Enter a job title or keyword

End-User Computing (EUC) Engineer


Job Location:

Washington, AR - USA

Monthly Salary: Not provided by the employer
Posted: 23 August 2026 (3 hours ago)
Application Deadline: 20 November 2026
Vacancies: 1 Vacancy

Job Summary

Koniag IT Systems LLC a Koniag Government Services company is seeking an End-User Computing (EUC) Engineer to support KITS and our government customer in Washington DC. This position requires the candidate to be able to obtain a Public offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and End-User Computing (EUC) Engineer provides advanced engineering support for SBAs enterprise end-user computing environment focusing on the design engineering automation and sustainment of endpoint platforms device management infrastructure and end-user computing technologies. This role is distinguished from the Desktop / Field Support Technician by its focus on engineering architecture and platform-level work rather than individual incident resolution. The EUC Engineer designs and builds endpoint platforms automation workflows deployment pipelines and configuration frameworks that enable the broader end-user services team to deliver consistent high-quality support at individual must be capable of operating autonomously on complex engineering tasks demonstrating deep expertise in Microsoft endpoint management device lifecycle engineering and end-user computing automation in a Federal enterprise Responsibilities:Endpoint Platform Engineering:Lead engineering design build and optimization of SBAs enterprise endpoint computing platforms including Windows 10/11 workstations laptops and mobile devicesDevelop and maintain endpoint configuration baselines hardening standards and compliance frameworks aligned with NIST SP 800-53 CIS benchmarks and SBA cybersecurity requirementsEngineer and maintain Microsoft Intune policies configuration profiles compliance baselines and application deployment packages for SBAs endpoint fleetDesign and implement Windows Autopilot deployment workflows for zero-touch device provisioning and refreshLead endpoint platform testing validation and quality assurance for configuration changes and new deploymentsEvaluate emerging endpoint technologies and recommend solutions aligned with SBAs enterprise environment and security requirementsSupport development and maintenance of the endpoint engineering roadmap in coordination with the End-User Services Lead and Microsoft Infrastructure teamDevice Management & Automation:Engineer and maintain automated device management workflows using Microsoft Intune PowerShell and related toolingDevelop and maintain software packaging deployment automation and application lifecycle management processesDesign and implement automated patch management and software update workflows for Windows endpointsBuild and maintain automation scripts and tools that reduce manual effort and improve consistency across end-user computing operationsEngineer self-healing and remediation automation workflows that proactively address common endpoint issues without requiring manual interventionSupport development and maintenance of endpoint monitoring and alerting configurations in coordination with the NOC and Infrastructure teamsConfiguration Management & Compliance:Develop and maintain endpoint configuration management documentation baselines and change recordsEngineer and maintain Group Policy Objects (GPOs) and Intune configuration profiles that enforce SBA security and compliance standardsSupport endpoint compliance monitoring and reporting providing actionable data to the End-User Services Lead and Service Management teamLead remediation of endpoint compliance findings identified through security assessments audits and continuous monitoringCoordinate with the Microsoft Infrastructure Administrator (Senior) on endpoint security policy alignment and enforcementMaintain accurate and current endpoint configuration documentation in the Government ITSM platform and knowledge baseEnd-User Computing Infrastructure:Engineer and maintain Virtual Desktop Infrastructure (VDI) or Windows Virtual Desktop (Azure Virtual Desktop) environments as applicable to SBAs environmentSupport engineering and administration of enterprise software distribution platforms and application virtualization solutionsMaintain and optimize endpoint imaging and deployment infrastructure including task sequences driver libraries and OS deployment workflowsEngineer and maintain mobile device management (MDM) configurations for SBA-issued smartphones and tabletsSupport integration of end-user computing platforms with Microsoft Entra identity conditional access and Zero Trust Architecture frameworksCoordinate with the Network Engineer T4 team on network requirements for endpoint management infrastructureSecurity Engineering & Zero Trust:Engineer endpoint security configurations aligned with Zero Trust Architecture principles (NIST SP 800-207 OMB M-22-09)Design and implement Microsoft Defender for Endpoint configurations policies and automated response workflowsSupport implementation of application control device guard and credential guard technologies across SBAs endpoint fleetEngineer and maintain endpoint data loss prevention (DLP) configurations in coordination with the Microsoft Infrastructure team and Purview compliance solutionsConduct endpoint security engineering reviews and provide recommendations for improving SBAs endpoint security postureSupport incident response activities involving endpoint security events in coordination with the NOC and Microsoft Infrastructure teamsKnowledge Management & Documentation:Maintain comprehensive and current documentation of all endpoint platform configurations engineering decisions and operational proceduresDevelop and maintain technical runbooks engineering standards and knowledge base articles for EUC engineering operationsEnsure all EUC engineering change activities are documented in the Government ITSM platform in accordance with ITIL 4 change management practicesProvide technical knowledge transfer to desktop support technicians and Service Desk staff on endpoint platform topicsSupport transition-in and transition-out activities by providing complete and accurate EUC engineering documentationSecurity & Compliance:Ensure all EUC engineering activities comply with FISMA NIST SP 800-53 FedRAMP and SBA cybersecurity policiesApply least-privilege and separation-of-duties principles to all endpoint management configurations and access controlsAdhere to all SBA policies regarding handling of CUI SBU and FOUO informationPromptly report suspected or confirmed security incidents involving endpoint platforms per SBA proceduresSupport FISMA assessment and authorization activities for endpoint-related systems and platformsRequired Qualifications:Experience:Minimum 46 years of hands-on enterprise end-user computing engineering experienceDemonstrated experience engineering and administering Microsoft Intune and endpoint management platforms at enterprise scaleProven experience with Windows Autopilot endpoint imaging and automated deployment workflowsExperience developing PowerShell scripts and automation for endpoint management and administrationExperience in a Federal or private-sector enterprise environment of comparable scale complexity and security postureDemonstrated experience with endpoint security engineering including Microsoft Defender for Endpoint and endpoint hardeningExperience implementing Zero Trust Architecture principles across enterprise endpoint environmentsFamiliarity with NIST SP 800-53 and CIS benchmark controls as applied to endpoint platformsTechnical ExpertiseExpert-level proficiency in:Microsoft Endpoint Manager (Intune) engineering policy design and automationWindows 10/11 platform engineering and configuration managementWindows Autopilot and zero-touch deployment workflowsPowerShell scripting for endpoint management and automationMicrosoft Defender for Endpoint configuration and policy managementGroup Policy Objects (GPOs) and Intune configuration profilesSoftware packaging deployment automation and application lifecycle managementEndpoint compliance monitoring and remediationStrong working knowledge of:Microsoft Azure Active Directory (Entra ID) and conditional accessZero Trust Architecture and OMB M-22-09 endpoint requirementsNIST SP 800-53 and CIS benchmark controls for endpointsAzure Virtual Desktop or Windows Virtual DesktopMicrosoft Purview DLP and information protectionITSM platforms (e.g. ServiceNow)ITIL 4 change and incident management practicesEnterprise network fundamentals relevant to endpoint managementRequired Certifications: (Must be current and unexpired throughout performance)Microsoft Certified: Modern Desktop Administrator Associate (MD-102) (required)Microsoft Certified: Azure Administrator Associate (AZ-104) (required)CompTIA Security (required)Additional preferred certifications:Microsoft Certified: Endpoint Administrator ExpertMicrosoft Certified: Identity and Access Administrator Associate (SC-300)Microsoft Certified: Security Operations Analyst Associate (SC-200)CompTIA NetworkITIL 4 FoundationOur Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352

Required Experience:

IC


About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile