Senior Lead Workstation and Systems Engineering

Innovative Computer Solutions Group, Inc

Rockville (MD)

Hybrid

USD 120,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible work from home

Job summary

Innovative Computer Solutions Group, Inc. is seeking a Senior Lead, Workstation & Systems Engineering to design, test, and deploy enterprise workstation images and patch management across on-prem, virtual, and cloud environments, including Azure Virtual Desktop.

You will lead image engineering via MECM/MDT and drive a unified configuration management strategy. You will harden builds to DISA STIGs and NIST baselines, coordinate with cross-functional teams for testing, and serve as the Tier 3

Qualifications

  • Bachelor's degree in IT, Computer Science, or related engineering discipline (or equivalent experience) with 8+ years in progressive systems engineering.
  • 8+ years in enterprise systems engineering, with 3+ years leading desktop/workstation operations in regulated environments.
  • Expert-level MECM/SCCM and MDT for zero-touch imaging and packaging.
  • Experience deploying Azure Virtual Desktop and integrating cloud services.
  • Advanced PowerShell for configuration scripts and automation.
  • Hands-on experience applying DISA STIGs, NIST 800-53 controls.

Responsibilities

  • Design, test, and maintain Gold/Base Image and image libraries across physical and virtual endpoints and Azure Virtual Desktop.
  • Build and version image variants through Change Control Board (CCB).
  • Maintain firmware, BIOS baselines, and driver packs.
  • Plan, test, and deploy monthly and out-of-band patches and software deployments.
  • Collaborate with multiple teams for regression testing and validation of deployment packages.
  • Harden workstation builds to meet federal baselines (FISMA, NIST, DISA STIGs).
  • Lead Tier 3 escalation for imaging failures and provide strong RCA and hotfixes.

Skills

PowerShell
Desktop engineering
Federal compliance

Education

Bachelor's degree in IT/CS or related engineering discipline

Tools

MECM / SCCM
MDT
Azure Virtual Desktop (AVD)
Microsoft Intune
GPO automation

Job description

Position Overview

Please Note -- this is a hybrid position. Candidate must be local to the area.

The Senior Lead, Workstation & Systems Engineering serves as the principal technical authority and task lead responsible for the design, testing, lifecycle maintenance, security, and deployment of enterprise workstation images and patch management across NRC physical, virtual, and cloud environments (including Azure Virtual Desktop).

This role directs image engineering via MECM and MDT, leads the transition toward a unified configuration management toolset, oversees the Enterprise Development and Testing Environment, and ensures strict compliance with federal baselines (DISA STIGs, NIST, FISMA, FDCCI). The Lead also acts as the top-tier escalation authority for Tier 3 troubleshooting and root cause analysis.

