About The Position

We are looking for highly skilled and proactive Service Desk Engineers to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a Service Desk Engineer, you will design, implement, and maintain technical controls to reduce the risk of unauthorized initial discovery and lateral movement, malicious credential use, and persistence via machine key and related system-abuse techniques. This role focuses on engineering support for escalated and complex tickets--not routine help desk support. Multiple positions are available: Engineer, Cloud Service Desk Representative, Apple/macOS SME, and Microsoft SME.

Requirements

  • Active Top Secret (TS) security clearance is required.
  • Minimum of 8 years of experience in Information Technology, Endpoint Engineering, or Cybersecurity.
  • Minimum of 6 years of experience performing engineering (not help desk) functions in enterprise environments.
  • Experience working under formal change control, audit, and security governance processes.
  • Demonstrated hands-on experience with: Windows and macOS workstation imaging and automation
  • Demonstrated hands-on experience with: Ivanti and/or KACE for OS and application patching
  • Demonstrated hands-on experience with: Microsoft Intune and Windows Autopilot
  • Demonstrated hands-on experience with: JAMF Pro for macOS endpoint management
  • Demonstrated hands-on experience with: Endpoint logging and SIEM/EDR platforms (Microsoft Sentinel/Defender)
  • Apple/macOS SME: Expertise in JAMF Pro and macOS endpoint management.
  • Microsoft SME: Expertise in Microsoft Intune, Autopilot, and Windows endpoint management.
  • U.S. Citizenship is required

Nice To Haves

  • Experience implementing passwordless authentication and hardware-backed credentials (YubiKeys, CAC).
  • Experience supporting forensic collection and audit readiness.
  • Bachelor's degree in Information Technology, Cybersecurity, or a related field (or equivalent experience).

Responsibilities

  • Design, build, and maintain secure standard workstation images for Windows and macOS that enable access to the VDI environment for both remote and on-site users.
  • Engineer and maintain operating system and application patching, version control, and lifecycle management for supported applications using Ivanti, KACE, Microsoft Intune, and Group Policy Objects (GPO).
  • Support Microsoft Intune registration and Windows Autopilot for desktops, laptops, and CBO-issued mobile devices.
  • Implement passwordless authentication, hardware security keys (e.g., YubiKeys), and other protections for privileged and sensitive accounts.
  • Engineer and maintain logging, monitoring, and audit capabilities to track device enrollment, user authentication, network access, and endpoint activity.
  • Produce user-facing runbooks for imaging/recovery, patch-validation steps, enrollment troubleshooting, and common remediation tasks.
  • Follow a formal workflow: Assess findings, recommend remediation plans, obtain approvals, implement changes, and validate results.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service