{"id":1743730,"url":"https://alion.io/job/empower-ai-patch-management-engineer","title":"PATCH MANAGEMENT ENGINEER","company":{"id":21818,"name":"Empower AI","domain":"empower.ai","url":"https://alion.io/company/empower-ai","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"iCIMS","truth_index":null},"role":"Industrial Engineering","role_family":"Industrial Engineering","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Quantico, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":70000,"max_usd":131000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":1812},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Digital Twin","optional":false},{"name":"Linux","optional":false},{"name":"Nessus","optional":false},{"name":"Windows","optional":false},{"name":"ITSM","optional":true},{"name":"Power BI","optional":true},{"name":"ServiceNow","optional":true},{"name":"SIEM","optional":true}],"status":"live","first_seen_at":"2026-10-03T04:38:15Z","employer_posted_date":"2026-10-03","last_verified_at":"2026-10-05T00:36:44Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Overview\nEmpower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.\nEmpower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.\nResponsibilities\nDescription\nEmpower AI is seeking a Patch Management Engineer to own the analysis, prioritization, and enterprise deployment of operating system and third-party security patches for thousands of endpoints supporting a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer translates ACAS scan results, vendor advisories, USCYBERCOM/JFHQ-DODIN orders, and IAVMs into CAT I/II/III remediation plans; engineers and validates patch deployments through MECM/SCCM in strict adherence to PRS timeframes and compliance AQLs; analyzes non-compliant endpoints to root cause; and produces the patch compliance evidence that feeds the weekly Vulnerability Scan Analysis Report, the POA&M in eMASS, and the Customer Support Metrics Dashboard. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.\nTHIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.\nJOB DUTIES:\nAnalyze weekly ACAS/Nessus scan results, vendor advisories, IAVMs, and USCYBERCOM/JFHQ-DODIN orders to determine applicability, assign CAT I/II/III categorization, and build prioritized remediation plans that meet PRS timeframes.\nEngineer, test (pre-production and Digital Twin), and deploy OS and third-party patches through MECM/SCCM and Intune, analyze deployment and compliance results, and drive remediation of non-compliant endpoints to root cause.\nProduce patch compliance reporting and evidence for the weekly Vulnerability Scan Analysis Report, POA&M items in eMASS, and the Customer Support Metrics Dashboard, and coordinate exceptions and mitigations with the ISSO and RMF team.\nMaintain the patch management process, maintenance-window schedules, and Change Management packages, and recommend automation to shorten time-to-remediate.\nAnalyze weekly ACAS/Nessus vulnerability scan results for all in-scope systems, identify and prioritize critical and high (CAT I/II/III) vulnerabilities, assign remediation to resolver groups, validate fixes, and produce the weekly Vulnerability Scan Analysis Report.\nAssess STIG compliance for endpoints, servers, printers, communications equipment, and platforms using STIG Viewer, SCAP, and endpoint management compliance data; track deviations and remediation; and produce the monthly STIG Compliance Report.\nMaintain and update POA&M items in eMASS for assigned systems, including milestones, mitigations, risk statements, and evidence of closure, in coordination with ISSOs and system administrators.\nMonitor the endpoint environment's security compliance status (patch compliance, baseline compliance, time-to-remediate) and ensure accurate cybersecurity metrics are fed to the Customer Support Metrics Dashboard.\nQualifications\nREQUIREMENTS:\nBachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).\nMust be a U.S. Citizen.\nMust have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.\nMust be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.\nMust possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security).\nDemonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.\nMinimum of 3 years of experience in cybersecurity analysis, vulnerability management, or RMF continuous monitoring for DoD or Federal systems.\nHands-on experience with ACAS/Nessus, STIG Viewer, and SCAP Compliance Checker, and interpreting scan and compliance results.\nWorking knowledge of NIST SP 800-53 controls, RMF (NIST SP 800-37, DoDI 8510.01), DISA STIGs, and DoD vulnerability management requirements (DoDI 8531.01).\nExperience maintaining POA&Ms and control evidence in eMASS.\nUnderstanding of Windows and Linux operating systems, Active Directory, networking fundamentals, and endpoint management concepts sufficient to assess and advise on remediation.\nStrong analytical, reporting, and communication skills; ability to produce accurate recurring reports on deadline.\nDESIRED SKILLS:\nCompTIA CySA+, Security+ CE, GSEC, or CISSP Associate.\nExperience supporting Department of War (DoW), DoD, or Intelligence Community systems across multiple enclaves.\nExperience with endpoint management compliance reporting (MECM/SCCM, Intune), HBSS/ESS, and SIEM/log analysis tools.\nFamiliarity with USCYBERCOM/JFHQ-DODIN orders and directives, IAVM compliance tracking, and cyber incident reporting.\nFamiliarity with Power BI for compliance dashboards.\nExperience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.\nAbout Empower AI\nAll hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.\nPay Band Min\nUSD $100,410.00/Yr.Pay Band Max\nUSD $155,410.00/Yr.","description_format":"text","description_chars":6398,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":true,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Endpoint Security","Vulnerability Management","Digital Government","IT Consulting & Digital Transformation"],"lifecycle":[{"event":"open","at":"2026-10-03T04:38:15Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":9,"reasons":["conf:1","velocity","win:early","comp:brand"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/empower-ai-patch-management-engineer","json_url":"https://alion.io/job/empower-ai-patch-management-engineer.json","meta":{"generated_at":"2026-10-05T02:18:38Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3051,"day_limit":5000,"remaining_today":1949,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}