Desktop Engineering Lead
Listed on 2026-07-22
-
IT/Tech
Cybersecurity
Desktop Engineering Lead
Lead is responsible for architecting, securing, and maintaining the organization's endpoint infrastructure (desktops, laptops, and mobile devices). They lead a team of engineers, oversee device life cycles, and drive modern IT automation.
Responsibilities- Administer endpoint management platforms including Microsoft Intune and related configuration management tools to enforce patch compliance, device encryption, application deployment standards, and endpoint security configurations consistent with industry cybersecurity control frameworks.
- Oversee enterprise patch management cycles for endpoints, ensuring timely vulnerability remediation, documentation within ITSM change workflows, and validation of successful deployment prior to closure.
- Coordinate with Identity, Credential, and Access Management (ICAM) leadership to ensure workstation authentication controls, MFA enforcement, certificate deployment, and conditional access configurations are functioning properly within Microsoft Entra Microsoft 365 integrations.
- Validate endpoint log forwarding and monitoring integration with enterprise monitoring platforms to ensure visibility into device health, configuration compliance, and potential security anomalies.
- Produce and maintain workstation engineering documentation including gold image standards, configuration baselines, lifecycle refresh schedules, and compliance dashboards.
- Support root cause analysis for enterprise-wide endpoint incidents, configuration conflicts, or patch deployment failures and implement corrective actions to prevent recurrence.
- Participate in Change Advisory Board (CAB) reviews to assess risk and approve major workstation environment changes prior to deployment.
- Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience.
- 7-9 years of IT support experience, with at least 1-2 years in a supervisory role.
- Compliance with all policies and standards.
- Maintain appropriate level government security clearance.
- Experience engineering enterprise Windows desktop environments and secure configuration baselines.
- Knowledge of endpoint management platforms including Intune or similar device management tools.
- Familiarity with endpoint encryption, Defender security controls, and compliance reporting.
- Experience integrating workstation logs with SIEM platforms.
- Knowledge of lifecycle refresh planning and endpoint inventory management.
- Preferred
Certifications:
Microsoft Certified:
Endpoint Administrator Associate;
CompTIA Security+.
- Highly competitive Medical, Dental, and Vision options including HSA options with company provided seed.
- Short- & Long-Term Disability (company paid).
- Life Insurance Non-Contributory 1X salary (company paid).
- AD&D Non-contributory 1x salary (company paid).
- Savings & Investment plan:
- Qualified Non-Elective Company Contribution of 5% each pay period with immediate vesting.
- Company match 50 cents/dollar up to 8% (5 years vesting in company match).
- Contributory Life Insurance up to 5x Salary with $1M Cap.
- Contributory AD&D (employee, spouse and children).
- Paid Time Off.
- Employee Assistance Plan.
- SRNL offers a competitive relocation package to ease the transition process. Domestic and international relocation assistance is available for certain positions.
BSRA is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status. BSRA is also committed to making our workplace accessible to individuals with disabilities and will provide reasonable accommodations, upon request, for individuals to participate in the application and hiring process. Please email us with any questions regarding the hiring process or to request an accommodation.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).