> Markdown version of [/jobs/ext/514371-bigfix-sme-architect](https://www.wearedevelopers.com/jobs/ext/514371-bigfix-sme-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # BigFix SME/Architect - **Company:** Guidehouse Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $149,000.0 - $248,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Configuration Management, Continuous Integration, Linux, DevOps, Security Content Automation Protocol, Security Information and Event Management, Software Vulnerability Management, Information Technology, CIS Benchmarks, Splunk - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bb341a0a178e0048 ## About the Role Do you have experience in Vulnerability management?, * Must be US Citizen. * An ACTIVE and MAINTAINED "TOP SECRET" Federal or DoD security clearance. * 8+ years of experience designing and architecting highly complex IT systems * Demonstrated SME-level mastery of HCL BigFix, including architecture, engineering, lifecycle management, and custom content development. * Proven experience delivering Tier 2/3 support for large-scale endpoint management or security systems. * Hands-on experience operating in secure enclave or high-side environments. * Strong understanding of enterprise compliance (patching, vulnerability management, configuration enforcement). * Ability to lead architecture forums, component discussions, and cross-functional technical engagements. * Experience working with platform vendors such as HCL or HCL-approved partners. * Ability to communicate excellently for interfacing with DOJ Components and senior technical stakeholders. What Would Be Nice To Have: * Prior experience supporting DOJ Components, federal law enforcement, or IC mission environments. * BigFix Administrator or Specialist certifications. * Familiarity with: + STIGs, NIST 800-53, SCAP, CIS Benchmarks + SIEM integrations (Splunk, Elastic, etc.) + Automation, DevOps, CI/CD pipelines + Windows/Linux hardening and enterprise security tooling * Experience designing BigFix deployments in virtualized or multi-enclave architectures. ## Description * Architect, engineer, and sustain DOJ's enterprise BigFix environment used for endpoint compliance and configuration management across all Components except FBI. * Primary Subject Matter expert for the platform, including driving the use of new features, leading major upgrades, assessing functionality gaps, and communicating with the customer base. * Provide Tier 2/3 engineering support, including advanced troubleshooting, diagnostics, and remediation for BigFix platform issues within the Federal Secure Enclave. * Lead platform upgrades, patching cycles, module deployments, and capability enhancements in coordination with infrastructure teams and HCL (or HCL-approved partners). * Develop custom fixlets, automation scripts, baselines, dashboards, and compliance content tailored to mission needs. * Engage directly with DOJ Components to gather requirements, resolve issues, and advise on endpoint compliance strategy and BigFix best practices. * Maintain authoritative engineering documentation, SOPs, configuration baselines, and change control artifacts. * Support audits, reporting, and compliance activities aligned with DOJ security standards and enclave governance. * Drive long-term roadmap planning, architectural improvements, and modernization initiatives for the DOJ enterprise BigFix platform. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)