Job Requirements
Washington, DC
Public Trust Polygraph Unspecified
Career Level not specified
$150,000 - $175,000
Job Description
Senior Endpoint Engineer
Hybrid in Washington, DC - on site at least 2 days per week
The Senior Endpoint Engineer defines the target state for how a federal agency's devices are provisioned, managed, secured and supported, and leads the engineering work to get there. The central mission is modernization: moving the fleet from a ConfigMgr-centric, on-premises model to a cloud-native model built on Microsoft Intune, Entra ID, Windows Autopilot and Windows Autopatch, aligned to federal Zero Trust requirements. You own the roadmap, the design decisions and the reference standards for that transition while staying hands-on with ConfigMgr, Intune, Dell enterprise tooling and BeyondTrust. This is an individual-contributor role with no supervisory duties; it leads through technical direction. Work is tracked in ServiceNow and Azure DevOps (ADO) Boards.
Endpoint Architecture and Strategy:
Modernization Delivery:
Security, Automation and Leadership:
Requirements:
Preferred:
Compensation: $150,000 - $175,000 per year
#cjpost
Hybrid in Washington, DC - on site at least 2 days per week
The Senior Endpoint Engineer defines the target state for how a federal agency's devices are provisioned, managed, secured and supported, and leads the engineering work to get there. The central mission is modernization: moving the fleet from a ConfigMgr-centric, on-premises model to a cloud-native model built on Microsoft Intune, Entra ID, Windows Autopilot and Windows Autopatch, aligned to federal Zero Trust requirements. You own the roadmap, the design decisions and the reference standards for that transition while staying hands-on with ConfigMgr, Intune, Dell enterprise tooling and BeyondTrust. This is an individual-contributor role with no supervisory duties; it leads through technical direction. Work is tracked in ServiceNow and Azure DevOps (ADO) Boards.
Endpoint Architecture and Strategy:
- Define and maintain the endpoint target-state architecture across identity, provisioning, configuration, application delivery, update management, security and support tooling.
- Own the multi-year endpoint modernization roadmap, with phases, dependencies, entry and exit criteria, and risk for each phase.
- Produce architecture artifacts: current- and target-state diagrams, design documents, architecture decision records (ADRs) and reference configurations.
- Evaluate new Microsoft and vendor capabilities, run proofs of concept, and recommend adoption, deferral or retirement with cost, risk and effort analysis.
- Define the user persona model and set endpoint engineering standards for naming, policy design, assignment and filtering, app packaging and baseline management.
- Advise program leadership on endpoint risk, technical debt, licensing and investment priorities.
Modernization Delivery:
- Lead the transition from ConfigMgr to Intune, moving co-management workloads in planned waves with pilot groups and defined success criteria.
- Drive the move from hybrid join toward Entra ID join and zero-touch provisioning with Windows Autopilot.
- Modernize update management with Windows Update for Business and Windows Autopatch, including ring design and driver and firmware update policy.
- Move application delivery to Intune Win32 apps and catalog-based app management, and retire legacy packages.
- Replace on-premises dependencies with cloud services where approved, such as Windows LAPS, cloud-based certificate delivery and Intune Remediations.
- Plan the reduction and eventual decommissioning of ConfigMgr infrastructure.
- Coordinate cutovers with imaging, identity, network, security and service desk teams, with tested rollback plans for each wave.
- Act as senior escalation point for ConfigMgr, Intune, co-management, Autopilot and Windows 11 client issues.
Security, Automation and Leadership:
- Design endpoint security configuration to meet NIST SP 800-53 controls, Microsoft security baselines and applicable DISA STIG or CIS benchmarks.
- Define device compliance signals for Entra Conditional Access in partnership with the identity and security teams.
- Build automation in PowerShell and the Microsoft Graph API for provisioning, configuration, compliance checks and reporting.
- Develop KQL and SQL queries and dashboards (SSRS, Power BI, or Intune and Endpoint Analytics reports), and report modernization metrics.
- Author and present Change Advisory Board (CAB) requests for architecture-level and high-risk changes, and review other engineers' changes.
- Plan roadmap work in ADO Boards linked to ServiceNow records; write SOPs, runbooks and knowledge articles.
- Mentor engineers through design reviews, pairing and walkthroughs.
Requirements:
- Bachelor's degree in Information Technology, Computer Science or a related field, or 12+ years of relevant experience in lieu of a degree.
- 8+ years of enterprise Windows endpoint management experience, including 2+ years leading the design of significant endpoint initiatives.
- Hands-on experience with both ConfigMgr and Microsoft Intune, including co-management, having moved at least one workload or device population from ConfigMgr to Intune.
- Has designed and deployed Windows Autopilot for production users in at least one deployment mode.
- PowerShell scripting for automation; able to read and adapt scripts that use the Microsoft Graph API.
- Clear writing of design documents, diagrams and SOPs that other engineers can carry out.
- Experience with incidents, problems and change requests in ServiceNow or a comparable ITSM tool.
- CompTIA Security+ held at start or earned within 90 days.
- On site in Washington, DC at least 2 days per week.
- US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.
Preferred:
- Windows Update for Business or Windows Autopatch, Intune Remediations and Endpoint Analytics.
- Working knowledge of Entra ID, Conditional Access and device compliance in a Zero Trust model.
- SQL and KQL for querying ConfigMgr, Intune and endpoint telemetry data.
- Endpoint work in a federal environment under FISMA, NIST SP 800-53 and CISA directives, including Microsoft government cloud.
- Dell enterprise tooling (Dell Command | Update, Dell Command | Configure, BIOS and Secure Boot management).
- BeyondTrust or a comparable privileged access or remote support platform; Microsoft Defender for Endpoint, Windows LAPS or Azure DevOps Boards.
- Certifications such as Microsoft MD-102, MS-102, SC-300 or ITIL 4 Foundation.
Compensation: $150,000 - $175,000 per year
#cjpost
group id: 10238000