Patch Management Engineer

Empower AIQuantico, VA
Onsite

About The Position

Empower AI is seeking a Patch Management Engineer to own the analysis, prioritization, and enterprise deployment of operating system and third-party security patches for thousands of endpoints supporting a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer translates ACAS scan results, vendor advisories, USCYBERCOM/JFHQ-DODIN orders, and IAVMs into CAT I/II/III remediation plans; engineers and validates patch deployments through MECM/SCCM in strict adherence to PRS timeframes and compliance AQLs; analyzes non-compliant endpoints to root cause; and produces the patch compliance evidence that feeds the weekly Vulnerability Scan Analysis Report, the POA&M in eMASS, and the Customer Support Metrics Dashboard. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

Requirements

  • Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security).
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 3 years of experience in cybersecurity analysis, vulnerability management, or RMF continuous monitoring for DoD or Federal systems.
  • Hands-on experience with ACAS/Nessus, STIG Viewer, and SCAP Compliance Checker, and interpreting scan and compliance results.
  • Working knowledge of NIST SP 800-53 controls, RMF (NIST SP 800-37, DoDI 8510.01), DISA STIGs, and DoD vulnerability management requirements (DoDI 8531.01).
  • Experience maintaining POA&Ms and control evidence in eMASS.
  • Understanding of Windows and Linux operating systems, Active Directory, networking fundamentals, and endpoint management concepts sufficient to assess and advise on remediation.
  • Strong analytical, reporting, and communication skills; ability to produce accurate recurring reports on deadline.

Nice To Haves

  • CompTIA CySA+, Security+ CE, GSEC, or CISSP Associate.
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across multiple enclaves.
  • Experience with endpoint management compliance reporting (MECM/SCCM, Intune), HBSS/ESS, and SIEM/log analysis tools.
  • Familiarity with USCYBERCOM/JFHQ-DODIN orders and directives, IAVM compliance tracking, and cyber incident reporting.
  • Familiarity with Power BI for compliance dashboards.
  • Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.

Responsibilities

  • Analyze weekly ACAS/Nessus scan results, vendor advisories, IAVMs, and USCYBERCOM/JFHQ-DODIN orders to determine applicability, assign CAT I/II/III categorization, and build prioritized remediation plans that meet PRS timeframes.
  • Engineer, test (pre-production and Digital Twin), and deploy OS and third-party patches through MECM/SCCM and Intune, analyze deployment and compliance results, and drive remediation of non-compliant endpoints to root cause.
  • Produce patch compliance reporting and evidence for the weekly Vulnerability Scan Analysis Report, POA&M items in eMASS, and the Customer Support Metrics Dashboard, and coordinate exceptions and mitigations with the ISSO and RMF team.
  • Maintain the patch management process, maintenance-window schedules, and Change Management packages, and recommend automation to shorten time-to-remediate.
  • Analyze weekly ACAS/Nessus vulnerability scan results for all in-scope systems, identify and prioritize critical and high (CAT I/II/III) vulnerabilities, assign remediation to resolver groups, validate fixes, and produce the weekly Vulnerability Scan Analysis Report.
  • Assess STIG compliance for endpoints, servers, printers, communications equipment, and platforms using STIG Viewer, SCAP, and endpoint management compliance data; track deviations and remediation; and produce the monthly STIG Compliance Report.
  • Maintain and update POA&M items in eMASS for assigned systems, including milestones, mitigations, risk statements, and evidence of closure, in coordination with ISSOs and system administrators.
  • Monitor the endpoint environment's security compliance status (patch compliance, baseline compliance, time-to-remediate) and ensure accurate cybersecurity metrics are fed to the Customer Support Metrics Dashboard.

Benefits

  • All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success.
  • It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status.
  • Empower AI is a VEVRAA Federal Contractor.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service