Job Requirements
Quantico, VA
Top Secret/SCI Polygraph Unspecified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Description
Empower AI is seeking an Endpoint Engineer - Classified Enclaves to engineer and sustain the endpoint infrastructure on the SIPRNet and JWICS enclaves of a Department of War agency, where the same standards of automation, hardening, and RMF compliance apply but tooling, connectivity, and handling procedures differ. The engineer operates the classified-enclave endpoint management infrastructure (e.g., MECM/SCCM), engineers and validates hardened images and Group Policy baselines, executes CAT I/II/III patching within enclave constraints, supports classified VDI and cross-domain considerations, and produces RMF evidence for the classified endpoint systems. This TS/SCI privileged-user role is the Tier III escalation point for classified endpoint incidents. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.
THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.
JOB DUTIES:
REQUIREMENTS:
DESIRED SKILLS:
PHYSICAL REQUIREMENTS
The physical demands described below are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to do the following:
Empower AI is seeking an Endpoint Engineer - Classified Enclaves to engineer and sustain the endpoint infrastructure on the SIPRNet and JWICS enclaves of a Department of War agency, where the same standards of automation, hardening, and RMF compliance apply but tooling, connectivity, and handling procedures differ. The engineer operates the classified-enclave endpoint management infrastructure (e.g., MECM/SCCM), engineers and validates hardened images and Group Policy baselines, executes CAT I/II/III patching within enclave constraints, supports classified VDI and cross-domain considerations, and produces RMF evidence for the classified endpoint systems. This TS/SCI privileged-user role is the Tier III escalation point for classified endpoint incidents. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.
THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.
JOB DUTIES:
- Engineer, operate, and maintain the SIPRNet and JWICS endpoint management infrastructure (MECM/SCCM, imaging, provisioning, Group Policy) in accordance with enclave-specific security, transfer, and handling procedures.
- Plan and execute CAT I/II/III patch and software deployments on the classified enclaves within PRS timeframes, managing media transfer and disconnected/air-gapped update workflows where required.
- Engineer and validate hardened images and configuration baselines for classified endpoints against DISA STIGs and enclave authority requirements, and provide RMF control evidence and POA&M inputs in eMASS for the classified endpoint systems.
- Serve as the Tier III escalation point for classified-enclave endpoint incidents and coordinate with the enclave network, cybersecurity, and communications teams.
- Lead the engineering design, implementation, and lifecycle of the enterprise endpoint infrastructure: hardened image pipelines, automated provisioning, endpoint management platform architecture (MECM/SCCM, Intune), configuration baselines, and VDI integration across all enclaves.
- Lead the evaluation, cost-benefit analysis, and phased implementation of the Digital Twin capability for network and system modeling; author the Digital Twin Evaluation and Implementation Plan; and establish the practice that every significant change is tested in the digital replica before deployment.
- Lead engineering for AI, automation, and analytics initiatives approved by the Government, including predictive analytics on service data, intelligent automation across support tiers, and integrations with the ITSM platform, and deliver Proof of Concept Reports documenting feasibility, risks, and benefits.
- Conduct market research and produce Market Research Reports and Rough Orders of Magnitude (ROMs) for emerging technologies and proposed solutions to support Government planning and IT Capability Request analysis.
REQUIREMENTS:
- Bachelor's degree and a minimum of 10 years of related experience (a Master's degree with 8 years of related experience, or an additional 4 years of related experience in lieu of a degree, may be substituted).
- Must be a U.S. Citizen.
- Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
- Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
- Must possess and maintain a current DoD 8570/8140 IAT Level III baseline certification (e.g., CASP+ CE, CISSP or Associate, CCNP Security, GCED, or GCIH).
- Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
- Minimum of 10 years of experience in systems or infrastructure engineering for enterprise Windows environments, including lead-engineer responsibility for endpoint or infrastructure programs at 10,000+ device scale.
- Expert knowledge of MECM/SCCM and/or Intune architecture, Windows Server, Active Directory, Group Policy, virtualization (VMware/Hyper-V), VDI, and PowerShell automation.
- Demonstrated experience designing and leading implementation of lab, pre-production, or digital twin environments and formal test-before-deploy practices.
- Experience leading proof-of-concept evaluations, market research, and cost-benefit/ROM development for Government or enterprise decision-makers.
- Extensive experience with DISA STIGs, ACAS/Nessus, RMF control implementation, POA&Ms, and eMASS.
- Experience leading engineering teams, establishing standards, and executing changes through formal Change Management.
- Excellent technical writing, briefing, and stakeholder communication skills; ability to participate in after-hours emergency on-call response.
- Experience working on siprnet and jwics enclaves and with classified media handling procedures.
DESIRED SKILLS:
- CISSP, CASP+ CE, or GCED; Microsoft 365 Certified: Administrator Expert; VMware VCP/VCAP; AWS or Azure architect certification.
- Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across NIPRNet, SIPRNet, and JWICS enclaves.
- Experience applying AI/ML, RPA, or AIOps to IT service management and endpoint operations, including ServiceNow integrations.
- Familiarity with DoD Zero Trust Strategy and Reference Architecture, DoDAF 2.02, DoD ICAM Strategy, and Technology Business Management (TBM).
- ITIL 4 Foundation or Managing Professional; PMP.
- Experience supporting IT Capability Request (ITCR) analysis and governance briefings.
PHYSICAL REQUIREMENTS
The physical demands described below are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to do the following:
- If remote, maintain home workspace in a safe manner, free from safety hazards and in line with information security policies.
- Communicate verbally in person, over the phone or by video chat and clearly/succinctly in writing, primarily utilizing a keyboard.
- Appear on camera for meetings with co-workers and government partners via video chat and ensure the protection of proprietary company and customer information is consistent with the company’s expectation of information security.
- Viewing computer screens and sitting for long periods of time.
- Travel minimally (10%), via car or plane, which requires ability to manage luggage, laptop, and briefing materials (up to 25 pounds).
group id: 10118911SU