IT Support Engineer (Service Desk Engineering)
About the Role
We are seeking an IT Support Engineer to design, implement, and maintain technical controls that secure IT environment. This role goes beyond routine end-user help desk support; you will focus on engineering tasks to resolve complex or escalated tickets and proactively enable secure endpoint, identity, and device lifecycle operations. Your work will directly support organization's threat detection and mitigation strategy by reducing the risk of unauthorized initial discovery, lateral movement, and malicious credential use.
Note: This role is open to candidates who do not need sponsorship, and will involve extensive Background check.
Key Responsibilities
- Workstation Imaging & VDI Support: Design, build, and maintain secure, standardized workstation images for both macOS and Windows platforms to support on-site and remote access, including Virtual Desktop Infrastructure (VDI) connectivity.
- Endpoint Configuration & Patching: Implement and maintain endpoint configuration baselines, operating system/application patching, and version control to reduce configuration drift. Ensure delivery through approved mechanisms like company app stores, Microsoft Intune, or Group Policy Objects (GPO).
- Device Lifecycle & Asset Management: Support device registration, enrollment, and lifecycle management (via Microsoft Intune and Windows Autopilot) to ensure accurate asset inventory and visibility into connected users and devices.
- Identity & Access Security: Implement secure authentication mechanisms, including passwordless authentication and hardware-backed credentials (e.g., YubiKeys, CAC cards) for privileged and sensitive accounts.
- Logging & Telemetry: Enhance and maintain logging, monitoring, and audit capabilities to track device enrollment, user authentication activity, network access, and endpoint behavior.
- Documentation & Playbooks: Produce and update documentation and operational playbooks necessary to support IRM&TS operations, service desk engineering escalations, and incident response functions.
Required Technical Qualifications
- Operating Systems: Deep expertise in configuring and securing macOS and Windows operating systems for enterprise environments.
- Endpoint Management Tools: Hands-on experience with Microsoft Intune, Windows Autopilot, Ivanti, and KACE for deployment workflows, device compliance, and patching.
- Virtualization: Experience supporting end-user connectivity to VDI environments.
- Identity & Security: Familiarity with implementing advanced authentication methods, including passwordless setups and hardware security keys (YubiKeys, CAC).
- Configuration Management: Proficiency with Group Policy Objects (GPO) and creating conditional access policies based on user roles and device posture.
Expected Scope of Impact
As a key escalation point, you will not field routine Tier 1 requests. Instead, you will tackle advanced configuration issues, proactively enforce secure baseline standards, and ensure that all new devices and applications deployed in agency's segmented environments (cloud and non-cloud) meet strict security validation requirements.