Position is full-time remote.
Interviews will be via Microsoft Teams Planning, implementing, managing, monitoring, and upgrading security measures for the protection of DRC data, systems, and networks
Responding to all system and/or network security breaches
Design and maintain enterprise SCCM/MECM patching strategies for Windows endpoints and supported server environments.
Create and manage SCCM device collections, deployment groups, maintenance windows, software update groups, and deployment schedules.
Coordinate vulnerability information from Qualys with SCCM patching data to identify vulnerable systems requiring remediation.
Perform vulnerability-first remediation by identifying affected assets and determining the appropriate patch, configuration change, software upgrade, or compensating control.
Analyze patch compliance, deployment status, failed installations, pending reboots, missing updates, and non-reporting devices.
Manage Software Update Points (SUP), WSUS synchronization, software update groups, deployment packages, and Automatic Deployment Rules (ADRs).
Troubleshoot SCCM client installation, client health, policy retrieval, software update scanning, deployment evaluation, and content download failures.
Develop procedures for emergency patch deployment when critical or actively exploited vulnerabilities require accelerated remediation.
Package and deploy third-party application updates and security fixes where Microsoft updates do not provide remediation.
Create and maintain SCCM operational runbooks, patching procedures, troubleshooting guides, deployment standards, and rollback procedures.
Testing and identifying network and system vulnerabilities
Evaluating the organization's security needs and establishing best practices and standards accordingly
Taking appropriate security measures to ensure that DRC's infrastructure and existing data are kept safe
Perform scheduled and ad-hoc vulnerability scans across networks, servers and endpoints.
Work with server, endpoint, security, network, and application teams to resolve cross-platform remediation dependencies.
Tune scans and reduce false positives to improve data accuracy
Develop vulnerability metrics, dashboards, and executive-level reports
Conducting testing and scans to identify any vulnerabilities in the network and system
Required/Desired Skills
| Skill | Required /Desired | Amount | of Experience |
| Network Security and threat detection, incident response and vulnerability management | Required | 10 | Years |
| Hands-on experience administering Qualys, remediation documentation and patch management processes | Required | 10 | Years |
| Microsoft SCCM/MECM administration. | Required | 10 | Years |
| Experience with Vulnerability scan reports and remediation tracking, risk assessment and compliance documentation | Highly desired | 0 | |
Questions
| No. | Question |
| Question1 | Do you understand, and will abide by, the provision in your subcontract with OST that it is PROHIBITED for government equipment to be taken or used outside of the United States by your contractors? The consequences of this occurring can and will result in repercussions to you, the prime vendor, regardless if the candidate works for a sub-vendor of yours. It will also result in immediate termination of the contractor and make them ineligible for rehire in the program. |
| Question2 | Please note: The selected candidate(s) must accept the offered position within 48 hours of vendor notification. Failure to do so will result in DRC moving to their next candidate choice. Do you accept? |
| Question3 | Once a candidate accepts an offered position, ALL DRC compliance items listed under the "Compliance" tab on the candidate record must be completed within 5 business days and uploaded into Vector. Failure to do so will result in DRC moving to their next candidate choice. Do you accept? |
| Question4 | Selected candidate will be required to have a Fingerprint check performed. Does your candidate agree? |