Skip to content

Open nowPosted 42 days ago

End-User Computing (EUC) Engineer

kgs401 open roles

Where
Washington, DC, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowEnd-User Computing (EUC) Engineerkgs · Washington, DC, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on kgs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 42 days ago

The posting

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking an End-User Computing (EUC) Engineer to support KITS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.   Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement. The End-User Computing (EUC) Engineer provides advanced engineering support for SBA's enterprise end-user computing environment, focusing on the design, engineering, automation, and sustainment of endpoint platforms, device management infrastructure, and end-user computing technologies.   This role is distinguished from the Desktop / Field Support Technician by its focus on engineering, architecture, and platform-level work rather than individual incident resolution. The EUC Engineer designs and builds endpoint platforms, automation workflows, deployment pipelines, and configuration frameworks that enable the broader end-user services team to deliver consistent, high-quality support at scale.   This individual must be capable of operating autonomously on complex engineering tasks, demonstrating deep expertise in Microsoft endpoint management, device lifecycle engineering, and end-user computing automation in a Federal enterprise environment.   Key Responsibilities: Endpoint Platform Engineering:

Lead engineering design, build, and optimization of SBA's enterprise endpoint computing platforms, including Windows 10/11 workstations, laptops, and mobile devices Develop and maintain endpoint configuration baselines, hardening standards, and compliance frameworks aligned with NIST SP 800-53, CIS benchmarks, and SBA cybersecurity requirements Engineer and maintain Microsoft Intune policies, configuration profiles, compliance baselines, and application deployment packages for SBA's endpoint fleet Design and implement Windows Autopilot deployment workflows for zero-touch device provisioning and refresh Lead endpoint platform testing, validation, and quality assurance for configuration changes and new deployments Evaluate emerging endpoint technologies and recommend solutions aligned with SBA's enterprise environment and security requirements Support development and maintenance of the endpoint engineering roadmap in coordination with the End-User Services Lead and Microsoft Infrastructure team

  Device Management & Automation:

Engineer and maintain automated device management workflows using Microsoft Intune, PowerShell, and related tooling Develop and maintain software packaging, deployment automation, and application lifecycle management processes Design and implement automated patch management and software update workflows for Windows endpoints Build and maintain automation scripts and tools that reduce manual effort and improve consistency across end-user computing operations Engineer self-healing and remediation automation workflows that proactively address common endpoint issues without requiring manual intervention Support development and maintenance of endpoint monitoring and alerting configurations in coordination with the NOC and Infrastructure teams

  Configuration Management & Compliance:

Develop and maintain endpoint configuration management documentation, baselines, and change records Engineer and maintain Group Policy Objects (GPOs) and Intune configuration profiles that enforce SBA security and compliance standards Support endpoint compliance monitoring and reporting, providing actionable data to the End-User Services Lead and Service Management team Lead remediation of endpoint compliance findings identified through security assessments, audits, and continuous monitoring Coordinate with the Microsoft Infrastructure Administrator (Senior) on endpoint security policy alignment and enforcement Maintain accurate and current endpoint configuration documentation in the Government ITSM platform and knowledge base

  End-User Computing Infrastructure:

Engineer and maintain Virtual Desktop Infrastructure (VDI) or Windows Virtual Desktop (Azure Virtual Desktop) environments as applicable to SBA's environment Support engineering and administration of enterprise software distribution platforms and application virtualization solutions Maintain and optimize endpoint imaging and deployment infrastructure, including task sequences, driver libraries, and OS deployment workflows Engineer and maintain mobile device management (MDM) configurations for SBA-issued smartphones and tablets Support integration of end-user computing platforms with Microsoft Entra identity, conditional access, and Zero Trust Architecture frameworks Coordinate with the Network Engineer T4 team on network requirements for endpoint management infrastructure

  Security Engineering & Zero Trust:

Engineer endpoint security configurations aligned with Zero Trust Architecture principles (NIST SP 800-207, OMB M-22-09) Design and implement Microsoft Defender for Endpoint configurations, policies, and automated response workflows Support implementation of application control, device guard, and credential guard technologies across SBA's endpoint fleet Engineer and maintain endpoint data loss prevention (DLP) configurations in coordination with the Microsoft Infrastructure team and Purview compliance solutions Conduct endpoint security engineering reviews and provide recommendations for improving SBA's endpoint security posture Support incident response activities involving endpoint security events in coordination with the NOC and Microsoft Infrastructure teams

  Knowledge Management & Documentation:

Maintain comprehensive and current documentation of all endpoint platform configurations, engineering decisions, and operational procedures Develop and maintain technical runbooks, engineering standards, and knowledge base articles for EUC engineering operations Ensure all EUC engineering change activities are documented in the Government ITSM platform in accordance with ITIL 4 change management practices Provide technical knowledge transfer to desktop support technicians and Service Desk staff on endpoint platform topics Support transition-in and transition-out activities by providing complete and accurate EUC engineering documentation

  Security & Compliance:

Ensure all EUC engineering activities comply with FISMA, NIST SP 800-53, FedRAMP, and SBA cybersecurity policies Apply least-privilege and separation-of-duties principles to all endpoint management configurations and access controls Adhere to all SBA policies regarding handling of CUI, SBU, and FOUO information Promptly report suspected or confirmed security incidents involving endpoint platforms per SBA procedures Support FISMA assessment and authorization activities for endpoint-related systems and platforms

  Required Qualifications: Experience:

Minimum 4–6 years of hands-on enterprise end-user computing engineering experience Demonstrated experience engineering and administering Microsoft Intune and endpoint management platforms at enterprise scale Proven experience with Windows Autopilot, endpoint imaging, and automated deployment workflows Experience developing PowerShell scripts and automation for endpoint management and administration Experience in a Federal or private-sector enterprise environment of comparable scale, complexity, and security posture Demonstrated experience with endpoint security engineering, including Microsoft Defender for Endpoint and endpoint hardening Experience implementing Zero Trust Architecture principles across enterprise endpoint environments Familiarity with NIST SP 800-53 and CIS benchmark controls as applied to endpoint platforms

  Technical Expertise

Expert-level proficiency in: Microsoft Endpoint Manager (Intune) engineering, policy design, and automation Windows 10/11 platform engineering and configuration management Windows Autopilot and zero-touch deployment workflows PowerShell scripting for endpoint management and automation Microsoft Defender for Endpoint configuration and policy management Group Policy Objects (GPOs) and Intune configuration profiles Software packaging, deployment automation, and application lifecycle management Endpoint compliance monitoring and remediation Strong working knowledge of: Microsoft Azure Active Directory (Entra ID) and conditional access Zero Trust Architecture and OMB M-22-09 endpoint requirements NIST SP 800-53 and CIS benchmark controls for endpoints Azure Virtual Desktop or Windows Virtual Desktop Microsoft Purview DLP and information protection ITSM platforms (e.g., ServiceNow) ITIL 4 change and incident management practices Enterprise network fundamentals relevant to endpoint management

  Required Certifications: (Must be current and unexpired throughout performance)

Microsoft Certified: Modern Desktop Administrator Associate (MD-102) (required) Microsoft Certified: Azure Administrator Associate (AZ-104) (required) CompTIA Security+ (required) Additional preferred certifications: Microsoft Certified: Endpoint Administrator Expert Microsoft Certified: Identity and Access Administrator Associate (SC-300) Microsoft Certified: Security Operations Analyst Associate (SC-200) CompTIA Network+ ITIL 4 Foundation

  Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.   The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at [email protected] or by calling 703-488-9377 to request accommodations.   Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.   Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against kgs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on kgs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    kgs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.