Key Responsibilities
Master Image Architecture & Management:
  • Engineer, test, and maintain the hardware-independent Gold/Base Image and full image library across physical endpoints, virtual instances, and Azure Virtual Desktop (AVD) platforms.
  • Build, maintain, and version specialized image variants through the Change Control Board (CCB), including Apple macOS workstations, International/Domestic Loaners, International Assignees, Public Document Room kiosks, and office-specific configurations.
  • Maintain and update hardware firmware, BIOS baselines, and certified driver packs across all deployed enterprise endpoints.
  • Provide multi-channel image distribution flexibility across network distribution servers, secure cloud storage, and offline media (USB).
Patch, Release & Deployment Engineering:
  • Plan, package, test, and execute monthly and out-of-band security updates, OS patches, and third-party software deployments across all workstations and Microsoft servers.
  • Maintain, validate, and conduct pre-deployment testing within the Enterprise Development and Testing Environment to guarantee environment congruency between Dev, Test, Pre-Production, and Production.
  • Collaborate with Application Owners, System Administrators, Network & Security Engineering, and Compute & Storage teams to coordinate pre-release regression testing and automated deployment package validation.
  • Evaluate release/deployment pipelines and author formal recommendations to modernize, consolidate, and streamline enterprise toolsets (e.g., transitioning and consolidating MDT to MECM).
Federal Security, Compliance & Governance:
  • Harden all workstation builds, images, and server baselines in strict alignment with FISMA, FDCCI, NIST SP 800-53 series standards, and DISA STIGs.
  • Partner with the Identity Management Team team to author, test, and scan workstation Group Policy Objects (GPOs) and security baselines.
  • Coordinate with agency security teams on monthly vulnerability scans, golden image validation, and next-generation endpoint antivirus/malware protection integrations.
  • Enforce software asset integrity by continuously monitoring for unapproved freeware/shareware and executing immediate (within 4 hours) remediation of unauthorized software.
Tier 3 Escalation, Re-Imaging & Continuous Improvement:
  • Direct Tier 3 incident response for critical workstation, AVD, and imaging failures, driving definitive Root Cause Analyses (RCAs) and developing stable hotfixes/workarounds.
  • Provide advanced technical guidance and re-imaging assistance to Deskside support teams.
  • Author and publish standardized Knowledge Base Articles (KBAs) and standard operating procedures to empower Tier 1 and Tier 2 Service Desk staff.
  • Log all Tier 3 ticket resolutions in the agency ITSM system within required contractual SLAs.
Other Responsibilities
  • Deliver monthly updates to Gold Image with 100% coordination.
  • Maintain greater than 95% timely completion on all enterprise workstations and MS server patching cycles.
  • Complete manual image updates within ≤ 72 hours of formal request.
  • Deliver the Weekly Tier 3 RCA & Findings Summary
  • Update the formal Image Change Log within 7 days of any version release.
  • Generate monthly reports tracking unauthorized software discoveries and removals.
  • .
Required Qualifications
  • Education & Experience: Bachelor's degree in IT, Computer Science, or related engineering discipline (or equivalent experience) plus 8+ years of progressive systems engineering experience, with at least 3+ years leading enterprise desktop/workstation operations in a federal or regulated environment.
  • Core Tooling: Expert-level mastery of MECM / SCCM and MDT (Microsoft Deployment Toolkit) for zero-touch OS imaging, task sequences, driver injection, and software packaging.
  • Virtualization & Cloud: Demonstrated experience deploying, scaling, and managing Azure Virtual Desktop (AVD) and integrating cloud-native services (Microsoft 365, Azure Intune).
  • Scripting & Automation: Advanced PowerShell proficiency for configuration scripts, task sequences, GPO automation, and silent package distribution.
  • Federal Baselines: Direct hands-on experience applying and auditing DISA STIGs, CIS benchmarks, and NIST 800-53 controls to Windows client/server operating systems.
Preferred Qualifications
  • Experience leading toolset consolidation efforts (e.g., migrating legacy MECM/MDT pipelines to modern unified cloud management like Microsoft Intune).
  • Working knowledge of ITIL v3/v4 frameworks (Change, Release, and Incident Management).
  • Familiarity with Apple macOS enterprise management (Intune).
Certifications:
  • Microsoft Certified: Endpoint Administrator Associate (MD-102)
  • Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140)
  • CompTIA Security+ CE or CISSP

Flexible work from home options available.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Lead: Enterprise Workstation & Cloud Imaging
Senior Lead: Enterprise Workstation & Cloud Imaging

Innovative Computer Solutions Group, Inc • Rockville (MD)

Hybrid
USD 120,000 - 150,000
Flexible work from home
Lead Windows Administrator
Lead Windows Administrator

Varmoda Tech • Washington

On-site
USD 85,000 - 110,000
Desktop Engineer III — Enhanced Desktop Engineering Support
Desktop Engineer III — Enhanced Desktop Engineering Support

NeevSys Inc • Gaithersburg (MD)

On-site
USD 85,000 - 120,000
Windows Engineer/SME
Windows Engineer/SME

Spectraforce Technologies • Oakland (CA)

Hybrid
USD 140,000 - 180,000
Deskside Support Lead
Deskside Support Lead

Saic • Ashburn (VA)

On-site
USD 40,000 - 80,000
Senior Endpoint Engineer
Senior Endpoint Engineer

ZENITH INFOTEK LLC • North Carolina

Hybrid
USD 120,000 - 170,000
Desktop/Workstation Design Engineer
Desktop/Workstation Design Engineer

Cgsfederal • Chantilly (VA)

On-site
USD 95,000 - 135,000
Health
Dental
Vision
+4
Senior Desktop Infrastructure Engineer
Senior Desktop Infrastructure Engineer

RK Management Consultants, Inc. • Chicago (IL)

On-site
USD 110,000 - 170,000
System Engineer (TS/SCI)- Senior or Mid Level
System Engineer (TS/SCI)- Senior or Mid Level

Vexterra Group • Bethesda (MD)

On-site
USD 90,000 - 120,000
Desktop Engineer
Desktop Engineer

Vaco Recruiter Services • Jacksonville (FL)

On-site
USD 90,000 - 130,000