End-User Computing (EUC) Engineer

Koniag Government Services, LLCWashington, DC
$100,000 - $113,500Onsite

About The Position

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking an End-User Computing (EUC) Engineer to support Koniag IT Systems and its government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. The End-User Computing (EUC) Engineer provides advanced engineering support for SBA's enterprise end-user computing environment, focusing on the design, engineering, automation, and sustainment of endpoint platforms, device management infrastructure, and end-user computing technologies. This role is distinguished from the Desktop / Field Support Technician by its focus on engineering, architecture, and platform-level work rather than individual incident resolution. The EUC Engineer designs and builds endpoint platforms, automation workflows, deployment pipelines, and configuration frameworks that enable the broader end-user services team to deliver consistent, high-quality support at scale. This individual must be capable of operating autonomously on complex engineering tasks, demonstrating deep expertise in Microsoft endpoint management, device lifecycle engineering, and end-user computing automation in a Federal enterprise environment.

Requirements

  • Minimum 4–6 years of hands-on enterprise end-user computing engineering experience
  • Demonstrated experience engineering and administering Microsoft Intune and endpoint management platforms at enterprise scale
  • Proven experience with Windows Autopilot, endpoint imaging, and automated deployment workflows
  • Experience developing PowerShell scripts and automation for endpoint management and administration
  • Experience in a Federal or private-sector enterprise environment of comparable scale, complexity, and security posture
  • Demonstrated experience with endpoint security engineering, including Microsoft Defender for Endpoint and endpoint hardening
  • Experience implementing Zero Trust Architecture principles across enterprise endpoint environments
  • Familiarity with NIST SP 800-53 and CIS benchmark controls as applied to endpoint platforms
  • Expert-level proficiency in: Microsoft Endpoint Manager (Intune) engineering, policy design, and automation
  • Expert-level proficiency in: Windows 10/11 platform engineering and configuration management
  • Expert-level proficiency in: Windows Autopilot and zero-touch deployment workflows
  • Expert-level proficiency in: PowerShell scripting for endpoint management and automation
  • Expert-level proficiency in: Microsoft Defender for Endpoint configuration and policy management
  • Expert-level proficiency in: Group Policy Objects (GPOs) and Intune configuration profiles
  • Expert-level proficiency in: Software packaging, deployment automation, and application lifecycle management
  • Expert-level proficiency in: Endpoint compliance monitoring and remediation
  • Strong working knowledge of: Microsoft Azure Active Directory (Entra ID) and conditional access
  • Strong working knowledge of: Zero Trust Architecture and OMB M-22-09 endpoint requirements
  • Strong working knowledge of: NIST SP 800-53 and CIS benchmark controls for endpoints
  • Strong working knowledge of: Azure Virtual Desktop or Windows Virtual Desktop
  • Strong working knowledge of: Microsoft Purview DLP and information protection
  • Strong working knowledge of: ITSM platforms (e.g., ServiceNow)
  • Strong working knowledge of: ITIL 4 change and incident management practices
  • Strong working knowledge of: Enterprise network fundamentals relevant to endpoint management
  • Microsoft Certified: Modern Desktop Administrator Associate (MD-102) (required)
  • Microsoft Certified: Azure Administrator Associate (AZ-104) (required)
  • CompTIA Security+ (required)

Nice To Haves

  • Microsoft Certified: Endpoint Administrator Expert
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CompTIA Network+
  • ITIL 4 Foundation

