Endpoint Engineering Specialist
Focused Management, Inc.
Our firm, Focused Management, Inc. (FMI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) and, Software Engineering Institute (SEI) – CMMI Maturity Level-3 Services Rated Company and we handle a wide range of government contracting...
Job description
Focused Management, Inc. (FMI) is seeking an experienced Endpoint Engineering Specialist to support the Congressional Budget Office (CBO). This position provides advanced engineering support for enterprise Windows and macOS endpoint environments, focusing on secure workstation engineering, operating system imaging, endpoint automation, patch management, device lifecycle management, Microsoft Intune, Windows Autopilot, JAMF, and enterprise telemetry. The successful candidate will engineer secure endpoint solutions, implement standardized workstation baselines, automate deployment processes, improve endpoint security, and support escalated engineering issues arising from the Service Desk. This is not a Tier 1 or Tier 2 Help Desk position; it is an enterprise endpoint engineering role supporting secure endpoint architecture and operations.
⸻
Primary Responsibilities
Design and maintain secure Windows and macOS workstation images.
Engineer standardized endpoint configurations and security baselines.
Manage endpoint operating system lifecycle and patch management.
Develop automated imaging and deployment processes.
Support Microsoft Intune and Windows Autopilot implementations.
Engineer endpoint compliance and configuration policies.
Integrate endpoint logging and telemetry with enterprise security platforms.
Support endpoint enrollment, provisioning, and lifecycle management.
Maintain enterprise asset inventory accuracy.
Develop endpoint engineering documentation and operational runbooks.
Perform root cause analysis for endpoint-related issues.
Support forensic data collection during security investigations.
Implement endpoint automation to improve operational efficiency.
Collaborate with cybersecurity, cloud, network, and Service Desk teams.
Provide Tier III engineering support for complex endpoint issues.
⸻
Required Qualifications
Minimum 8 years of Information Technology, Endpoint Engineering, or Cybersecurity experience.
Minimum 6 years performing enterprise engineering functions (not Help Desk support).
Experience supporting enterprise Windows and macOS environments.
Experience working within formal change management processes.
Experience supporting security and audit compliance initiatives.
Strong troubleshooting and analytical skills.
Excellent written and verbal communication skills.
Ability to work independently within an enterprise engineering team.
⸻
Required Technical Skills
US Citizenship is required (required)
Top Secret (TS) security clearance (required)
Candidates should demonstrate experience with:
Endpoint Engineering
Windows 11
macOS
Enterprise workstation engineering
Endpoint hardening
Configuration baselines
Endpoint lifecycle management
Endpoint Management
Microsoft Intune
Windows Autopilot
JAMF Pro
Group Policy (GPO)
Endpoint compliance policies
Device enrollment
Imaging & Deployment
Windows imaging
macOS imaging
Image automation
Image validation
Image version control
Image deployment
Rollback procedures
Patch Management
Ivanti
KACE
Microsoft Intune
Windows Update management
Third-party application patching
Configuration drift remediation
Authentication
Microsoft Entra ID
Passwordless authentication
YubiKeys
CAC/PIV authentication
Multi-Factor Authentication (MFA)
Monitoring & Logging
Windows Event Logs
macOS Unified Logs
SIEM integration
Endpoint telemetry
Security logging
Audit logging
Automation
PowerShell
Bash
Endpoint automation
Deployment scripting
Documentation
Runbooks
Standard Operating Procedures
Engineering documentation
Change documentation
Technical diagrams
These requirements reflect the engineering responsibilities defined for endpoint imaging, configuration management, enrollment, telemetry, and lifecycle operations. A
⸻
Preferred Qualifications
Experience supporting Federal Government environments.
Experience implementing NIST SP 800-53 controls.
Experience supporting Zero Trust initiatives.
Experience supporting enterprise VDI environments.
Experience integrating endpoint telemetry with Microsoft Sentinel or other SIEM platforms.
Experience supporting digital forensics and incident response.
Experience implementing enterprise automation solutions.
⸻
Preferred Certifications
One or more of the following is highly desirable:
Microsoft Certified: Endpoint Administrator Associate
Microsoft Certified: Identity and Access Administrator Associate
JAMF Certified Technician (100/200)
JAMF Certified Admin
CompTIA Security+
CompTIA Network+
Microsoft Certified: Modern Desktop Administrator (or successor certification)
ITIL Foundation
Note: The solicitation requires a for this SMA3 effort but does not mandate specific technical certifications for this role.
Job Types: Full-time, Contract
Pay: $110,000.00 - $115,000.00 per year
Benefits:
401(k)
Dental insurance
Health insurance
Paid time off
Vision insurance
Education:
Bachelor's (Preferred)
Experience:
Federal Government IT support: 3 years (Preferred)
Endpoint Engineering: 3 years (Required)
Windows 11: 4 years (Required)
macOS: 4 years (Required)
Microsoft Intune: 4 years (Required)
JAMF Pro: 4 years (Required)
SIEM: 4 years (Required)
PowerShell: 4 years (Preferred)
Security clearance:
Top Secret (Required)
Work Location: In person