Empower AI

ENDPOINT ENGINEER – (MAC SME)

Empower AI • $100K — $155K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree and 3+ years of experience, or a Master's degree with 8 years, or 4 years additional experience in lieu of a degree.
  • Active U.S. citizenship.
  • Top Secret clearance with SCI eligibility required.
  • Current DoD 8570/8140 IAT Level I certification needed before cybersecurity duties.
  • Minimum 5 years in enterprise MAC OS systems or infrastructure engineering.

Responsibilities

  • Engineer and maintain macOS/iOS/ Jamf endpoint systems within classified networks.
  • Plan and execute patch deployments adhering to enclave protocols.
  • Validate hardening and configuration baselines against DISA STIGs.
  • Provide Tier III support for classified endpoint incidents, collaborating with various teams.
  • Lead design and implementation of endpoint infrastructure, ensuring compliance and security.

Benefits

  • Ongoing professional development opportunities.
  • Supportive work environment for independent decision-making.
  • Exposure to cutting-edge technologies and methodologies.
  • Involvement with government cybersecurity initiatives.
  • Potential for engaging interdisciplinary projects.
Full Job Description
Overview

Empower AI is seeking an Endpoint Engineer – MAC SME to engineer and sustain the MAC (macOS / iOS/ Jamf) endpoint systems and infrastructure on the NIPRNet, SIPRNet and JWICS (as available) enclaves of a Department of War agency, where the same standards of automation, hardening, and RMF compliance apply but tooling, connectivity, and handling procedures differ. The engineer operates the classified-enclave endpoint management infrastructure (e.g., Jamf), engineers and validates hardened images and Group Policy baselines, executes CAT I/II/III patching within enclave constraints, supports classified VDI and cross-domain considerations, and produces RMF evidence for the classified endpoint systems. This TS/SCI privileged-user role is the Tier III escalation point for classified endpoint incidents. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.

 

THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

 

JOB DUTIES:

  • Engineer, operate, and maintain the NIPIRNet, SIPRNet and JWICS endpoint systems and management infrastructure (macOS / iOS/ Jamf, imaging, provisioning, Group Policy) in accordance with enclave-specific security, transfer, and handling procedures.
  • Plan and execute CAT I/II/III patch and software deployments on the classified enclaves within PRS timeframes, managing media transfer and disconnected/air-gapped update workflows where required.
  • Engineer and validate hardened images and configuration baselines for classified endpoints against DISA STIGs and enclave authority requirements, and provide RMF control evidence and POA&M inputs in eMASS for the classified endpoint systems.
  • Serve as the Tier III escalation point for classified-enclave endpoint incidents and coordinate with the enclave network, cybersecurity, and communications teams.
  • Lead the engineering design, implementation, and lifecycle of the enterprise endpoint infrastructure: hardened image pipelines, automated provisioning, endpoint management platform architecture (Jamf), configuration baselines, and VDI integration across all enclaves.
  • Lead the evaluation, cost-benefit analysis, and phased implementation of the Digital Twin capability for network and system modeling; author the Digital Twin Evaluation and Implementation Plan; and establish the practice that every significant change is tested in the digital replica before deployment.
  • Lead engineering for AI, automation, and analytics initiatives approved by the Government, including predictive analytics on service data, intelligent automation across support tiers, and integrations with the ITSM platform, and deliver Proof of Concept Reports documenting feasibility, risks, and benefits.
  • Conduct market research and produce Market Research Reports and Rough Orders of Magnitude (ROMs) for emerging technologies and proposed solutions to support Government planning and IT Capability Request analysis.
Qualifications

REQUIREMENTS:

  • Bachelor's degree and a minimum of 3 years of related experience (a Master's degree with 8 years of related experience, or an additional 4 years of related experience in lieu of a degree, may be substituted). 7 years (education/experience) overall minimum required.
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level I baseline certification (e.g., CompTIA A+ CE, Network+ CE, Security+ CE, CCNA-Security, or SSCP) prior to performing cybersecurity-related duties.
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 5 years of experience in systems or infrastructure engineering for enterprise MAC OS environments.
  • Current Apple Certified Support Professional (ACSP) Badge.
  • Expert knowledge of macOS / iOS/ Jamf and/or MAC architecture, Active Directory, Group Policy, and MAC automation.
  • Demonstrated experience designing and leading implementation of lab, pre-production, or digital twin environments and formal test-before-deploy practices.
  • Experience leading proof-of-concept evaluations, market research, and cost-benefit/ROM development for Government or enterprise decision-makers.
  • Extensive experience with DISA STIGs, ACAS/Nessus, RMF control implementation, POA&Ms, and eMASS.
  • Experience leading engineering teams, establishing standards, and executing changes through formal Change Management.
  • Excellent technical writing, briefing, and stakeholder communication skills; ability to participate in after-hours emergency on-call response.
  • Experience working on NIPRNet, SIPRNet and/or JWICS enclaves and with classified media handling procedures.

 

DESIRED SKILLS:

  • CISSP, CASP+ CE, or GCED; AWS or Azure architect certification.
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across NIPRNet, SIPRNet, and JWICS enclaves.
  • Experience applying AI/ML, RPA, or AIOps to IT service management and endpoint operations, including ServiceNow integrations.
  • Familiarity with DoD Zero Trust Strategy and Reference Architecture, DoDAF 2.02, DoD ICAM Strategy, and Technology Business Management (TBM).
  • ITIL 4 Foundation or Managing Professional; PMP.
  • Experience supporting IT Capability Request (ITCR) analysis and governance briefings.

 

Pay Band MinUSD $100,410.00/Yr. Pay Band MaxUSD $155,410.00/Yr.

About Empower AI

Empower AI is a privately held company that develops artificial intelligence software for the healthcare industry. The company was founded in 2017 and is headquartered in Cambridge, Massachusetts. Empower AI's software uses machine learning algorithms to analyze medical data and provide insights to healthcare providers. The company's software is designed to improve patient outcomes and reduce healthcare costs. Empower AI has approximately 50 employees and operates in the United States.
Learn more about Empower AI
Size
50 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Empower AI

More Information Technology Jobs

Find similar ENDPOINT ENGINEER – (MAC SME) jobs: