The Desktop Engineer III provides enhanced Level 3 (Tier 3) desktop engineering support to HRSA's Division of Enterprise User Support (DEUS), sustaining and improving HRSA's desktop environment, automation processes, and workstation infrastructure across all HRSA offices and facilities. This role supports critical operations and project deliverables during periods of fluctuating workload driven by new systems, special initiatives, or geographic expansion, and operates under the direction of OIT/DEUS leadership in close coordination with federal desktop engineering staff.
Key Responsibilities
- Provide Tier 3 troubleshooting and resolution for hardware and software incidents escalated from Tier 1 and Tier 2 support.
- Interface with federal desktop engineering staff and other OIT divisions to resolve complex or cross-system issues.
Training & Documentation
- Train new Desktop Support technicians on HRSA systems, tools, and procedures.
- Collaborate with the Knowledge Management Team to develop training materials and deliver instruction to technicians, DEUS staff, and end users.
- Create and maintain ServiceNow Knowledge Base articles on advanced troubleshooting and configuration standards.
- Develop and maintain technical documentation for engineered solutions, imaging processes, and software deployment standards.
Software Deployments
- Support enterprise software deployments using Tanium Endpoint Management or other HRSA-approved tools.
- Develop automated installation packages and uninstall routines, with full documentation.
- Test packages per the established testing SOP and verify successful operation.
- Plan and execute deployment activities (communications, lab/Phase 1/Phase 2 testing, user notification) per HRSA change management policy.
- Troubleshoot deployment failures and report progress to DEUS leadership.
Workstation Configuration & Automation
- Develop and automate workstation configuration changes using Tanium, Microsoft Intune, or Active Directory GPOs.
- Document automated updates, rollback procedures, and testing results.
- Implement and validate changes per approved Technical Implementation Plans (TIPs).
Imaging & Build Management
- Maintain and enhance HRSA's workstation imaging process using Tanium or other approved platforms.
- Update base images at least quarterly for current drivers, BIOS, and baseline configurations.
- Validate and test new workstation models added to HRSA inventory.
- Develop and publish image release notes summarizing updates and changes.
Group Policy Management
- Support federal desktop engineers in creating, modifying, and testing GPOs within Quest GPOAdmin or Intune.
- Follow established SOPs for GPO creation, testing, and deployment.
- Prepare documentation, TIPs, and Change Approval Board (CAB) submissions.
- Provide Tier 3 support for ~130 networked printers and multifunction devices (MFDs).
- Maintain print servers, print queues, and managed print systems (e.g., Netaphor SiteAudit).
- Troubleshoot escalated incidents, coordinate vendor repairs, and recommend improvements.
- Ensure consistent operation of Follow Me Print and Scan to Email systems, including documentation and upgrades.
Security Engineering
- Identify and assess workstation security vulnerabilities using Tenable, Tanium, or equivalent tools.
- Review vendor patch releases and recommend remediation or configuration strategies.
- Develop and maintain workstation and application security baselines aligned with CIS Benchmarks.
Systems Management Automation
- Identify opportunities for process automation in desktop management operations (e.g., PowerShell, Tanium tasks).
- Propose, design, and implement automation solutions upon OIT/DEUS leadership approval.
- Document and test all automation scripts and procedures prior to implementation.
- Provide weekly or monthly engineering activity summaries for the DEUS Weekly Presentation and other standard reporting.
- Contribute a dedicated section to the DEUS Weekly Presentation summarizing Level 3 Desktop Engineering activities.
- Maintain detailed documentation of software packages, configuration changes, GPO updates, and automation scripts.
- Submit Technical Implementation Plans (TIPs), test results, and deployment reports for each engineering activity.
- Provide quarterly updates summarizing system improvements, image revisions, and automation accomplishments.
Minimum Qualifications
- Demonstrated experience performing desktop engineering or endpoint management in an enterprise environment supporting 2,000+ users.
- Expertise with Tanium Endpoint Management, Microsoft Intune, Active Directory Group Policy, and Windows 10/11 administration.
- Experience creating and testing software deployment packages and GPOs following change control procedures.
- Proficiency with PowerShell scripting, automation, and configuration compliance enforcement.
- Understanding of CIS Benchmark standards and federal information security controls.
Preferred Certifications