SAIC is seeking a motivated Cybersecurity Tools Administrator to join our MAJESTIC Joint Program Office (JPO) Team in support of an on-premises enterprise IT environment. This role focuses on implementing, administering, and optimizing cybersecurity toolsets centered on Trellix Endpoint Security (ENS) and integrated capabilities such as Endpoint Detection & Response (EDR), Network Detection & Response (NDR), and malware protection. The administrator will manage policy, deployment, health/compliance, telemetry, and integrations with SIEM/SOAR to strengthen enterprise security posture.
All work is performed on-site in Springfield, VA.
Key Responsibilities:
- Administer Trellix ePolicy Orchestrator (ePO): configure policies, tasks, and client assignments; perform agent deployment/updates; monitor health and compliance across Windows/Linux endpoints.
- Implement and maintain cybersecurity toolsets including ESS/ENS, EDR, NDR, and malware protection; tune detections and containment to reduce false positives while improving fidelity.
- Integrate endpoint tools with enterprise SIEM/SOAR (e.g., Splunk) and vulnerability management stacks (e.g., Nessus/ACAS) to enable unified visibility, correlation, and automated response.
- Develop and maintain dashboards, reports, and KPIs for endpoint coverage, policy compliance, threat activity, and vulnerability remediation progress.
- Conduct enterprise-wide agent posture checks; remediate orphaned agents, stale policies, connectivity issues, and broken update channels.
- Author and maintain standard operating procedures (SOPs), change records, and implementation plans; follow standardized test, certification, and deployment procedures.
- Support incident response by providing endpoint forensics, containment actions (e.g., DAC), isolation, and IOC sweep capability; assist with root-cause analysis and corrective actions.
- Coordinate with Systems Administrators, Network Engineers, and Cybersecurity personnel to assess risks, validate configurations, and enforce security controls in accordance with RMF/NIST 800-53.
- Ensure tool and control configuration compliance; review change requests; validate effectiveness of security controls across virtualized Windows/Linux servers and enterprise networks.
- Maintain detailed documentation including release notes, configuration baselines, incident investigations, and compliance/authorization artifacts.
SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Learn more about this Employer on their Career Site
