SAIC

Cybersecurity Tools Administrator

SAIC$80K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in related field with 2-9+ years of experience or Master's degree with 0-7+ years or High School diploma with 6-13+ years.
  • Experience administering enterprise cybersecurity tools like Trellix ePO/ENS and performing endpoint/security operations.
  • Proficiency in cybersecurity frameworks (NIST 800-53, RMF) and familiarity with compliance standards.
  • Active TS/SCI clearance with ability to obtain TS/SCI with CI Poly.
  • Certifications satisfying Cybersecurity Workforce Framework ID 521 requirements.

Responsibilities

  • Administer and configure Trellix ePolicy Orchestrator (ePO) and manage Windows/Linux endpoint compliance.
  • Implement and optimize cybersecurity toolsets including EDR, NDR, and malware protection.
  • Integrate endpoint tools with enterprise systems to enhance visibility and automate responses.
  • Develop and maintain reports and dashboards for security metrics and compliance.
  • Conduct agent posture checks and remedy connectivity and policy issues.
  • Author and maintain SOPs and documentation for cybersecurity processes.
  • Support incident response through forensic analysis and remediation actions.

Benefits

  • Opportunities for ongoing skills development through training and certifications.
  • Work in a dynamic, collaborative environment focused on enterprise cybersecurity.
  • Exposure to advanced cybersecurity technologies and methodologies.
  • Engagement with a diverse team supporting critical national security initiatives.
Full Job Description
Job Description

Description

SAIC is seeking a motivated Cybersecurity Tools Administrator to join our MAJESTIC Joint Program Office (JPO) Team in support of an on-premises enterprise IT environment. This role focuses on implementing, administering, and optimizing cybersecurity toolsets centered onTrellixEndpoint Security (ENS) andintegrated capabilities such as Endpoint Detection & Response (EDR), Network Detection & Response (NDR), and malware protection. The administrator will manage policy, deployment, health/compliance, telemetry, and integrations with SIEM/SOAR to strengthen enterprise security posture.

All work is performed on-site in Springfield, VA.

Key Responsibilities:
  • Administer Trellix ePolicy Orchestrator (ePO): configure policies, tasks, and client assignments; perform agent deployment/updates; monitor health and compliance across Windows/Linux endpoints.
  • Implement and maintain cybersecurity toolsets including ESS/ENS, EDR, NDR, and malware protection; tune detections and containment to reduce false positives while improving fidelity.
  • Integrate endpoint tools with enterprise SIEM/SOAR (e.g., Splunk) and vulnerability management stacks (e.g., Nessus/ACAS) to enable unified visibility, correlation, and automated response.
  • Develop and maintain dashboards, reports, and KPIs for endpoint coverage, policy compliance, threat activity, and vulnerability remediation progress.
  • Conduct enterprise-wide agent posture checks; remediate orphaned agents, stale policies, connectivity issues, and broken update channels.
  • Author and maintain standard operating procedures (SOPs), change records, and implementation plans; follow standardized test, certification, and deployment procedures.
  • Support incident response by providing endpoint forensics, containment actions (e.g., DAC), isolation, and IOC sweep capability; assist with root-cause analysis and corrective actions.
  • Coordinate with Systems Administrators, Network Engineers, and Cybersecurity personnel to assess risks, validate configurations, and enforce security controls in accordance with RMF/NIST 800-53.
  • Ensure tool and control configuration compliance; review change requests; validate effectiveness of security controls across virtualized Windows/Linux servers and enterprise networks.
  • Maintain detailed documentation including release notes, configuration baselines, incident investigations, and compliance/authorization artifacts.

Qualifications

Education:
  • Bachelors degree in related field and 2-9+ years of experience OR;
  • Masters degree in related field and 0-7+ years of experience OR;
  • High School diploma or equivalent and 6-13+ years of experience.
Certifications (CWF Requirements):
  • Candidates must satisfyCybersecurity Workforce Framework (CWF)ID 521 (Cyber Defense Infrastructure Support Specialist, Intermediate Level)requirements, as outlined byNavy COOL.
    This requirement can be met by possessing one or more of the following qualifyingcertifications:
  • Certified Ethical Hacker (CEH).
  • CompTIA Cloud+.
  • CompTIA Cybersecurity Analyst (CySA+).
  • CompTIA PenTest+.
  • CompTIA Security+.
  • GIAC Continuous Monitoring Certification (GMON).
  • GIAC Response and Industrial Defense (GRID).
  • GIAC Security Essentials Certification (GSEC).
  • Systems Security Certified Practitioner (SSCP).
OR This requirement can be met through:
  • ABachelor's Degreein Cybersecurity, Computer Science, IT, or a related field.
Experience:
  • 2-5 yearsof experienceadministering enterprise cybersecurity tools (e.g., Trellix ePO/ENS, EDR/NDR) and performing endpoint/security operations in an enterprise IT environment.
Technical Skills:
  • Proficiency administering Trellix ePO and ENS/ESS; familiarity with Dynamic Application Containment (DAC), IOC sweep, and endpoint isolation.
  • Understanding of cybersecurity frameworks and processes (NIST 800-53, RMF, ICD 503).
  • Solid knowledge of Windows/Linux security configurations, AD-integrated deployments, and enterprise network concepts.
  • Familiarity with incident response procedures, log analysis, and database/server hardening.
Clearance Requirement:
  • ActiveTS/SCIclearance with the ability to obtain and maintain aTS/SCI with CI Poly.
Work Environment and Notes:
  • On-site Work:All work must be conducted on-site in Springfield, VA.
  • Program Scope:Supports on-premises enterprise IT environments, including virtualized Windows/Linux servers, databases, and comprehensive networking layers.
  • Subcontractor Role:Roles and responsibilities are defined per the subcontract agreement, with salary based on competitive market rates and role-specific requirements.

Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

About SAIC

Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.
Learn more about SAIC
Size
26,000 employees
Market Cap
$6 billion
Industry
Net Income
$206 million
Founded
1969
5 Year Trend
+10.7%
Revenue
$6.8 billion
NASDAQ

Similar Jobs

More Jobs at SAIC

More Information Technology Jobs

Find similar Cybersecurity Tools Administrator jobs: