Senior Lead Workstation and Systems Engineering

Innovative Computer Solutions Group, Inc

Rockville (MD)

Hybrid

USD 120,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible work from home options

Job summary

Innovative Computer Solutions Group, Inc in Rockville, MD seeks a Senior Lead for Workstation & Systems Engineering to oversee image design, patch management, and security across physical, virtual, and cloud environments including Azure Virtual Desktop.

Responsibilities include evolving from MECM/MDT to a unified cloud management approach, enforcing DISA STIGs/NIST baselines, and guiding Tier 3 incident resolution with advanced troubleshooting and RCAs.

Qualifications

  • Bachelor’s degree in IT, CS, or related field with 8+ years of progressive systems engineering experience.
  • Expert-level MECM/SCCM and MDT for zero-touch OS imaging, driver injection, and packaging.
  • Demonstrated Azure Virtual Desktop deployment, scaling, and cloud-native service integration (Intune).
  • PowerShell scripting for configuration, automation, and silent software distribution.
  • Experience applying DISA STIGs, CIS benchmarks, and NIST 800-53 controls to Windows environments.

Responsibilities

  • Design, test, and maintain enterprise workstation images across physical, virtual, and Azure Virtual Desktop environments.
  • Plan, package, test, and deploy monthly security updates and OS patches across workstations and servers.
  • Harden builds to align with FISMA, FDCCI, NIST, and DISA STIGs; coordinate with security teams on baselines and vulnerability scans.
  • Lead Tier 3 escalation, perform root-cause analyses, and publish KBAs/SOPs for IT staff.
  • Coordinate toolset modernization efforts (e.g., MECM/MDT consolidation to Intune) and ensure smooth enterprise deployments.

Skills

PowerShell
Azure Virtual Desktop
GPO automation
Security baselines
Imaging automation

Education

Bachelor’s degree in IT/CS or related field

Tools

MECM / SCCM
MDT
Azure Intune

Job description

Position Overview

Please Note -- this is a hybrid position. Candidate must be local to the area.

The Senior Lead, Workstation & Systems Engineering serves as the principal technical authority and task lead responsible for the design, testing, lifecycle maintenance, security, and deployment of enterprise workstation images and patch management across NRC physical, virtual, and cloud environments (including Azure Virtual Desktop).

This role directs image engineering via MECM and MDT, leads the transition toward a unified configuration management toolset, oversees the Enterprise Development and Testing Environment, and ensures strict compliance with federal baselines (DISA STIGs, NIST, FISMA, FDCCI). The Lead also acts as the top-tier escalation authority for Tier 3 troubleshooting and root cause analysis.

