MECM / SCCM ENGINEER with Security Clearance
Empower AI
Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience...
Job description
* Design and maintain automated deployment mechanisms (software update deployments, application deployments, task sequences, PXE/OSD provisioning) and analyze deployment results to resolve failures and improve success rates.
* Plan and validate MECM upgrades, client updates, and configuration changes in pre-production and the Digital Twin environment, and implement them through formal Change Management with rollback plans.
* Produce MECM compliance and deployment reporting (patch compliance, image deployment cycle time, client health) for the Customer Support Metrics Dashboard and provide artifacts supporting the endpoint POA&M.
* Design, engineer, test, and implement endpoint infrastructure solutions including hardened image pipelines, automated provisioning, configuration baselines, endpoint management platform enhancements, and VDI integration across multiple security enclaves.
* Support the evaluation and phased implementation of a Digital Twin capability for network and system modeling, including building and maintaining the pre-production replica, defining test procedures, and validating significant changes before production deployment.
* Develop engineering artifacts for Government approval: requirements, design documents, test plans and results, implementation and rollback plans, change packages, and as-built documentation.
* Engineer and integrate automation, AI/ML, and analytics capabilities (e.g., predictive analytics on service data, automated remediation, ServiceNow integrations) that improve support across all tiers, upon Government approval. REQUIREMENTS: * Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
* Must be a U.S. Citizen.
* Must have an Active Top Secret Clearance (favorably adjudicated T5/T5R) to start; this is a Privileged User position.
* Must be willing and able to obtain TS/SCI eligibility after start, if required by mission needs.
* Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
* Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security).
* Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
* Minimum of 3 years of experience in systems engineering, infrastructure engineering, or senior systems administration in an enterprise Windows environment.
* Hands-on experience with MECM/SCCM and/or Intune, Windows Server, Active Directory, Group Policy, virtualization (e.g., VMware, Hyper-V), and PowerShell scripting.
* Experience developing engineering documentation (requirements, designs, test plans, change packages) and executing changes through formal Change Management.
* Experience applying DISA STIGs, working with ACAS/Nessus results, and supporting RMF control implementation and evidence collection.
* Understanding of IP networking, VDI, and endpoint security concepts sufficient to design and troubleshoot integrated solutions.
* Strong analytical, technical writing, and communication skills; ability to participate in an after-hours on-call rotation.
DESIRED SKILLS: * CompTIA Security+ CE, CySA+, or CASP+ CE; Microsoft 365 Certified: Endpoint Administrator Associate; VMware VCP.
* Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across NIPRNet, SIPRNet, and JWICS enclaves.
* Experience building lab, pre-production, or digital twin environments for change validation and network modeling.
* Experience integrating AI/ML, RPA, or predictive analytics into IT operations, and familiarity with ServiceNow integrations and APIs.
* Familiarity with DoD Zero Trust Reference Architecture, DoDAF, and DoD ICAM Strategy.
* Experience with eMASS and RMF documentation.
* ITIL 4 Foundation certification.
PHYSICAL REQUIREMENTS: This position requires the ability to perform the below essential functions: * Sitting for long periods
* Standing for long periods
* Ambulate throughout an office
* Ambulate between several buildings