirements are maintained.
- Assist in remediation of critical endpoint security events (high severity vulnerabilities, malware outbreaks, compliance failures).
- Provide assistance to the NIH Incident Response Team (IRT) and internal security teams in handling endpoint incidents and remediation activities, including containment and recovery support.
- Support security monitoring and enforcement of endpoint security baselines and authorized tools.
Vulnerability Management & Continuous Monitoring
- Perform and analyze system/application vulnerability scans using enterprise/federal tools.
- Analyze results from vulnerability scans and external penetration tests; support remediation and validation.
- Track vulnerability remediation efforts and provide reports internally and to federal stakeholders.
- Support continuous monitoring activities and reporting as mandated by NIH.
Malware Defense, Logging & Security Monitoring
- Manage anti-virus/malware detection, analysis, and remediation, including support for authorized AV consoles.
- Support log consolidation and analysis for endpoint and enterprise systems.
- Develop and enforce automated security processes supporting monitoring and compliance.
Security Incident Response & Forensics
- Provide comprehensive security incident support including notification, response, remediation, forensic support, reporting, and coordination with external stakeholders.
- Support investigations requested by NIH/HHS or other government agencies.
Security Assessment & Authorization (SA&A) Support
Under direction of the Federal Lead/ISSO, support documentation and compliance activities to ensure readiness for audits and re-authorization.
Key activities include:
- Maintain security artifacts and support SA&A activities (SSPs, POAsMs,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).