End Point security
Quick Overview
Job Description
Position Summary
Focused role responsible for correlating vulnerability data, validating CMDB accuracy, developing automation, and ensuring compliance reporting across Windows and macOS endpoints and servers within the HRSA enterprise environment. This role works in close coordination with the Desktop Engineer, Patch Management to form a complete, closed-loop endpoint security function — where the Patch Management Engineer executes deployments and this role validates, analyzes, and reports on compliance outcomes.
The Desktop Engineer II supports both Microsoft Intune and Jamf Pro environments, ensuring enterprise endpoints meet HRSA, HHS, and federal cybersecurity standards, with a strong emphasis on data integrity, vulnerability analysis, automation, and compliance analytics. This position works closely with the Federal Desktop Engineering Team, DEUS leadership, the HRSA Security Operations Center (SOC), and the HRSA Information System Security Officer (ISSO) to maintain continuous visibility into HRSA''s security posture and support FISMA compliance and GSS accreditation activities.
Essential Duties and Responsibilities
§ Vulnerability Analysis and Remediation Engineering
o Analyze vulnerability scan data from Tenable and correlate with patch and compliance data from Tanium, Microsoft Intune, and Jamf to validate remediation progress and identify persistent vulnerabilities, patch failures, and non-compliant endpoints across Windows and macOS environments.
o Identify root causes of recurring vulnerabilities, installation failures, and devices consistently missing patches; provide documented remediation strategies and recommendations to DEUS leadership.
o Track and validate remediation progress against HRSA''s required federal timelines:
§ Known Exploited Vulnerabilities (KEVs): remediated within 5 calendar days
§ Critical vulnerabilities: remediated within 15 calendar days
§ High vulnerabilities: remediated within 30 calendar days
§ Medium vulnerabilities: remediated within 90 calendar days
§ Low vulnerabilities: remediated within 365 calendar days
o Ensure all vulnerabilities exceeding SLA remediation timelines have corresponding ServiceNow tickets opened for tracking and resolution, with associated severity levels and target completion dates documented.
o Monitor Microsoft and Apple security advisories, vendor patch bulletins, and emerging threat intelligence to support proactive mitigation planning; provide input to DEUS on emerging vulnerabilities requiring out-of-band remediation as directed by the HRSA CISO.
o Immediately notify DEUS leadership of any critical vulnerabilities or widespread compliance failures affecting large numbers of systems or mission-critical infrastructure.
§ Configuration Compliance and Baseline Management
o Apply and validate system configurations aligned with Center for Internet Security (CIS) Benchmarks for Windows and macOS endpoints and servers.
o Monitor and analyze configuration drift across enterprise endpoints; identify deviations from approved baselines and assist DEUS in executing corrective actions to restore compliance.
o Support enforcement of configuration policies through Microsoft Intune for Windows endpoints, Jamf Pro and Jamf Cloud for macOS endpoints, and Active Directory Group Policy Objects (GPOs) where applicable.
o Configure and maintain Jamf policies, smart groups, and configuration profiles; maintain Intune compliance and configuration policies consistent with HRSA security standards.
o Recommend improvements to endpoint hardening standards, patching policies, and compliance baselines to align with evolving CIS, HHS, and HRSA requirements.
§ CMDB Validation and Data Integrity
o Maintain and validate Configuration Item (CI) records within the ServiceNow CMDB, ensuring accurate relationships between hardware assets, installed software, assigned users, and patch and compliance status across all managed endpoints.
o Support ServiceNow Discovery and IT Operations Management (ITOM) processes to ensure automated asset discovery results are validated and reconciled with manual records.
o Validate device records used by vulnerability management and patch management tools to ensure CMDB data accurately reflects device ownership, OS configuration, patch compliance status, and vulnerability remediation progress.
o Conduct monthly CMDB configuration reviews; ensure device records are current, accurate, and support operational reporting and SLA compliance monitoring.
o Coordinate with the Asset Management Specialist and Desktop Engineer, Patch Management to ensure CMDB data remains synchronized across all endpoint management platforms.
§ Automation and Integration Engineering
o Develop and maintain automation scripts using PowerShell and Bash to support patch and compliance validation, vulnerability correlation, cross-platform data reconciliation, and custom reporting workflows within Tanium, Intune, Jamf, and ServiceNow environments.
o Maintain integrations between Tanium, Tenable, Microsoft Intune, Jamf, and ServiceNow ITOM and CMDB for automated vulnerability identification, patch deployment tracking, and compliance reporting.
o Build and maintain dashboards and reporting workflows within ServiceNow ITOM for vulnerability tracking, patch compliance metrics, and SLA performance monitoring.
o Identify and implement opportunities to automate patching, compliance validation, and reporting processes; recommend process improvements to reduce manual intervention and improve data accuracy.