Key Responsibilities
  • Master Image Architecture & Management:
    • Engineer, test, and maintain the hardware-independent Gold/Base Image and full image library across physical endpoints, virtual instances, and Azure Virtual Desktop (AVD) platforms.
    • Build, maintain, and version specialized image variants through the Change Control Board (CCB), including Apple macOS workstations, International/Domestic Loaners, International Assignees, Public Document Room kiosks, and office-specific configurations.
    • Maintain and update hardware firmware, BIOS baselines, and certified driver packs across all deployed enterprise endpoints.
    • Provide multi-channel image distribution flexibility across network distribution servers, secure cloud storage, and offline media (USB).
  • Patch, Release & Deployment Engineering:
    • Plan, package, test, and execute monthly and out-of-band security updates, OS patches, and third-party software deployments across all workstations and Microsoft servers.
    • Maintain, validate, and conduct pre-deployment testing within the Enterprise Development and Testing Environment to guarantee environment congruency between Dev, Test, Pre-Production, and Production.
    • Collaborate with Application Owners, System Administrators, Network & Security Engineering, and Compute & Storage teams to coordinate pre-release regression testing and automated deployment package validation.
    • Evaluate release/deployment pipelines and author formal recommendations to modernize, consolidate, and streamline enterprise toolsets (e.g., transitioning and consolidating MDT to MECM).
  • Federal Security, Compliance & Governance:
    • Harden all workstation builds, images, and server baselines in strict alignment with FISMA, FDCCI, NIST SP 8---series standards, and DISA STIGs.
    • Partner with the Identity Management Team team to author, test, and scan workstation Group Policy Objects (GPOs) and security baselines.
    • Coordinate with agency security teams on monthly vulnerability scans, golden image validation, and next-generation endpoint antivirus/malware protection integrations.
    • Enforce software asset integrity by continuously monitoring for unapproved freeware/shareware and executing immediate (within 4 hours) remediation of unauthorized software.
  • Tier 3 Escalation, Re-Imaging & Continuous Improvement:
    • Direct Tier 3 incident response for critical workstation, AVD, and imaging failures, driving definitive Root Cause Analyses (RCAs) and developing stable hotfixes/workarounds.
    • Provide advanced technical guidance and re-imaging assistance to Deskside support teams.
    • Author and publish standardized Knowledge Base Articles (KBAs) and standard operating procedures to empower Tier 1 and Tier 2 Service Desk staff.
    • Log all Tier 3 ticket resolutions in the agency ITSM system within required contractual SLAs.
Other Responsibilities
  • Deliver monthly updates to Gold Image with 100% coordination.
  • Maintain greater than 95% timely completion on all enterprise workstations and MS server patching cycles.
  • Complete manual image updates within ≤ 72 hours of formal request.
  • Deliver the Weekly Tier 3 RCA & Findings Summary
  • Update the formal Image Change Log within 7 days of any version release.
  • Generate monthly reports tracking unauthorized software discoveries and removals.
Required Qualifications
  • Education & Experience: Bachelor’s degree in IT, Computer Science, or related engineering discipline (or equivalent experience) plus 8+ years of progressive systems engineering experience, with at least 3+ years leading enterprise desktop/workstation operations in a federal or regulated environment.
  • Core Tooling: Expert-level mastery of MECM / SCCM and MDT (Microsoft Deployment Toolkit) for zero-touch OS imaging, task sequences, driver injection, and software packaging.
  • Virtualization & Cloud: Demonstrated experience deploying, scaling, and managing Azure Virtual Desktop (AVD) and integrating cloud-native services (Microsoft 365, Azure Intune).
  • Scripting & Automation: Advanced PowerShell proficiency for configuration scripts, task sequences, GPO automation, and silent package distribution.
  • Federal Baselines: Direct hands-on experience applying and auditing DISA STIGs, CIS benchmarks, and NIST 800-53 controls to Windows client/server operating systems.
Preferred Qualifications
  • Experience leading toolset consolidation efforts (e.g., migrating legacy MECM/MDT pipelines to modern unified cloud management like Microsoft Intune).
  • Working knowledge of ITIL v3/v4 frameworks (Change, Release, and Incident Management).
  • Familiarity with Apple macOS enterprise management (Intune).
  • Certifications:
    • Microsoft Certified: Endpoint Administrator Associate (MD-102)
    • Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140)
    • CompTIA Security+ CE or CISSP

Flexible work from home options available.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Lead: Enterprise Workstation & Imaging (Hybrid)
Senior Lead: Enterprise Workstation & Imaging (Hybrid)

Innovative Computer Solutions Group, Inc • Rockville (MD)

Hybrid
USD 120,000 - 150,000
Flexible work from home options
Lead Windows Administrator
Lead Windows Administrator

Varmoda Tech • Washington

On-site
USD 85,000 - 110,000
Desktop Engineer III — Enhanced Desktop Engineering Support
Desktop Engineer III — Enhanced Desktop Engineering Support

NeevSys Inc • Gaithersburg (MD)

On-site
USD 85,000 - 120,000
Windows Engineer/SME
Windows Engineer/SME

Spectraforce Technologies • Oakland (CA)

Hybrid
USD 140,000 - 180,000
Release and Deployment Lead
Release and Deployment Lead

Nowges • Fort Meade (MD), Northern (KY)

Hybrid
USD 85,000 - 100,000
Systems Administrator Lead
Systems Administrator Lead

CACI • Maryland

On-site
USD 110,000 - 160,000
System Engineer (TS/SCI)- Senior or Mid Level
System Engineer (TS/SCI)- Senior or Mid Level

Vexterra Group • Bethesda (MD)

On-site
USD 90,000 - 120,000
Senior Endpoint Engineer
Senior Endpoint Engineer

ZENITH INFOTEK LLC • North Carolina

Hybrid
USD 120,000 - 170,000
Senior Desktop Infrastructure Engineer
Senior Desktop Infrastructure Engineer

RK Management Consultants, Inc. • Chicago (IL)

On-site
USD 110,000 - 170,000
Desktop/Workstation Design Engineer
Desktop/Workstation Design Engineer

Cgsfederal • Chantilly (VA)

On-site
USD 95,000 - 135,000
Health
Dental
Vision
+4