Junior Endpoint Engineer

TIAG•Bethesda, MD
•$70,000 - $85,000•Hybrid

About The Position

TIAG is hiring a Junior Endpoint Engineer to support a major cybersecurity modernization effort for the Uniformed Services University (USU). This role reports onsite in a Hybrid capacity at the customer location in Bethesda, MD. This position requires a Secret level clearance to be processed in order to begin work, so US or Naturalized Citizenship is a requirement. In this role, the candidate will assist the Lead Security Architect and senior engineers in migrating approximately 3,000 heterogeneous endpoints (Windows, macOS, and Linux) from a legacy Trellix environment to Microsoft Defender for Endpoint (MDE).

Requirements

  • Active DoD Secret clearance.
  • 1–3 years of hands-on experience in IT support, systems administration, or endpoint management.
  • Familiarity with enterprise deployment tools such as MECM/SCCM.
  • Basic administrative knowledge across multiple operating systems, including Windows, macOS, and Linux.
  • Understanding of disk encryption tools like BitLocker and FileVault.
  • DoD 8570.01-M Information Assurance Management (IAM) Level I or Information Assurance Technical (IAT) Level II certification (e.g., CompTIA Security+ CE).
  • Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) or foundational Microsoft certifications (e.g., SC-900).
  • CompTIA A+, Network+, or basic OS-specific certifications (Windows/macOS).

Responsibilities

  • Assist in executing high-velocity rollouts of the MDE agent to Windows, macOS, and Linux systems using Microsoft Endpoint Configuration Manager (MECM/SCCM) and automated deployment scripts.
  • Monitor the Microsoft Defender portal during deployment waves to verify that endpoints are establishing active, error-free telemetry reporting.
  • Track failed deployments and retry statuses.
  • Assist in systematically uninstalling legacy Trellix agents across all supported operating systems once MDE telemetry is verified.
  • Support the transition of disk encryption management from Trellix to native OS tools, specifically BitLocker for Windows and FileVault for macOS.
  • Help verify that all native encryption recovery keys are successfully escrowed and protected within Entra ID to prevent any loss of access.
  • Support manual reviews and compliance checks to ensure applied DISA Security Technical Implementation Guides (STIGs) are correctly functioning at the agent level.
  • Document device-specific blockers and agent conflicts that require further troubleshooting by senior engineers or Government IT staff.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service