We use essential cookies

Please Accept our Privacy Policy

Senior Lead Workstation and Systems Engineering

Innovative Computer Solutions Group, Inc

Rockville, MD 20852 • $45.00 / hr • 9/24/2026

Job Description

Job Description
Position OverviewPlease Note -- this is a hybrid position. Candidate must be local to the area.

The Senior Lead, Workstation & Systems Engineering serves as the principal technical authority and task lead responsible for the design, testing, lifecycle maintenance, security, and deployment of enterprise workstation images and patch management across NRC physical, virtual, and cloud environments (including Azure Virtual Desktop).

This role directs image engineering via MECM and MDT, leads the transition toward a unified configuration management toolset, oversees the Enterprise Development and Testing Environment, and ensures strict compliance with federal baselines (DISA STIGs, NIST, FISMA, FDCCI). The Lead also acts as the top-tier escalation authority for Tier 3 troubleshooting and root cause analysis.

Key Responsibilities
· Master Image Architecture & Management:

o Engineer, test, and maintain the hardware-independent Gold/Base Image and full image library across physical endpoints, virtual instances, and Azure Virtual Desktop (AVD)
platforms.

o Build, maintain, and version specialized image variants through the Change Control Board (CCB), including Apple macOS workstations, International/Domestic Loaners,
International Assignees, Public Document Room kiosks, and office-specific configurations.

o Maintain and update hardware firmware, BIOS baselines, and certified driver packs across all deployed enterprise endpoints.

o Provide multi-channel image distribution flexibility across network distribution servers, secure cloud storage, and offline media (USB)

· Patch, Release & Deployment Engineering:
o Plan, package, test, and execute monthly and out-of-band security updates, OS patches, and third-party software deployments across all workstations and Microsoft servers.

o Maintain, validate, and conduct pre-deployment testing within the Enterprise Development and Testing Environment to guarantee environment congruency between Dev, Test, Pre-Production, and Production.

o Collaborate with Application Owners, System Administrators, Network & Security

Engineering, and Compute & Storage teams to coordinate pre-release regression testing and automated deployment package validation.

o Evaluate release/deployment pipelines and author formal recommendations to modernize, consolidate, and streamline enterprise toolsets (e.g., transitioning and consolidating MDT to MECM).

· Federal Security, Compliance & Governance:
o Harden all workstation builds, images, and server baselines in strict alignment with FISMA, FDCCI, NIST SP 8---series standards, and DISA STIGs.

o Partner with the Identity Management Team team to author, test, and scan workstation

Group Policy Objects (GPOs)
and security baselines.

o Coordinate with agency security teams on monthly vulnerability scans, golden image validation, and next-generation endpoint antivirus/malware protection integrations.

o Enforce software asset integrity by continuously monitoring for unapproved freeware/shareware and executing immediate (within 4 hours) remediation of unauthorized software.



Tier 3 Escalation, Re-Imaging & Continuous Improvement:
o Direct Tier 3 incident response for critical workstation, AVD, and imaging failures, driving definitive Root Cause Analyses (RCAs) and developing stable hotfixes/workarounds.

o Provide advanced technical guidance and re-imaging assistance to Deskside support teams.

o Author and publish standardized Knowledge Base Articles (KBAs) and standard operating procedures to empower Tier 1 and Tier 2 Service Desk staff.

o Log all Tier 3 ticket resolutions in the agency ITSM system within required contractual SLAs.

Other Responsibilities
· Deliver monthly updates to Gold Image with 100% coordination.

· Maintain greater than 95% timely completion on all enterprise workstations and MS server patching cycles.

· Complete manual image updates within 72 hours of formal request.

· Deliver the Weekly Tier 3 RCA & Findings Summary

· Update the formal Image Change Log within 7 days of any version release.

· Generate monthly reports tracking unauthorized software discoveries and removals.

.
Required Qualifications
· Education & Experience: Bachelor’s degree in IT, Computer Science, or related engineering discipline (or equivalent experience) plus 8+ years of progressive systems engineering
experience, with at least 3+ years leading enterprise desktop/workstation operations in a federal or regulated environment.

· Core Tooling: Expert-level mastery of MECM / SCCM and MDT (Microsoft Deployment Toolkit)

for zero-touch OS imaging, task sequences, driver injection, and software packaging.

· Virtualization & Cloud: Demonstrated experience deploying, scaling, and managing Azure Virtual Desktop (AVD) and integrating cloud-native services (Microsoft 365, Azure Intune).

· Scripting & Automation: Advanced PowerShell proficiency for configuration scripts, task sequences, GPO automation, and silent package distribution.

· Federal Baselines: Direct hands-on experience applying and auditing DISA STIGs, CIS benchmarks, and NIST 800-53 controls to Windows client/server operating systems.

·
Preferred Qualifications
· Experience leading toolset consolidation efforts (e.g., migrating legacy MECM/MDT pipelines to modern unified cloud management like Microsoft Intune).

· Working knowledge of ITIL v3/v4 frameworks (Change, Release, and Incident Management).

· Familiarity with Apple macOS enterprise management (Intune).
· Certifications:
o Microsoft Certified: Endpoint Administrator Associate (MD-102)

o Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140)

o CompTIA Security+ CE or CISSP


Flexible work from home options available.