
Service Desk Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Washington.
• Develop, construct, sustain, and secure standardized workstation images for both Windows and macOS to facilitate on-site, remote, and VDI access.
• Design endpoint baselines and technical controls aimed at minimizing the risks of unauthorized discovery, lateral movement, misuse of credentials, persistence, and evasion of defense mechanisms.
• Take ownership of the engineering design and lifecycle maintenance for imaging, patching, automation, validation, rollback, and release management.
• Oversee OS and application patching, version control, and deployment workflows utilizing approved enterprise tools such as Ivanti, KACE, Intune, GPO, JAMF, or similar.
• Engineer and manage logging, telemetry, monitoring, and auditing capabilities to monitor endpoint activities, enrollment, user authentication, network access, and compliance status.
• Create and implement validation testing following imaging or significant patch cycles to ensure endpoint functionality, security agent integrity, authentication, and VDI connectivity.
• Assist in the evaluation, recommendation, implementation, and validation processes by generating Findings Reports, Remediation Plans, Validation Reports, and change documentation.
• Develop and maintain runbooks, technical standards, deployment processes, rollback methods, and engineering documentation for Service Desk and IRM teams.
• Provide support for engineering escalations that arise from complex incidents related to Endpoint, imaging, patching, telemetry, and device management.
• A Bachelor’s degree in IT, Cybersecurity, or a related field is preferred; equivalent experience is acceptable.
• An active or interim Top Secret security clearance is required.
• A minimum of 8 years of experience in IT, Endpoint Engineering, or Cybersecurity.
• At least 6 years of experience performing engineering functions within enterprise environments.
• Proficient in working under formal change control, audit, and security governance processes.
• Experience in creating and maintaining Windows and macOS workstation images.
• Familiarity with image automation, image validation, rollback procedures, and version control.
• Experience integrating workstation images with VDI, EDR, authentication mechanisms, and logging agents.
• Skilled in maintaining imaging toolchains and automation scripts using Ivanti, KACE, JAMF, or equivalent tools.
• Knowledge of formal image-release processes, including build, testing, signoff, and release.
• Practical experience with Ivanti and/or KACE for OS and application patching.
• Experience handling configuration drift, remediation workflows, deployment failures, and rollback procedures.
• Proficient in validating patches post-deployment and providing support for rollback/recovery.
• Experience coordinating Intune/GPO-based patch orchestration for Windows endpoints.
• Skilled in configuring Windows Event Logs, macOS Unified Logs, application logs, and endpoint logging agents.
• Familiarity with forwarding and validating logs to SIEM/EDR platforms such as Microsoft Sentinel or equivalent.
• Experience implementing monitoring for patch status, enrollment status, image deployment status, and compliance posture.
• Support experience for forensic collection, artifact preservation, and audit readiness.
• Health insurance
• Retirement plans
• Paid time off
• Flexible work arrangements
Dr. Födisch Umweltmesstechnik AG
QuidelOrtho
Siemens Healthineers
Get handpicked remote jobs straight to your inbox weekly.