Service Desk & Infrastructure EngineerPosition SummarySofttek Government Solutions is seeking highly cleared, experienced IT engineering professionals to support the Congressional Budget Office (CBO) Service Desk Engineering task order. This initiative focuses on fundamentally hardening the CBO's enterprise environment to reduce the risk of unauthorized lateral movement, credential misuse, and persistence techniques.
Note: This is an advanced engineering scope focused on resolving complex escalations, implementing security architecture, and developing automated workflows. It does not involve routine Tier 1 end-user help desk support.
The engineering team will be responsible for designing, deploying, and maintaining the technical controls necessary to secure endpoint, identity, and device lifecycle operations.
Responsibilities- Design, implement, and maintain secure standard workstation images for both macOS and Windows (on-site and VDI).
- Engineer and operate patch management processes and application lifecycle management using Ivanti and/or KACE.
- Maintain imaging toolchains and automation scripts with version control and a formal build, test, sign-off, release process.
- Ensure endpoint logging agents (EDR, AV) are installed and reporting accurately to central SIEM platforms.
- Configure log-forwarding, parsing, and normalization rules so security-relevant events are usable for detection and incident response.
- Support device registration, enrollment, and asset inventory accuracy across macOS and Windows platforms.
- Produce user-facing runbooks, validation steps, and automation scripts for the Service Desk.
Education- Bachelor's degree in Information Technology, Cybersecurity, or a related field. Formal education requirements may be waived based on relevant professional experience
Qualifications- Must be a US Citizen
- Minimum 8 years of experience in IT, Endpoint Engineering, or Cybersecurity, with at least 6 years in engineering (not help desk) roles in enterprise environments.
- Extensive experience with image automation, validation, and version control across macOS and Windows.
- Hands-on expertise using Ivanti and/or KACE for OS and third-party application patching.
- Proficiency configuring endpoint logging and log forwarding to SIEM/EDR platforms (e.g., MS Sentinel).
- Experience working under formal change control, audit, and security governance processes.
Required Clearance - Active Top Secret (TS) security clearance.