- Senior
- Bureau à Fort Belvoir
HBSS/MDE Administrator SME
GES is seeking a skilled HBSS/MDE Administrator SME in Fort Belvoir, VA, to join the I3TS team supporting DTRA. The I3TS program provides enterprise-wide IT support to enable DTRA’s Information Management & Technology Directorate (ITD) to consolidate, modernize, and continuously innovate the delivery of IT services and mission capabilities to DTRA’s internal and external mission partners operating in CONUS and OCONUS locations. The candidate will be responsible for ensuring the security and integrity of IT systems by running their Endpoint Security with experience in Trellix and Microsoft Defender. The administrator will also be responsible for applying Security Technical Implementation Guides (STIGs), managing system patches, and overseeing vulnerability management processes. This role supports federal clients in maintaining compliance with the Department of Defense (DoD) and other federal cybersecurity standards.
The candidate will be responsible for identifying points of vulnerability, non-compliance with established Information Assurance (IA) guidelines and regulations and recommend mitigation strategies, along with assisting users as needed in a classified computing environment. The selected candidate must be able to work independently as well as with a team of IT analysts, administrators, and engineers. The position requires excellent communication skills, both verbal and written. The candidate must be able to work in a high-energy environment and adapt to shifting priorities.
Must possess an active DoD TS/SCI Clearance at the time of consideration
Key Responsibilities:
- Responsible for migration from Trellix to Microsoft Defender
- Cloud experience since InTune, which will manage MDE
- Continuous upkeep, monitoring, analysis, and response to Information System, network, and security events using Endpoint Security tools such as Trellix and Microsoft Defender.
- STIG Application and Compliance:
- Implement and maintain Security Technical Implementation Guides (STIGs) on Endpoint Security Tools.
- Conduct regular STIG compliance checks using tools like SCAP Compliance Checker and STIG Viewer.
- Document STIG configurations and remediation actions to ensure audit readiness.
- Patching and System Updates:
- Manage and deploy operating systems and application patches in accordance with federal patch management policies.
- Coordinate patch schedules to minimize operational impact while meeting compliance deadlines.
- Verify patch deployment success and troubleshoot any issues arising from updates.
- System Hardening:
- Harden systems by applying best practices and federal security guidelines to reduce attack surfaces.
- Maintain configuration baselines and ensure systems adhere to DoD and NIST standards.
- Incident Response Support:
- Participates in internal/external security audits/inspections; performs risk assessments and Continuous Monitoring.
- Assist in identifying and responding to security incidents related to vulnerabilities or misconfigurations.
- Document incidents and contribute to after-action reports for continuous improvement.
- Collaboration and Reporting:
- Work closely with system administrators, engineering staff, and compliance teams to ensure cohesive security operations.
- Prepare detailed reports and briefings for federal clients on STIG compliance, patching status, and vulnerability management efforts.
- Develop, implement, and enforce Information Security Policies and Procedures.
- Tool Utilization:
- Trellix and Microsoft Defender.
Required Qualifications
- BS bachelor’s degree with 12-15 years’ experience or 16+ years of IA experience without a degree. Specific experience, education and training may be considered in lieu of degree.
- A Current DoD 8570 baseline certification
- Understanding of the Risk Management Framework (RMF), NIST, ICD, and CNSS standards.
- Familiarity with network technologies (LAN & WAN) and best practices within a classified environment to include crypto and key management
- STIG compliance, SCC and STIG Viewer experience, and ACAS expertise.
- Expert with Microsoft Windows, Linux, and system virtualization in a secure network environment.
- Must be able to work in a constantly changing regulatory environment with short-, mid-, and long-term timelines for remediating any non-compliance
- Must be able to work well within a team environment and be able to adapt quickly to change
- Good writing and verbal presentation skills
Desired Qualifications
- Security+ or CISSP or equivalent
- DoD IS knowledge and experience
- Security hardening scripting/automation experience
- Ansible and or MECM experience
- Microsoft OS Certification (MCSE Win 7 or other)
- Linux certification (RHCSA, CompTIA Linux, LCFS/LCFE, etc.)
Location: Fort Belvoir, Virginia
Postuler maintenant