Mecm / Sccm Engineer
Empower AI
Overview Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of...
Job description
experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai. Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees. Responsibilities Description Empower AI is seeking a MECM / SCCM Engineer to engineer and operate the Microsoft Endpoint Configuration Manager infrastructure that manages thousands of endpoints for a Department of War agency across Pre-Production, NIPRNet, SIPRNet, and JWICS enclaves. The engineer designs and maintains the MECM hierarchy, distribution points, boundaries, collections, client health, and reporting; engineers automated patch and software deployment, task sequences, and PXE provisioning; and validates every significant change in pre-production and the Digital Twin environment before release. As a privileged user, the engineer is a Tier III escalation resource and a primary contributor to CAT I/II/III patch compliance and RMF evidence for the endpoint environment. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED. JOB DUTIES: - Engineer, operate, and maintain the MECM/SCCM infrastructure across enclaves: hierarchy and site health, distribution points, boundaries and boundary groups, collections, client health remediation, role-based administration, and reporting. - Design and maintain automated deployment mechanisms (software update deployments, application deployments, task sequences, PXE/OSD provisioning) and analyze deployment results to resolve failures and improve success rates. - Plan and validate MECM upgrades, client updates, and configuration changes in pre-production and the Digital Twin environment, and implement them through formal Change Management with rollback plans. - Produce MECM compliance and deployment reporting (patch compliance, image deployment cycle time, client health) for the Customer Support Metrics Dashboard and provide artifacts supporting the endpoint POA&M. - Design, engineer, test, and implement endpoint infrastructure solutions including hardened image pipelines, automated provisioning, configuration baselines, endpoint management platform enhancements, and VDI integration across multiple security enclaves. - Support the evaluation and phased implementation of a Digital Twin capability for network and system modeling, including building and maintaining the pre-production replica, defining test procedures, and validating significant changes before production deployment. - Develop engineering artifacts for Government approval: requirements, design documents, test plans and results, implementation and rollback plans, change packages, and as-built documentation. - Engineer and integrate automation, AI/ML, and analytics capabilities (e.g., predictive analytics on service data, automated remediation, ServiceNow integrations) that improve support across all tiers, upon Government approval. Qualifications REQUIREMENTS: - Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree). - Must be a U.S. Citizen. - Must have an Active Top Secret Clearance (favorably adjudicated T5/T5R) to start; this is a Privileged User position. - Must be willing and able to obtain TS/SCI eligibility after start, if required by mission needs. - Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting. - Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security). - Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision. - Minimum of 3 years of experience in systems engineering, infrastructure engineering, or senior systems administration in an enterprise Windows environment. - Hands-on experience with MECM/SCCM and/or Intune, Windows Server, Active Directory, Group Policy, virtualization (e.g., VMware, Hyper-V), and PowerShell scripting. - Experience developing engineering documentation (requirements, designs, test plans, change packages) and executing changes through formal Change Management. - Experience applying DISA STIGs, working with ACAS/Nessus results, and supporting RMF control implementation and evidence collection. - Understanding of IP networking, VDI, and endpoint security concepts sufficient to design and troubleshoot integrated solutions. - Strong analytical, technical writing, and communication skills; ability to participate in an after-hours on-call rotation. DESIRED SKILLS: - CompTIA Security+ CE, CySA+, or CASP+ CE; Microsoft 365 Certified: Endpoint Administrator Associate; VMware VCP. - Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across NIPRNet, SIPRNet, and JWICS enclaves. - Experience building lab, pre-production, or digital twin environments for change validation and network modeling. - Experience integrating AI/ML, RPA, or predictive analytics into IT operations, and familiarity with ServiceNow integrations and APIs. - Familiarity with DoD Zero Trust Reference Architecture, DoDAF, and DoD ICAM Strategy. - Experience with eMASS and RMF documentation. - ITIL 4 Foundation certification. PHYSICAL REQUIREMENTS: This position requires the ability to perform the below essential functions: - Sitting for long periods - Standing for long periods - Ambulate throughout an office - Ambulate between several buildings About Empower AI All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.