Demo

Cybersecurity Tools Administrator

SAIC
Springfield, VA Full Time
POSTED ON 9/19/2026
AVAILABLE BEFORE 10/27/2026
Job ID 2616218

Location Springfield, VA, US

Date Posted 2026-08-27

Category Cyber

Subcategory Cyberspace Ops

Schedule Full-Time

Shift Day Job

Travel Yes - 10% of the time

Minimum Clearance Required TS.SCI

Clearance Level Must Be Able to Obtain TS/SCI with Poly

Potential for Remote Work ORA_ON_SITE

Description

SAIC is seeking a motivated Cybersecurity Tools Administrator to join our MAJESTIC Joint Program Office (JPO) Team in support of an on-premises enterprise IT environment. This role focuses on implementing, administering, and optimizing cybersecurity toolsets centered on Trellix Endpoint Security (ENS) and integrated capabilities such as Endpoint Detection & Response (EDR), Network Detection & Response (NDR), and malware protection. The administrator will manage policy, deployment, health/compliance, telemetry, and integrations with SIEM/SOAR to strengthen enterprise security posture.

All work is performed on-site in Springfield, VA. 

Key Responsibilities

  • Administer Trellix ePolicy Orchestrator (ePO) configure policies, tasks, and client assignments; perform agent deployment/updates; monitor health and compliance across Windows/Linux endpoints.
  • Implement and maintain cybersecurity toolsets including ESS/ENS, EDR, NDR, and malware protection; tune detections and containment to reduce false positives while improving fidelity.
  • Integrate endpoint tools with enterprise SIEM/SOAR (e.g., Splunk) and vulnerability management stacks (e.g., Nessus/ACAS) to enable unified visibility, correlation, and automated response.
  • Develop and maintain dashboards, reports, and KPIs for endpoint coverage, policy compliance, threat activity, and vulnerability remediation progress.
  • Conduct enterprise-wide agent posture checks; remediate orphaned agents, stale policies, connectivity issues, and broken update channels.
  • Author and maintain standard operating procedures (SOPs), change records, and implementation plans; follow standardized test, certification, and deployment procedures.
  • Support incident response by providing endpoint forensics, containment actions (e.g., DAC), isolation, and IOC sweep capability; assist with root-cause analysis and corrective actions.
  • Coordinate with Systems Administrators, Network Engineers, and Cybersecurity personnel to assess risks, validate configurations, and enforce security controls in accordance with RMF/NIST 800-53.
  • Ensure tool and control configuration compliance; review change requests; validate effectiveness of security controls across virtualized Windows/Linux servers and enterprise networks.
  • Maintain detailed documentation including release notes, configuration baselines, incident investigations, and compliance/authorization artifacts.

Qualifications

Education

  • High School diploma or equivalent

Certifications (CWF Requirements)

  • Candidates must satisfy Cybersecurity Workforce Framework (CWF) ID 521 (Cyber Defense Infrastructure Support Specialist, Intermediate Level) requirements, as outlined by Navy COOL. This requirement can be met by possessing one or more of the following qualifying certifications
  • Certified Ethical Hacker (CEH).
  • CompTIA Cloud .
  • CompTIA Cybersecurity Analyst (CySA ).
  • CompTIA PenTest .
  • CompTIA Security .
  • GIAC Continuous Monitoring Certification (GMON).
  • GIAC Response and Industrial Defense (GRID).
  • GIAC Security Essentials Certification (GSEC).
  • Systems Security Certified Practitioner (SSCP).

OR This requirement can be met through

  • A Bachelor’s Degree in Cybersecurity, Computer Science, IT, or a related field.

Experience

  • 2-5 years of experience administering enterprise cybersecurity tools (e.g., Trellix ePO/ENS, EDR/NDR) and performing endpoint/security operations in an enterprise IT environment.

Technical Skills

  • Proficiency administering Trellix ePO and ENS/ESS; familiarity with Dynamic Application Containment (DAC), IOC sweep, and endpoint isolation.
  • Understanding of cybersecurity frameworks and processes (NIST 800-53, RMF, ICD 503).
  • Solid knowledge of Windows/Linux security configurations, AD-integrated deployments, and enterprise network concepts.
  • Familiarity with incident response procedures, log analysis, and database/server hardening.

Clearance Requirement

  • Active TS/SCI clearance with the ability to obtain and maintain a TS/SCI with CI Poly.

Work Environment and Notes

  • On-site Work All work must be conducted on-site in Springfield, VA.
  • Program Scope Supports on-premises enterprise IT environments, including virtualized Windows/Linux servers, databases, and comprehensive networking layers.
  • Subcontractor Role Roles and responsibilities are defined per the subcontract agreement, with salary based on competitive market rates and role-specific requirements.

Target salary range $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Salary : $80,001 - $120,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Tools Administrator?

Sign up to receive alerts about other jobs on the Cybersecurity Tools Administrator career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$83,502 - $107,152
Income Estimation: 
$104,896 - $133,785
Income Estimation: 
$123,198 - $153,566
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at SAIC

  • SAIC Washington, DC
  • Job ID: 2615324-OTHLOC-006 Location: Washington, DC, US Date Posted: 2026-08-06 Category: Cyber Subcategory: Cybersecurity Ops Schedule: Full-Time Shift: D... more
  • 11 Days Ago

  • SAIC Force, NE
  • Job ID 2613599 Location Offutt AFB, NE, US Date Posted 2026-06-11 Category Information Technology Subcategory Database Engr Schedule Full-Time Shift Day Jo... more
  • 11 Days Ago

  • SAIC Smith, NV
  • Job ID 2610981 Location Camp Smith, HI, US Date Posted 2026-04-03 Category Defense/Intel Subcategory Military Operations Schedule Full-Time Shift Day Job T... more
  • 11 Days Ago

  • SAIC Albuquerque, NM
  • Job ID 2615572-OTHLOC-100000685975201 Location Albuquerque, NM, US Date Posted 2026-08-14 Category Logistics Subcategory Logistics Schedule Full-Time Shift... more
  • 11 Days Ago


Not the job you're looking for? Here are some other Cybersecurity Tools Administrator jobs in the Springfield, VA area that may be a better fit.

  • Irongate Cybersecurity Washington, DC
  • We are seeking an experienced Threat Hunter. This role is ideal for a seasoned professional with deep technical expertise in endpoint detection and respons... more
  • 24 Days Ago

  • RealmOne Mc Lean, VA
  • Job Brief System Administration; Network Tools Job Description RealmOne was built on the principle that people matter first and foremost. We believe in pro... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!