> Markdown version of [/jobs/ext/1996632-host-based-security-system-hbss-administrator](https://www.wearedevelopers.com/jobs/ext/1996632-host-based-security-system-hbss-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Host-Based Security System (HBSS) Administrator - **Company:** CareerCircle - **Location:** Hampton Roads, United States (Remote available) - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Bash Shell, Cloud Computing, Software Documentation, CompTIA Security+, Cyber Security, Information Systems, Information Leak Prevention, Linux, Information Systems Security Architecture Professional, Python (Programming Language), Linux System Administration, McAfee VirusScan, Windows Servers, Package Management Systems, Windows PowerShell, Red Hat Enterprise Linux, Security Information and Event Management, Scripting, Computer Networking Systems, Selinux, Information Technology, Tenable Nessus, Nessus, CIS Benchmarks, Cyber Warfare, McAfee EPolicy, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/va/hampton/d0741376-7231-421b-b656-d4558f1825e4 ## About the Role * US Citizen with an active TS/SCI security clearance. * Bachelor's degree with 4+ years of experience of a Master's degree with 2+ years of experience. Additional experience may be considered in lieu of a degree. * Certification: DoD 8570/8140-compliant certification at IAT Level II or higher - CompTIA Security+ CE required at a minimum. * Experience: 3-5 years of hands-on experience administering HBSS, McAfee ePO, or the Trellix Security Platform Suite in a DoD or federal government environment, including deployment and management in a predominantly Red Hat Enterprise Linux (RHEL) environment. * Technical Knowledge: Working knowledge of DISA STIGs, NIST SP 800-53, and DoD IA policies and regulations; familiarity with Linux-specific HBSS agent deployment, configuration, and troubleshooting. * System Administration: Proficiency in Red Hat Enterprise Linux (RHEL) administration - including RPM package management, SELinux policy, systemd services, and security baseline configuration - as well as Windows Server administration and OS patching., * Additional certifications such as CISSP, CISA, CEH, or vendor-specific ePO/Trellix training and certification. * Proficiency in scripting and automation (e.g., Bash, PowerShell, Python) * Experience with Assured Compliance Assessment Solution (ACAS) / Tenable Nessus for vulnerability scanning and remediation tracking. * Familiarity with Security Information and Event Management (SIEM) tools and integration with HBSS/Trellix event data. * Experience supporting RMF Authorization packages, including development of System Security Plans (SSPs) and continuous monitoring activities. * Red Hat certifications such as RHCSA or RHCE, or equivalent demonstrated Linux administration experience in a security-focused role. * Knowledge of scripting (Bash, Python, or PowerShell) for automating HBSS agent deployments, compliance checks, or ePO reporting tasks across mixed OS environments. * Prior experience in a SOC, NOC, or Cyber Defense environment supporting 24/7 operations. * Familiarity with cloud-based endpoint security management or hybrid on-prem/cloud ePO deployments. ## Description Nessus On Prem Selinux Auditing Equities Scripting Leadership Management Automation Market Data NIST 800-53 System Status Cyber Defense Ancient History Operating Systems Incident Response Endpoint Security Windows PowerShell Exception Reporting Data Loss Prevention CompTIA Security+ CE Linux Administration Information Assurance Continuous Monitoring Software Documentation Vulnerability Scanning Red Hat Enterprise Linux Certified Ethical Hacker Bash (Scripting Language) Authorization (Computing) IAT Level II Certification Package Management Systems McAfee Epolicy Orchestrator Intrusion Prevention Systems Python (Programming Language) Host Based Security System (HBSS) Red Hat Certified Engineer (RHCE) Plan Of Action And Milestones (POA&M) Microsoft Windows Server Administration Certified Information System Auditor (CISA) Red Hat Certified System Administrator (RHCSA) Security Information And Event Management (SIEM) Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance), The Defense Sector at Leidos is seeking an experienced Host-Based Security System (HBSS) Administrator to support the management, configuration, and maintenance of endpoint security infrastructure across Department of Defense (DoD) and federal government networks. The ideal candidate brings hands-on experience with McAfee ePolicy Orchestrator (ePO) and the Trellix Security Platform Suite and operates comfortably within a compliance-driven environment governed by DoD standards. Langley AFB is the main work location for this position but work will occur at government facilities in the Hampton Roads area. Travel may be required to CONUS and OCONUS locations as needed. Roles and Responsibilities: * Manage, deploy, and maintain HBSS/Trellix endpoint protection technologies across enterprise networks to monitor, detect, and respond to security events. * Configure and fine-tune HBSS modules including Host Intrusion Prevention System (HIPS), Data Loss Prevention (DLP), and Policy Auditor. * Implement and maintain DISA Security Technical Implementation Guides (STIGs) to ensure systems remain audit-ready for command inspections and authorization reviews. * Oversee OS and application patch deployments through McAfee ePO; track vulnerabilities and support Information Assurance (IA) compliance efforts. * Identify and isolate system anomalies; assist with incident response activities and coordinate with engineering and security operations teams to resolve HBSS point-product issues. * Monitor server and network health, generate compliance and exception reports, and brief leadership on system status as required. * Support Authority to Operate (ATO) activities by maintaining accurate system documentation, POA&Ms, and security baselines. * Coordinate with system owners and the ISSM/ISSO to ensure endpoint policies align with organizational security requirements., Nessus On Prem Selinux Auditing Equities Scripting Leadership Management Automation Market Data NIST 800-53 System Status Cyber Defense Ancient History Operating Systems Incident Response Endpoint Security Windows PowerShell Exception Reporting Data Loss Prevention CompTIA Security+ CE Linux Administration Information Assurance Continuous Monitoring Software Documentation Vulnerability Scanning Red Hat Enterprise Linux Certified Ethical Hacker Bash (Scripting Language) Authorization (Computing) IAT Level II Certification Package Management Systems McAfee Epolicy Orchestrator Intrusion Prevention Systems Python (Programming Language) Host Based Security System (HBSS) Red Hat Certified Engineer (RHCE) Plan Of Action And Milestones (POA&M) Microsoft Windows Server Administration Certified Information System Auditor (CISA) Red Hat Certified System Administrator (RHCSA) Security Information And Event Management (SIEM) Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Medical Device Cyber Security Program Manager TEKsystems Virginia Beach, VA*Remote Operations Leadership Management Cyber Security Medical Devices Program Management Business Valuation Technology Ecosystems Health Administration Information Technology Full Stack Development Artificial Intelligence Business Transformation +0 ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [For the Cars and the Curious: Android Drift](https://www.wearedevelopers.com/videos/499-for-the-cars-and-the-curious-android-drift) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)