Find Jobs
Find Jobs Near You – Available Work in Your Location
Sr Desktop Engg/End Point security
Job Description
Sr Desktop Engg/End Point security
Skills
- Active Directory
- Asset Management
- Cyber Security
- Endpoint Protection
- FISMA
- Hardening
- Information System Security
- Information Security
- Continuous Monitoring
- Security Operations
- Security+
- Vulnerability Scanning
- Vulnerability Management
- Vulnerability Assessment
- Windows PowerShell
- Scripting
- Corrective And Preventive Action
- Internet Security
- Group Policy
- Active Directory
- Asset Management
- Cyber Security
- Endpoint Protection
- FISMA
- Hardening
- Information System Security
- Information Security
- Continuous Monitoring
- Security Operations
- Security+
- Vulnerability Scanning
- Vulnerability Management
- Vulnerability Assessment
- Windows PowerShell
- Scripting
- Corrective And Preventive Action
- Internet Security
- Group Policy
- Summary Position Summary Focused role responsible for correlating vulnerability data, validating CMDB accuracy, developing automation, and ensuring compliance reporting across Windows and macOS endpoints and servers within the HRSA enterprise environment.
This role works in close coordination with the Desktop Engineer, Patch Management to form a complete, closed-loop endpoint security function — w the Patch Management Engineer executes deployments and this role validates, analyzes, and reports on compliance outcomes. The Desktop Engineer II supports both Microsoft Intune and Jamf Pro environments, ensuring enterprise endpoints meet HRSA, HHS, and federal cybersecurity standards, with a strong emphasis on data integrity, vulnerability analysis, automation, and compliance analytics. This position works closely with the Federal Desktop Engineering Team, DEUS leadership, the HRSA Security Operations Center (SOC), and the HRSA Information System Security Officer (ISSO) to maintain continuous visibility into HRSA''s security posture and support FISMA compliance and GSS accreditation activities. Essential Duties and Responsibilities § Vulnerability Analysis and Remediation Engineering o Analyze vulnerability scan data from Tenable and correlate with patch and compliance data from Tanium, Microsoft Intune, and Jamf to validate remediation progress and identify persistent vulnerabilities, patch failures, and non-compliant endpoints across Windows and macOS environments. o Identify root causes of recurring vulnerabilities, installation failures, and devices consistently missing patches; provide documented remediation strategies and recommendations to DEUS leadership. o Track and validate remediation progress against HRSA''s required federal timelines: § Known Exploited Vulnerabilities (KEVs): remediated within 5 calendar days § Critical vulnerabilities: remediated within 15 calendar days § High vulnerabilities: remediated within 30 calendar days § Medium vulnerabilities: remediated within 90 calendar days § Low vulnerabilities: remediated within 365 calendar days o Ensure all vulnerabilities exceeding SLA remediation timelines have corresponding ServiceNow tickets opened for tracking and resolution, with associated severity levels and target completion dates documented. o Monitor Microsoft and Apple security advisories, vendor patch bulletins, and emerging threat intelligence to support proactive mitigation planning; provide input to DEUS on emerging vulnerabilities requiring out-of-band remediation as directed by the
HRSA CISO.
o Immediately notify DEUS leadership of any critical vulnerabilities or widespread compliance failures affecting large numbers of systems or mission-critical infrastructure. § Configuration Compliance and Baseline Management o and validate system configurations aligned with Center for Internet Security (CIS) Benchmarks for Windows and macOS endpoints and servers. o Monitor and analyze configuration drift across enterprise endpoints; identify deviations from approved baselines and assist DEUS in executing corrective actions to restore compliance. o Support enforcement of configuration policies through Microsoft Intune for Windows endpoints, Jamf Pro and Jamf Cloud for macOS endpoints, and Active Directory Group Policy Objects (GPOs) w applicable. o Configure and maintain Jamf policies, smart groups, and configuration profiles; maintain Intune compliance and configuration policies consistent with HRSA security standards. o Recommend improvements to endpoint hardening standards, patching policies, and compliance baselines to align with evolving CIS, HHS, and HRSA requirements. § CMDB Validation and Data Integrity o Maintain and validate Configuration Item (CI) records within the ServiceNow CMDB, ensuring accurate relationships between hardware assets, installed software, assigned users, and patch and compliance status across all managed endpoints. o Support ServiceNow Discovery and IT Operations Management (ITOM) processes to ensure automated asset discovery results are validated and reconciled with manual records. o Validate device records used by vulnerability management and patch management tools to ensure CMDB data accurately reflects device ownership, OS configuration, patch compliance status, and vulnerability remediation progress. o Conduct monthly CMDB configuration reviews; ensure device records are current, accurate, and support operational reporting and SLA compliance monitoring. o Coordinate with the Asset Management Specialist and Desktop Engineer, Patch Management to ensure CMDB data remains synchronized across all endpoint management platforms. § Automation and Integration Engineering o Develop and maintain automation scripts using PowerShell and Bash to support patch and compliance validation, vulnerability correlation, cross-platform data reconciliation, and custom reporting workflows within Tanium, Intune, Jamf, and ServiceNow environments. o Maintain integrations between Tanium, Tenable, Microsoft Intune, Jamf, and ServiceNow ITOM and CMDB for automated vulnerability identification, patch deployment tracking, and compliance reporting. o Build and maintain dashboards and reporting workflows within ServiceNow ITOM for vulnerability tracking, patch compliance metrics, and SLA performance monitoring. o Identify and implement opportunities to automate patching, compliance validation, and reporting processes; recommend process improvements to reduce manual intervention and improve data accuracy. § macOS Endpoint Engineering o Manage macOS endpoint configuration, patching, and compliance using Jamf Pro or Jamf Cloud, including deploying macOS operating system updates and third-party application patches. o Configure and maintain Jamf policies, smart groups, and configuration profiles; troubleshoot Jamf deployment issues, policy conflicts, and patch failures. o Support Apple device lifecycle activities including enrollment, provisioning, policy enforcement, and compliance monitoring through Apple Business Manager (ABM) and Jamf. o Ensure macOS endpoints meet HRSA and HHS security baselines and CIS Benchmark compliance standards. o Develop Bash scripting automation to support macOS patch deployment, compliance validation, and reporting workflows. § Reporting and Compliance o Provide weekly and monthly vulnerability and compliance data for inclusion in the DEUS Weekly Presentation, specifically the Vulnerability Compliance Snapshot, Vulnerability History, and Patch Summary sections. o Contribute to the monthly Vulnerability Management Report (due the first Friday of each month), including total workstations scanned, vulnerability counts by severity, CVE listings, remediation status, six-month trend analysis, and identification of recurring vulnerabilities. o Submit data for the Monthly Patch Compliance Report and OIT Metrics Dashboard (due by the 15th of each month), including patch success rates, outstanding vulnerabilities by severity, and sys... Visit the Employer site for more details
Benefits
- Dental Insurance