Our firm, Focused Management, Inc. (FMI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) and, Software Engineering Institute (SEI) – CMMI Maturity Level-3 Services Rated Company and we handle a wide range of government contracting opportunities. www.focusedmgmtinc.com
Focused Management, Inc. (FMI) is seeking an experienced Endpoint Engineering Specialist to support the Congressional Budget Office (CBO). This position provides advanced engineering support for enterprise Windows and macOS endpoint environments, focusing on secure workstation engineering, operating system imaging, endpoint automation, patch management, device lifecycle management, Microsoft Intune, Windows Autopilot, JAMF, and enterprise telemetry. The successful candidate will engineer secure endpoint solutions, implement standardized workstation baselines, automate deployment processes, improve endpoint security, and support escalated engineering issues arising from the Service Desk. This is not a Tier 1 or Tier 2 Help Desk position; it is an enterprise endpoint engineering role supporting secure endpoint architecture and operations.
⸻
Primary Responsibilities
- Design and maintain secure Windows and macOS workstation images.
- Engineer standardized endpoint configurations and security baselines.
- Manage endpoint operating system lifecycle and patch management.
- Develop automated imaging and deployment processes.
- Support Microsoft Intune and Windows Autopilot implementations.
- Engineer endpoint compliance and configuration policies.
- Integrate endpoint logging and telemetry with enterprise security platforms.
- Support endpoint enrollment, provisioning, and lifecycle management.
- Maintain enterprise asset inventory accuracy.
- Develop endpoint engineering documentation and operational runbooks.
- Perform root cause analysis for endpoint-related issues.
- Support forensic data collection during security investigations.
- Implement endpoint automation to improve operational efficiency.
- Collaborate with cybersecurity, cloud, network, and Service Desk teams.
- Provide Tier III engineering support for complex endpoint issues.
⸻
Required Qualifications
- Minimum 8 years of Information Technology, Endpoint Engineering, or Cybersecurity experience.
- Minimum 6 years performing enterprise engineering functions (not Help Desk support).
- Experience supporting enterprise Windows and macOS environments.
- Experience working within formal change management processes.
- Experience supporting security and audit compliance initiatives.
- Strong troubleshooting and analytical skills.
- Excellent written and verbal communication skills.
- Ability to work independently within an enterprise engineering team.
⸻
Required Technical Skills
- US Citizenship is required (required)
- Top Secret (TS) security clearance (required)
Candidates should demonstrate experience with:
Endpoint Engineering
- Windows 11
- macOS
- Enterprise workstation engineering
- Endpoint hardening
- Configuration baselines
- Endpoint lifecycle management
Endpoint Management
- Microsoft Intune
- Windows Autopilot
- JAMF Pro
- Group Policy (GPO)
- Endpoint compliance policies
- Device enrollment
Imaging & Deployment
- Windows imaging
- macOS imaging
- Image automation
- Image validation
- Image version control
- Image deployment
- Rollback procedures
Patch Management
- Ivanti
- KACE
- Microsoft Intune
- Windows Update management
- Third-party application patching
- Configuration drift remediation
Authentication
- Microsoft Entra ID
- Passwordless authentication
- YubiKeys
- CAC/PIV authentication
- Multi-Factor Authentication (MFA)
Monitoring & Logging
- Windows Event Logs
- macOS Unified Logs
- SIEM integration
- Endpoint telemetry
- Security logging
- Audit logging
Automation
- PowerShell
- Bash
- Endpoint automation
- Deployment scripting
Documentation
- Runbooks
- Standard Operating Procedures
- Engineering documentation
- Change documentation
- Technical diagrams
These requirements reflect the engineering responsibilities defined for endpoint imaging, configuration management, enrollment, telemetry, and lifecycle operations. A
⸻
Preferred Qualifications
- Experience supporting Federal Government environments.
- Experience implementing NIST SP 800-53 controls.
- Experience supporting Zero Trust initiatives.
- Experience supporting enterprise VDI environments.
- Experience integrating endpoint telemetry with Microsoft Sentinel or other SIEM platforms.
- Experience supporting digital forensics and incident response.
- Experience implementing enterprise automation solutions.
⸻
Preferred Certifications
One or more of the following is highly desirable:
- Microsoft Certified: Endpoint Administrator Associate
- Microsoft Certified: Identity and Access Administrator Associate
- JAMF Certified Technician (100/200)
- JAMF Certified Admin
- CompTIA Security+
- CompTIA Network+
- Microsoft Certified: Modern Desktop Administrator (or successor certification)
- ITIL Foundation
Note: The solicitation requires a for this SMA3 effort but does not mandate specific technical certifications for this role.
Job Types: Full-time, Contract
Pay: $110,000.00 - $115,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Education:
Experience:
- Federal Government IT support: 3 years (Preferred)
- Endpoint Engineering: 3 years (Required)
- Windows 11: 4 years (Required)
- macOS: 4 years (Required)
- Microsoft Intune: 4 years (Required)
- JAMF Pro: 4 years (Required)
- SIEM: 4 years (Required)
- PowerShell: 4 years (Preferred)
Security clearance:
Work Location: In person