Desktop Engineering Lead.
Desktop Engineering Lead
Lead is responsible for architecting, securing, and maintaining the organization's endpoint infrastructure (desktops, laptops, and mobile devices). They lead a team of engineers, oversee device lifecycles, and drive modern IT automation.
Responsibilities
Administer endpoint management platforms including Microsoft Intune and related configuration management tools to enforce patch compliance, device encryption, application deployment standards, and endpoint security configurations consistent with industry cybersecurity control frameworks
Oversee enterprise patch management cycles for endpoints, ensuring timely vulnerability remediation, documentation within ITSM change workflows, and validation of successful deployment prior to closure
- Coordinate with Identity, Credential, and Access Management (ICAM) leadership to ensure workstation authentication controls, MFA enforcement, certificate deployment, and conditional access configurations are functioning properly within Microsoft Entra ID and Microsoft 365 integrations
- Validate endpoint log forwarding and monitoring integration with enterprise monitoring platforms to ensure visibility into device health, configuration compliance, and potential security anomalies
- Produce and maintain workstation engineering documentation including gold image standards, configuration baselines, lifecycle refresh schedules, and compliance dashboards
- Support root cause analysis for enterprise-wide endpoint incidents, configuration conflicts, or patch deployment failures and implement corrective actions to prevent recurrence
- Participate in Change Advisory Board (CAB) reviews to assess risk and approve major workstation environment changes prior to deployment
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Computer Engineering, or equivalent experience.
- 7-9 years of IT support experience, with at least 1–2 years in a supervisory role.
- Complies with all policies and standards.
- Maintain appropriate level government security clearance.
- Experience engineering enterprise Windows desktop environments and secure configuration baselines
Preferred Qualifications:
- Knowledge of endpoint management platforms including Intune or similar device management tools
- Familiarity with endpoint encryption, Defender security controls, and compliance reporting
- Experience integrating workstation logs with SIEM platforms
- Knowledge of lifecycle refresh planning and endpoint inventory management
- Preferred Certifications: Microsoft Certified: Endpoint Administrator Associate; CompTIA Security+