Senior Lead Workstation and Systems Engineering

Innovative Computer Solutions Group, Inc
United States
3 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$124,800.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Apple Mac Systems Application Packaging Systems Engineering Audio Video Distribution Microsoft Azure BIOS Cloud Computing Cloud Computing Security Configuration Management CompTIA Security+ Identity and Access Management
+20 more
Network Security Microsoft Servers System Center Configuration Manager Virtual Desktops Windows PowerShell Proprietary Software Regression Testing Systems Integration Microsoft Deployment Toolkit Cloud Platform System Delivery Pipeline Microsoft InTune Information Technology Deployment Automation Patch Management 3-tier Architectures CIS Benchmarks Serverless Computing Server Operating Systems & Platforms Windows Client

Job description

The Senior Lead, Workstation & Systems Engineering serves as the principal technical authority and task lead responsible for the design, testing, lifecycle maintenance, security, and deployment of enterprise workstation images and patch management across NRC physical, virtual, and cloud environments (including Azure Virtual Desktop). This role directs image engineering via MECM and MDT, leads the transition toward a unified configuration management toolset, oversees the Enterprise Development and Testing Environment, and ensures strict compliance with federal baselines (DISA STIGs, NIST, FISMA, FDCCI). The Lead also acts as the top-tier escalation authority for Tier 3 troubleshooting and root cause analysis., * Master Image Architecture & Management:

o Engineer, test, and maintain the hardware-independent Gold/Base Image and full image library across physical endpoints, virtual instances, and Azure Virtual Desktop (AVD) platforms. o Build, maintain, and version specialized image variants through the Change Control Board (CCB), including Apple macOS workstations, International/Domestic Loaners, International Assignees, Public Document Room kiosks, and office-specific configurations. o Maintain and update hardware firmware, BIOS baselines, and certified driver packs across all deployed enterprise endpoints. o Provide multi-channel image distribution flexibility across network distribution servers, secure cloud storage, and offline media (USB)

  • Patch, Release & Deployment Engineering:

o Plan, package, test, and execute monthly and out-of-band security updates, OS patches, and third-party software deployments across all workstations and Microsoft servers. o Maintain, validate, and conduct pre-deployment testing within the Enterprise Development and Testing Environment to guarantee environment congruency between Dev, Test, Pre-Production, and Production. o Collaborate with Application Owners, System Administrators, Network & Security Engineering, and Compute & Storage teams to coordinate pre-release regression testing and automated deployment package validation. o Evaluate release/deployment pipelines and author formal recommendations to modernize, consolidate, and streamline enterprise toolsets (e.g., transitioning and consolidating MDT to MECM).

  • Federal Security, Compliance & Governance:

o Harden all workstation builds, images, and server baselines in strict alignment with FISMA, FDCCI, NIST SP 8-series standards, and DISA STIGs. o Partner with the Identity Management Team team to author, test, and scan workstation Group Policy Objects (GPOs) and security baselines. o Coordinate with agency security teams on monthly vulnerability scans, golden image validation, and next-generation endpoint antivirus/malware protection integrations. o Enforce software asset integrity by continuously monitoring for unapproved freeware/shareware and executing immediate (within 4 hours) remediation of unauthorized software.

Tier 3 Escalation, Re-Imaging & Continuous Improvement:

o Direct Tier 3 incident response for critical workstation, AVD, and imaging failures, driving definitive Root Cause Analyses (RCAs) and developing stable hotfixes/workarounds. o Provide advanced technical guidance and re-imaging assistance to Deskside support teams. o Author and publish standardized Knowledge Base Articles (KBAs) and standard operating procedures to empower Tier 1 and Tier 2 Service Desk staff. o Log all Tier 3 ticket resolutions in the agency ITSM system within required contractual SLAs.

Other Responsibilities

  • Deliver monthly updates to Gold Image with 100% coordination.

  • Maintain greater than 95% timely completion on all enterprise workstations and MS server patching cycles.

  • Complete manual image updates within 72 hours of formal request.

  • Deliver the Weekly Tier 3 RCA & Findings Summary

  • Update the formal Image Change Log within 7 days of any version release.

  • Generate monthly reports tracking unauthorized software discoveries and removals.

Requirements

  • Education & Experience: Bachelor’s degree in IT, Computer Science, or related engineering discipline (or equivalent experience) plus 8+ years of progressive systems engineering

experience, with at least 3+ years leading enterprise desktop/workstation operations in a federal or regulated environment.

  • Core Tooling: Expert-level mastery of MECM / SCCM and MDT (Microsoft Deployment Toolkit)

for zero-touch OS imaging, task sequences, driver injection, and software packaging.

  • Virtualization & Cloud: Demonstrated experience deploying, scaling, and managing Azure Virtual Desktop (AVD) and integrating cloud-native services (Microsoft 365, Azure Intune).

  • Scripting & Automation: Advanced PowerShell proficiency for configuration scripts, task sequences, GPO automation, and silent package distribution.

  • Federal Baselines: Direct hands-on experience applying and auditing DISA STIGs, CIS benchmarks, and NIST 800-53 controls to Windows client/server operating systems., * Experience leading toolset consolidation efforts (e.g., migrating legacy MECM/MDT pipelines to modern unified cloud management like Microsoft Intune).

  • Working knowledge of ITIL v3/v4 frameworks (Change, Release, and Incident Management).

  • Familiarity with Apple macOS enterprise management (Intune).

  • Certifications:

o Microsoft Certified: Endpoint Administrator Associate (MD-102) o Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140) o CompTIA Security+ CE or CISSP

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

3:24 min

Transitioning static data fetching to real-time live queries

Noam Honig · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann Chris Heilmann +1 · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all