ENDPOINT ENGINEER - CLASSIFIED ENCLAVES (SIPRNET / JWICS)

Empower AI Inc.•Quantico, VA
•$121,490 - $188,040•Onsite

About The Position

Empower AI is seeking an Endpoint Engineer - Classified Enclaves to engineer and sustain the endpoint infrastructure on the SIPRNet and JWICS enclaves of a Department of War agency. This role requires adherence to the same standards of automation, hardening, and RMF compliance as other environments, but with specific tooling, connectivity, and handling procedures for classified enclaves. The engineer will manage the classified-enclave endpoint management infrastructure (e.g., MECM/SCCM), design and validate hardened images and Group Policy baselines, execute CAT I/II/III patching within enclave constraints, support classified VDI and cross-domain considerations, and produce RMF evidence for the classified endpoint systems. This TS/SCI privileged-user role serves as the Tier III escalation point for classified endpoint incidents. This is a salaried, FLSA-exempt position requiring independent analysis, decision-making, and judgment on significant matters.

Requirements

  • Bachelor's degree and a minimum of 10 years of related experience (a Master's degree with 8 years of related experience, or an additional 4 years of related experience in lieu of a degree, may be substituted).
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level III baseline certification (e.g., CASP+ CE, CISSP or Associate, CCNP Security, GCED, or GCIH).
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 10 years of experience in systems or infrastructure engineering for enterprise Windows environments, including lead-engineer responsibility for endpoint or infrastructure programs at 10,000+ device scale.
  • Expert knowledge of MECM/SCCM and/or Intune architecture, Windows Server, Active Directory, Group Policy, virtualization (VMware/Hyper-V), VDI, and PowerShell automation.
  • Demonstrated experience designing and leading implementation of lab, pre-production, or digital twin environments and formal test-before-deploy practices.
  • Experience leading proof-of-concept evaluations, market research, and cost-benefit/ROM development for Government or enterprise decision-makers.
  • Extensive experience with DISA STIGs, ACAS/Nessus, RMF control implementation, POA&Ms, and eMASS.
  • Experience leading engineering teams, establishing standards, and executing changes through formal Change Management.
  • Excellent technical writing, briefing, and stakeholder communication skills; ability to participate in after-hours emergency on-call response.
  • Experience working on siprnet and jwics enclaves and with classified media handling procedures.

Nice To Haves

  • CISSP, CASP+ CE, or GCED; Microsoft 365 Certified: Administrator Expert; VMware VCP/VCAP; AWS or Azure architect certification.
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across NIPRNet, SIPRNet, and JWICS enclaves.
  • Experience applying AI/ML, RPA, or AIOps to IT service management and endpoint operations, including ServiceNow integrations.
  • Familiarity with DoD Zero Trust Strategy and Reference Architecture, DoDAF 2.02, DoD ICAM Strategy, and Technology Business Management (TBM).
  • ITIL 4 Foundation or Managing Professional; PMP.
  • Experience supporting IT Capability Request (ITCR) analysis and governance briefings.

Responsibilities

  • Engineer, operate, and maintain the SIPRNet and JWICS endpoint management infrastructure (MECM/SCCM, imaging, provisioning, Group Policy) in accordance with enclave-specific security, transfer, and handling procedures.
  • Plan and execute CAT I/II/III patch and software deployments on the classified enclaves within PRS timeframes, managing media transfer and disconnected/air-gapped update workflows where required.
  • Engineer and validate hardened images and configuration baselines for classified endpoints against DISA STIGs and enclave authority requirements, and provide RMF control evidence and POA&M inputs in eMASS for the classified endpoint systems.
  • Serve as the Tier III escalation point for classified-enclave endpoint incidents and coordinate with the enclave network, cybersecurity, and communications teams.
  • Lead the engineering design, implementation, and lifecycle of the enterprise endpoint infrastructure: hardened image pipelines, automated provisioning, endpoint management platform architecture (MECM/SCCM, Intune), configuration baselines, and VDI integration across all enclaves.
  • Lead the evaluation, cost-benefit analysis, and phased implementation of the Digital Twin capability for network and system modeling; author the Digital Twin Evaluation and Implementation Plan; and establish the practice that every significant change is tested in the digital replica before deployment.
  • Lead engineering for AI, automation, and analytics initiatives approved by the Government, including predictive analytics on service data, intelligent automation across support tiers, and integrations with the ITSM platform, and deliver Proof of Concept Reports documenting feasibility, risks, and benefits.
  • Conduct market research and produce Market Research Reports and Rough Orders of Magnitude (ROMs) for emerging technologies and proposed solutions to support Government planning and IT Capability Request analysis.

Benefits

  • 401k
  • health insurance
  • dental insurance
  • vision insurance
  • disability insurance
  • life insurance
  • paid holidays
  • professional development
  • continued education
  • learning development program
  • employee discount programs
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service