Endpoint Engineer (Public Trust)

System One

Washington, DC

JOB DETAILS
SALARY
$55.31–$55.31 Per Hour
SKILLS
Apple, Automation, Business Performance Management, Change Control, Computer Science, Computer Security, Contract Requirements, Cross-Functional, Customer Support/Service, Desktop Virtualization, Documentation, Ecosystems, Endpoint Security, Enterprise Applications, Enterprise Endpoint, FISMA - Federal Information Security Management Act, ITIL (IT Infrastructure Library), Identify Issues, Information Technology & Information Systems, Laptop PC, Leadership, Machine Tool, Maintain Compliance, Management Strategy, Mentoring, Metrics, Microsoft Product Family, Microsoft Windows Operating System, Microsoft Windows System Administration, Migration Strategy, Mobile Devices, Multiplatform/Cross-Platform, Onboarding, Operational Audit, Operational Support, Outsourcing, Problem Solving Skills, Process Improvement, Regulatory Compliance, Reliability Engineering, Reporting Dashboards, Scripting (Scripting Languages), Securities and Exchange Commission (SEC), Security Analysis, Security Clearance, Security Compliance, Security Infrastructure, Security Policy, Service Delivery, Service Level Agreement (SLA), Software Patches, Source Code/Configuration Management (SCM), Standard Operating Procedures (SOP), Support Documentation, Systems Administration/Management, Technical Leadership, U.S. National Institute of Standards and Technology (NIST), Virtualization, Windows PowerShell
LOCATION
Washington, DC
POSTED
1 day ago

Job Title: Endpoint Engineer
Role Type: 6 + months Contractto Hire
Location: Onsite – Washington, DC.
Security Clearance: Ability to obtain and maintain SEC Public Trust (or higher if required)


POSITION SUMMARY
The EUT Specialist-SME provides senior technical leadership for endpoint management services supporting the SEC Infrastructure Support Services (ISS) contract. This role ensures secure, reliable lifecycle operations for SEC endpoint platforms, including Windows devices, virtual endpoints, and mobile assets, in alignment with PWS requirements for compliance, operational readiness, and service quality. The SME leads design and enforcement of endpoint baselines, patching, vulnerability remediation, and policy controls while supporting modernization initiatives such as Microsoft Intune, Windows Autopilot, and Microsoft Defender for Endpoint. The position also drives cross-functional resolution of complex endpoint issues, maintains SOPs and documentation for audit readiness, and mentors technical staff to improve service performance and consistency.

PRIMARY RESPONSIBILITIES

Endpoint Lifecycle and Platform Operations

- Lead operations and maintenance for SEC-issued endpoints, including laptops, desktops, virtual computers, and mobile devices.
- Direct provisioning, configuration, and decommissioning activities across the full endpoint lifecycle in accordance with SEC standards.
- Oversee enterprise application packaging, deployment, and maintenance for baseline and mission-specific software.
- Manage preproduction endpoint environments to validate new configurations, updates, and releases before production deployment.

Security, Compliance, and Policy Governance

- Establish and maintain endpoint configuration baselines, compliance policies, and security controls for Windows and supported mobile platforms.
- Lead patch and vulnerability management activities, including remediation planning and closure reporting.
- Develop, maintain, and version-control endpoint SOPs, architecture artifacts, and operational documentation to support FISMA and audit readiness.
- Ensure endpoint operations align with SEC policy, zero-trust objectives, and approved change control processes.

Intune Engineering and Automation

- Serve as the technical SME for Microsoft Intune in Windows environments, including device configuration profiles, compliance policies, and application delivery.
- Lead Autopilot and endpoint onboarding workflows to improve deployment speed, user readiness, and provisioning consistency.
- Design and implement PowerShell and automation solutions to reduce manual effort, improve reliability, and standardize endpoint operations.
- Integrate endpoint management workflows with enterprise tooling and reporting processes to improve visibility and service performance.

Incident Resolution, Collaboration, and Service Improvement

- Lead complex troubleshooting for Autopilot enrollment failures, policy conflicts, application packaging issues, and endpoint compliance anomalies.
- Coordinate with security, infrastructure, service desk, and vendor teams to resolve escalated incidents and prevent recurrence.
- Provide technical mentorship and quality oversight to endpoint engineers and support personnel.
- Support endpoint SLA/operational reporting, including metrics for patch compliance, incident trends, lifecycle status, and service outcomes.

REQUIRED QUALIFICATIONS

Citizenship/Work Authorization:
Must meet contract requirements.
Clearance:
Ability to obtain and maintain SEC Public Trust (or higher if required).
Education:
Bachelors in a relevant field (e.g., Information Technology, Computer Science, Engineering).

Experience:

- 12+ years of experience in endpoint engineering and enterprise endpoint management within complex IT environments.
- Demonstrated subject matter expertise in Microsoft Intune for Windows endpoint administration and policy management.
- Demonstrated experience supporting multi-platform endpoint environments, including Windows and mobile/Apple ecosystems.
- Proven experience leading endpoint security, lifecycle management, troubleshooting, and documentation/SOP governance in regulated environments.
- Demonstrated experience leading endpoint modernization initiatives, including Windows Autopilot and Microsoft Defender for Endpoint.

Technical Skills:

- Microsoft Intune (Windows endpoint management, configuration profiles, compliance policies, and application delivery)
- Multi-platform endpoint administration across Windows and mobile/Apple ecosystem devices
- Windows lifecycle management and endpoint policy baselines
- Endpoint security controls and compliance policy governance
- Windows Autopilot
- Microsoft Defender for Endpoint
- PowerShell scripting and endpoint automation
- Enterprise application packaging and deployment
- Troubleshooting of enrollment failures, policy conflicts, and compliance anomalies

PREFERRED QUALIFICATIONS

- Experience supporting U.S. federal IT environments with FISMA, NIST, and zero-trust control implementation.
- Hands-on experience with co-management or migration strategies across Intune and legacy endpoint management platforms.
- Demonstrated success building endpoint operational dashboards and reporting integrations for compliance and SLA tracking.
- Strong experience leading cross-functional endpoint modernization efforts in large, distributed user environments.
- Advanced troubleshooting experience across identity, policy, and security tooling integrations impacting endpoint compliance.
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- ITIL 4 Foundation


System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

#M-2
#LI-CB5

Ref: #851-Rockville-S1


About the Company

S

System One

Every day, System One focuses on services and solutions that require a high degree of specialization, in-demand technical skills, and large-scale operational expertise. We are essential partners to those on the front lines of our nation’s most critical infrastructure, technology, and life sciences initiatives. 

Founded more than 40 years ago as a staffing partner to the engineering industry, today System One is a diversified organization operating in over 50 locations and putting more than 9,000 people to work in the United States, Canada, and the United Kingdom.

COMPANY SIZE
2,500 to 4,999 employees
INDUSTRY
Staffing/Employment Agencies
WEBSITE
https://systemone.com