Cybersecurity Tools Administrator
Sign up free to see how well your resume matches this role.
What you'll do
- Administer Trellix ePolicy Orchestrator (ePO): configure policies, tasks, and client assignments; perform agent deployment/updates; monitor health and compliance across Windows/Linux endpoints.
- Implement and maintain cybersecurity toolsets including ESS/ENS, EDR, NDR, and malware protection; tune detections and containment to reduce false positives while improving fidelity.
- Integrate endpoint tools with enterprise SIEM/SOAR (e.g., Splunk) and vulnerability management stacks (e.g., Nessus/ACAS) to enable unified visibility, correlation, and automated response.
- Develop and maintain dashboards, reports, and KPIs for endpoint coverage, policy compliance, threat activity, and vulnerability remediation progress.
- Conduct enterprise-wide agent posture checks; remediate orphaned agents, stale policies, connectivity issues, and broken update channels.
- Author and maintain standard operating procedures (SOPs), change records, and implementation plans; follow standardized test, certification, and deployment procedures.
- Support incident response by providing endpoint forensics, containment actions (e.g., DAC), isolation, and IOC sweep capability; assist with root-cause analysis and corrective actions.
- Coordinate with Systems Administrators, Network Engineers, and Cybersecurity personnel to assess risks, validate configurations, and enforce security controls in accordance with RMF/NIST 800-53.
- Ensure tool and control configuration compliance; review change requests; validate effectiveness of security controls across virtualized Windows/Linux servers and enterprise networks.
- Maintain detailed documentation including release notes, configuration baselines, incident investigations, and compliance/authorization artifacts.
What they're looking for
- Experience with Trellix ePolicy Orchestrator (ePO) including configuring policies, tasks, and client assignments
- Experience with cybersecurity toolsets including ESS/ENS, EDR, NDR, and malware protection
- Experience integrating endpoint tools with enterprise SIEM/SOAR (e.g., Splunk) and vulnerability management stacks (e.g., Nessus/ACAS)
- Knowledge of RMF/NIST 800-53 frameworks
- Experience managing Windows and Linux endpoints
- Ability to work on-site in Springfield, VA
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
SAIC is seeking a motivated Cybersecurity Tools Administrator to join our MAJESTIC Joint Program Office (JPO) Team in support of an on-premises enterprise IT environment. This role focuses on implementing, administering, and optimizing cybersecurity toolsets centered on Trellix Endpoint Security (ENS) and integrated capabilities such as Endpoint Detection & Response (EDR), Network Detection & Response (NDR), and malware protection. The administrator will manage policy, deployment, health/compliance, telemetry, and integrations with SIEM/SOAR to strengthen enterprise security posture.
All work is performed on-site in Springfield, VA.
Key Responsibilities:
- Administer Trellix ePolicy Orchestrator (ePO): configure policies, tasks, and client assignments; perform agent deployment/updates; monitor health and compliance across Windows/Linux endpoints.
- Implement and maintain cybersecurity toolsets including ESS/ENS, EDR, NDR, and malware protection; tune detections and containment to reduce false positives while improving fidelity.
- Integrate endpoint tools with enterprise SIEM/SOAR (e.g., Splunk) and vulnerability management stacks (e.g., Nessus/ACAS) to enable unified visibility, correlation, and automated response.
- Develop and maintain dashboards, reports, and KPIs for endpoint coverage, policy compliance, threat activity, and vulnerability remediation progress.
- Conduct enterprise-wide agent posture checks; remediate orphaned agents, stale policies, connectivity issues, and broken update channels.
- Author and maintain standard operating procedures (SOPs), change records, and implementation plans; follow standardized test, certification, and deployment procedures.
- Support incident response by providing endpoint forensics, containment actions (e.g., DAC), isolation, and IOC sweep capability; assist with root-cause analysis and corrective actions.
- Coordinate with Systems Administrators, Network Engineers, and Cybersecurity personnel to assess risks, validate configurations, and enforce security controls in accordance with RMF/NIST 800-53.
- Ensure tool and control configuration compliance; review change requests; validate effectiveness of security controls across virtualized Windows/Linux servers and enterprise networks.
- Maintain detailed documentation including release notes, configuration baselines, incident investigations, and compliance/authorization artifacts.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.