Responsibilities

  • Lead engineering design, build, and optimization of SBA's enterprise endpoint computing platforms, including Windows 10/11 workstations, laptops, and mobile devices
  • Develop and maintain endpoint configuration baselines, hardening standards, and compliance frameworks aligned with NIST SP 800-53, CIS benchmarks, and SBA cybersecurity requirements
  • Engineer and maintain Microsoft Intune policies, configuration profiles, compliance baselines, and application deployment packages for SBA's endpoint fleet
  • Design and implement Windows Autopilot deployment workflows for zero-touch device provisioning and refresh
  • Lead endpoint platform testing, validation, and quality assurance for configuration changes and new deployments
  • Evaluate emerging endpoint technologies and recommend solutions aligned with SBA's enterprise environment and security requirements
  • Support development and maintenance of the endpoint engineering roadmap in coordination with the End-User Services Lead and Microsoft Infrastructure team
  • Engineer and maintain automated device management workflows using Microsoft Intune, PowerShell, and related tooling
  • Develop and maintain software packaging, deployment automation, and application lifecycle management processes
  • Design and implement automated patch management and software update workflows for Windows endpoints
  • Build and maintain automation scripts and tools that reduce manual effort and improve consistency across end-user computing operations
  • Engineer self-healing and remediation automation workflows that proactively address common endpoint issues without requiring manual intervention
  • Support development and maintenance of endpoint monitoring and alerting configurations in coordination with the NOC and Infrastructure teams
  • Develop and maintain endpoint configuration management documentation, baselines, and change records
  • Engineer and maintain Group Policy Objects (GPOs) and Intune configuration profiles that enforce SBA security and compliance standards
  • Support endpoint compliance monitoring and reporting, providing actionable data to the End-User Services Lead and Service Management team
  • Lead remediation of endpoint compliance findings identified through security assessments, audits, and continuous monitoring
  • Coordinate with the Microsoft Infrastructure Administrator (Senior) on endpoint security policy alignment and enforcement
  • Maintain accurate and current endpoint configuration documentation in the Government ITSM platform and knowledge base
  • Engineer and maintain Virtual Desktop Infrastructure (VDI) or Windows Virtual Desktop (Azure Virtual Desktop) environments as applicable to SBA's environment
  • Support engineering and administration of enterprise software distribution platforms and application virtualization solutions
  • Maintain and optimize endpoint imaging and deployment infrastructure, including task sequences, driver libraries, and OS deployment workflows
  • Engineer and maintain mobile device management (MDM) configurations for SBA-issued smartphones and tablets
  • Support integration of end-user computing platforms with Microsoft Entra identity, conditional access, and Zero Trust Architecture frameworks
  • Coordinate with the Network Engineer T4 team on network requirements for endpoint management infrastructure
  • Engineer endpoint security configurations aligned with Zero Trust Architecture principles (NIST SP 800-207, OMB M-22-09)
  • Design and implement Microsoft Defender for Endpoint configurations, policies, and automated response workflows
  • Support implementation of application control, device guard, and credential guard technologies across SBA's endpoint fleet
  • Engineer and maintain endpoint data loss prevention (DLP) configurations in coordination with the Microsoft Infrastructure team and Purview compliance solutions
  • Conduct endpoint security engineering reviews and provide recommendations for improving SBA's endpoint security posture
  • Support incident response activities involving endpoint security events in coordination with the NOC and Microsoft Infrastructure teams
  • Maintain comprehensive and current documentation of all endpoint platform configurations, engineering decisions, and operational procedures
  • Develop and maintain technical runbooks, engineering standards, and knowledge base articles for EUC engineering operations
  • Ensure all EUC engineering change activities are documented in the Government ITSM platform in accordance with ITIL 4 change management practices
  • Provide technical knowledge transfer to desktop support technicians and Service Desk staff on endpoint platform topics
  • Support transition-in and transition-out activities by providing complete and accurate EUC engineering documentation
  • Ensure all EUC engineering activities comply with FISMA, NIST SP 800-53, FedRAMP, and SBA cybersecurity policies
  • Apply least-privilege and separation-of-duties principles to all endpoint management configurations and access controls
  • Adhere to all SBA policies regarding handling of CUI, SBU, and FOUO information
  • Promptly report suspected or confirmed security incidents involving endpoint platforms per SBA procedures
  • Support FISMA assessment and authorization activities for endpoint-related systems and platforms

Benefits

  • health, dental and vision insurance
  • 401K with company matching
  • flexible spending accounts
  • paid holidays
  • three weeks paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service