AntiVirus Engineer
POSITION SUMMAR
YThe AntiVirus Engineer-Senior supports the SEC ISS contract by leading enterprise anti-virus operations that protect SEC workstations and servers across the agency environment. This role is responsible for centralized policy administration, secure deployment and configuration, signature/DAT and engine currency, and scheduled scanning to maintain consistent endpoint protection. The engineer serves as an escalation point for complex malware and endpoint security incidents, driving rapid restoration and durable corrective actions. The position also supports ISS objectives for zero-trust enforcement, SLA-driven service delivery, and FISMA-aligned operational documentation
.
PRIMARY RESPONSIBILITI
ESEnterprise Anti-Virus Operatio
- nsManage and lead day-to-day deployment and configuration of enterprise anti-virus software across required SEC workstations and server
- s.Administer centrally managed anti-virus policies, exceptions, and protection settings through enterprise management servers/console
- s.Manage anti-virus signature/DAT and engine updates to maintain current protection coverage across the endpoint flee
- t.Execute and validate scheduled anti-virus scans, update tasks, and protection health check
- s.Centralized Management and Endpoint Integrati
- onOperate and optimize centralized anti-virus management platforms (e.g., enterprise policy orchestration tools) to enforce standardized control
- s.Coordinate anti-virus configurations with endpoint management processes, baseline images, and software deployment standard
- s.Support pre-production testing and controlled rollout of anti-virus policy or agent changes to reduce operational ris
- k.Maintain and update SOPs, runbooks, and configuration baselines for endpoint protection operation
- s.Incident Response and Escalation SupportTroubleshoot complex anti-virus and malware-related issues requiring senior-level escalation support and subject matter expertis
- e.Perform incident triage, technical analysis, and root-cause identification for endpoint protection failures or infection
- s.Coordinate with SEC support teams and stakeholders to restore services quickly and prevent repeat incident
- s.Document actions, status, and resolution details in approved ticket/workflow systems in alignment with ISS support processe
- s.Security Compliance, Reporting, and Continuous ImprovementSupport vulnerability identification, tracking, and remediation activities related to endpoint protection controls and finding
- s.Monitor anti-virus operational metrics (coverage, update compliance, scan status, incident trends) and provide regular reportin
- g.Ensure endpoint protection operations align with SEC security policies, change control requirements, and audit readiness expectation
- s.Contribute to zero-trust and continuous-improvement efforts by recommending automation and control enhancements for endpoint security operation
s.
REQUIRED QUALIFICATI
ONSCitizenship/Work Authorization: Must meet contract requiremen
ts.Clearance: Ability to obtain and maintain SEC Public Trust (or higher if require
d).Education: Bachelor's degree in a relevant field (e.g., Information Technology, Computer Science, Engineerin
- g).Experience:Minimum 8 years of experience, including 7-10 years of related experience managing and leading support of enterprise anti-virus software solutio
- ns.Demonstrated experience using centralized anti-virus management platforms (e.g., enterprise policy orchestration tool
- s).Experience deploying, configuring, and sustaining anti-virus controls for both workstation and server operating environmen
- ts.Technical Skills:Enterprise anti-virus administration for workstation and server endpoi
- ntsCentralized policy/orchestration management conso
- lesSignature/DAT and engine update lifecycle managem
- entMalware scanning operations, scheduling, and health validat
- ionEscalated incident troubleshooting and root-cause analy
- sisPREFERRED QUALIFICATIONSPrior experience supporting a federal civilian agency IT contract with FISMA-driven security and audit requiremen
- ts.Hands-on experience integrating endpoint protection operations with Microsoft Intune or comparable endpoint management platfor
- ms.Experience implementing endpoint controls aligned to zero-trust security objectiv
- es.Experience with ServiceNow-based ticketing, escalation workflows, and SLA performance reporti
- ng.Experience managing endpoint POA&M remediation and response to Known Exploited Vulnerabilities (KEV) timelin
- es.CompTIA Securi
- ty+Trellix/McAfee ePO certificat
ion- Microsoft Certified: Security Operations Analyst Associate (SC-2
00)
WORK ENVIRONMENT / O
THEROperational Support: May require participation in on-call or surge support activities depending on operational ne
eds.Location: Washington, DC Metropolitan Area (on-site at SEC facilities with approved telework as directed by contract/task ord
er).Travel: As required per contract direct
ion.