Empower AI

PATCH MANAGEMENT ENGINEER

Empower AI • $100K — $155K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 3+ years of related experience (or 7+ years without a degree)
  • Active Top Secret Clearance with SCI eligibility
  • Current DoD 8570/8140 IAT Level II certification (e.g., CompTIA Security+ CE)
  • 3+ years in cybersecurity analysis or vulnerability management for DoD/Federal systems
  • Hands-on experience with ACAS/Nessus and STIG compliance tools
  • Strong analytical and reporting skills
  • Understanding of Windows/Linux OS and networking fundamentals

Responsibilities

  • Analyze ACAS/Nessus scan results and vendor advisories to create remediation plans
  • Engineer and deploy OS and third-party patches through MECM/SCCM and Intune
  • Produce patch compliance reports for Vulnerability Scan Analysis and POA&M
  • Maintain patch management processes and recommend automation for efficiency
  • Assess STIG compliance and track remediation for various systems
  • Update POA&M items in eMASS and coordinate with ISSOs
  • Monitor endpoint security compliance and ensure accurate metrics reporting

Benefits

  • Onsite role in Quantico, VA with up to 10% travel
  • Opportunity to work independently and exercise discretion
  • Engagement with a Department of War agency
  • Involvement in critical cybersecurity operations
  • Potential for professional growth in a high-security environment
Full Job Description
Responsibilities

Description

Empower AI is seeking a Patch Management Engineer to own the analysis, prioritization, and enterprise deployment of operating system and third-party security patches for thousands of endpoints supporting a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer translates ACAS scan results, vendor advisories, USCYBERCOM/JFHQ-DODIN orders, and IAVMs into CAT I/II/III remediation plans; engineers and validates patch deployments through MECM/SCCM in strict adherence to PRS timeframes and compliance AQLs; analyzes non-compliant endpoints to root cause; and produces the patch compliance evidence that feeds the weekly Vulnerability Scan Analysis Report, the POA&M in eMASS, and the Customer Support Metrics Dashboard. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.

THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

JOB DUTIES:
  • Analyze weekly ACAS/Nessus scan results, vendor advisories, IAVMs, and USCYBERCOM/JFHQ-DODIN orders to determine applicability, assign CAT I/II/III categorization, and build prioritized remediation plans that meet PRS timeframes.
  • Engineer, test (pre-production and Digital Twin), and deploy OS and third-party patches through MECM/SCCM and Intune, analyze deployment and compliance results, and drive remediation of non-compliant endpoints to root cause.
  • Produce patch compliance reporting and evidence for the weekly Vulnerability Scan Analysis Report, POA&M items in eMASS, and the Customer Support Metrics Dashboard, and coordinate exceptions and mitigations with the ISSO and RMF team.
  • Maintain the patch management process, maintenance-window schedules, and Change Management packages, and recommend automation to shorten time-to-remediate.
  • Analyze weekly ACAS/Nessus vulnerability scan results for all in-scope systems, identify and prioritize critical and high (CAT I/II/III) vulnerabilities, assign remediation to resolver groups, validate fixes, and produce the weekly Vulnerability Scan Analysis Report.
  • Assess STIG compliance for endpoints, servers, printers, communications equipment, and platforms using STIG Viewer, SCAP, and endpoint management compliance data; track deviations and remediation; and produce the monthly STIG Compliance Report.
  • Maintain and update POA&M items in eMASS for assigned systems, including milestones, mitigations, risk statements, and evidence of closure, in coordination with ISSOs and system administrators.
  • Monitor the endpoint environment's security compliance status (patch compliance, baseline compliance, time-to-remediate) and ensure accurate cybersecurity metrics are fed to the Customer Support Metrics Dashboard.


Qualifications

REQUIREMENTS:
  • Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security).
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 3 years of experience in cybersecurity analysis, vulnerability management, or RMF continuous monitoring for DoD or Federal systems.
  • Hands-on experience with ACAS/Nessus, STIG Viewer, and SCAP Compliance Checker, and interpreting scan and compliance results.
  • Working knowledge of NIST SP 800-53 controls, RMF (NIST SP 800-37, DoDI 8510.01), DISA STIGs, and DoD vulnerability management requirements (DoDI 8531.01).
  • Experience maintaining POA&Ms and control evidence in eMASS.
  • Understanding of Windows and Linux operating systems, Active Directory, networking fundamentals, and endpoint management concepts sufficient to assess and advise on remediation.
  • Strong analytical, reporting, and communication skills; ability to produce accurate recurring reports on deadline.


DESIRED SKILLS:
  • CompTIA CySA+, Security+ CE, GSEC, or CISSP Associate.
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across multiple enclaves.
  • Experience with endpoint management compliance reporting (MECM/SCCM, Intune), HBSS/ESS, and SIEM/log analysis tools.
  • Familiarity with USCYBERCOM/JFHQ-DODIN orders and directives, IAVM compliance tracking, and cyber incident reporting.
  • Familiarity with Power BI for compliance dashboards.
  • Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.


Pay Band Min

USD $100,410.00/Yr.

Pay Band Max

USD $155,410.00/Yr.

About Empower AI

Empower AI is a privately held company that develops artificial intelligence software for the healthcare industry. The company was founded in 2017 and is headquartered in Cambridge, Massachusetts. Empower AI's software uses machine learning algorithms to analyze medical data and provide insights to healthcare providers. The company's software is designed to improve patient outcomes and reduce healthcare costs. Empower AI has approximately 50 employees and operates in the United States.
Learn more about Empower AI
Size
50 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Empower AI

More Aerospace & Defense Jobs

Find similar PATCH MANAGEMENT ENGINEER jobs: