Job DescriptionDesktop Engineering LeadLead is responsible for architecting, securing, and maintaining the organization's endpoint infrastructure (desktops, laptops, and mobile devices). They lead a team of engineers, oversee device lifecycles, and drive modern IT automation.
ResponsibilitiesResponsibilities- Administer endpoint management platforms including Microsoft Intune and related configuration management tools to enforce patch compliance, device encryption, application deployment standards, and endpoint security configurations consistent with industry cybersecurity control frameworks
- Oversee enterprise patch management cycles for endpoints, ensuring timely vulnerability remediation, documentation within ITSM change workflows, and validation of successful deployment prior to closure
- Coordinate with Identity, Credential, and Access Management (ICAM) leadership to ensure workstation authentication controls, MFA enforcement, certificate deployment, and conditional access configurations are functioning properly within Microsoft Entra ID and Microsoft 365 integrations
- Validate endpoint log forwarding and monitoring integration with enterprise monitoring platforms to ensure visibility into device health, configuration compliance, and potential security anomalies
- Produce and maintain workstation engineering documentation including gold image standards, configuration baselines, lifecycle refresh schedules, and compliance dashboards
- Support root cause analysis for enterprise-wide endpoint incidents, configuration conflicts, or patch deployment failures and implement corrective actions to prevent recurrence
- Participate in Change Advisory Board (CAB) reviews to assess risk and approve major workstation environment changes prior to deployment
QualificationsMinimum Qualifications:- Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience.
- 7-9 years of IT support experience, with at least 1-2 years in a supervisory role.
- Complies with all policies and standards.
- Maintain appropriate level government security clearance.
- Experience engineering enterprise Windows desktop environments and secure configuration baselines
Preferred Qualifications:- Knowledge of endpoint management platforms including Intune or similar device management tools
- Familiarity with endpoint encryption, Defender security controls, and compliance reporting
- Experience integrating workstation logs with SIEM platforms
- Knowledge of lifecycle refresh planning and endpoint inventory management
- Preferred Certifications: Microsoft Certified: Endpoint Administrator Associate; CompTIA Security+
Some of the *Benefits offered to employees include:
*Benefits vary based upon employment status
- Highly competitive Medical, Dental, and Vision options including HSA options with company provided seed
- Short- & Long-Term Disability (company paid)
- Life Insurance Non-Contributary 1X salary (company paid)
- AD&D Non-contributary 1x salary (company paid)
- Savings & Investment plan:
-
- Qualified Non-Elective Company Contribution of 5% each pay period with immediate vesting
- Company match 50 cents/dollar up to 8% (5 yrs. vesting in company match)
- Contributory Life Insurance up to 5x Salary with $1M Cap
- Contributory AD&D (employee, spouse and children)
- Paid Time Off
- Employee Assistance Plan
- SRNL offers a competitive relocation package to ease the transition process. Domestic and international relocation assistance is available for certain positions.
For more information about our benefits, working here, and living here, visit the "About" tab at www.srnl.doe.gov.