§ macOS Endpoint Engineering
o Manage macOS endpoint configuration, patching, and compliance using Jamf Pro or Jamf Cloud, including deploying macOS operating system updates and third-party application patches.
o Configure and maintain Jamf policies, smart groups, and configuration profiles; troubleshoot Jamf deployment issues, policy conflicts, and patch failures.
o Support Apple device lifecycle activities including enrollment, provisioning, policy enforcement, and compliance monitoring through Apple Business Manager (ABM) and Jamf.
o Ensure macOS endpoints meet HRSA and HHS security baselines and CIS Benchmark compliance standards.
o Develop Bash scripting automation to support macOS patch deployment, compliance validation, and reporting workflows.
§ Reporting and Compliance
o Provide weekly and monthly vulnerability and compliance data for inclusion in the DEUS Weekly Presentation, specifically the Vulnerability Compliance Snapshot, Vulnerability History, and Patch Summary sections.
o Contribute to the monthly Vulnerability Management Report (due the first Friday of each month), including total workstations scanned, vulnerability counts by severity, CVE listings, remediation status, six-month trend analysis, and identification of recurring vulnerabilities.
o Submit data for the Monthly Patch Compliance Report and OIT Metrics Dashboard (due by the 15th of each month), including patch success rates, outstanding vulnerabilities by severity, and systems pending remediation.
o Support FISMA compliance activities, GSS accreditation, and continuous monitoring requirements by providing documentation, inventory data, configuration details, and compliance evidence as directed by HRSA OIT/DEUS or the HRSA ISSO.
o Support internal and external audits by providing evidence of vulnerability scanning, patch deployment, configuration compliance, and remediation documentation.
o Ensure all data reflected in reporting deliverables is system-generated from HRSA-approved tools including Tanium, Tenable, Jamf, and ServiceNow, and validated for accuracy before submission.
§ Change Management and Engineering Support
o Participate in change management reviews for patch and configuration deployments; validate patches and configurations prior to production rollout in accordance with HRSA change management policy.
o Collaborate with the Patch Management Engineer, Security Operations, the Federal Desktop Engineering Team, and federal stakeholders to ensure coordinated, compliant endpoint management across the enterprise.
o Coordinate with the HRSA SOC and ISSO on security incident response activities involving endpoint vulnerabilities or configuration exposures.
Required Qualifications
§ Bachelor''s degree in Information Technology, Cybersecurity, Computer Science, or a related field; or equivalent combination of education and experience.
§ Minimum 5 years of experience in desktop engineering, endpoint management, or vulnerability management in a federal or large enterprise environment.
§ Demonstrated experience with Tenable vulnerability scanning, including CVE analysis and remediation validation.
§ Hands-on experience with Microsoft Intune for Windows endpoint configuration and compliance management.
§ Demonstrated proficiency with Jamf Pro or Jamf Cloud for macOS endpoint management.
§ Proficiency in PowerShell and Bash scripting for automation and compliance reporting.
§ Experience with ServiceNow ITOM, Discovery, and CMDB administration.
§ Ability to obtain and maintain a federal Public Trust (Tier 2) background investigation and HHS PIV credential.
§ Preferred Qualifications (At least one of the following certifications is required):
o Microsoft Certified: Endpoint Administrator Associate (MD-102)
o Jamf Certified Administrator (JCA) or Jamf Certified Technician (JCT)
o Tanium Certified Operator
o CompTIA Security+
o CIS Certified Benchmark Implementer
Knowledge, Skills, and Abilities
§ Vulnerability Analysis and Correlation: Demonstrated skill in analyzing vulnerability scan outputs from Tenable, correlating findings with patch deployment data from Tanium, Intune, and Jamf, identifying persistent or recurring vulnerabilities, and producing prioritized remediation recommendations aligned with HRSA''s federal SLA timelines and security policy requirements.
§ Configuration Baseline and Compliance Management: Knowledge of CIS Benchmark standards for both Windows and macOS systems, with the ability to apply, monitor, and enforce configuration baselines using Microsoft Intune, Active Directory Group Policy Objects, and Jamf Pro, including identifying and remediating configuration drift across a large enterprise endpoint fleet.
§ CMDB Validation and Data Integrity: Skill in maintaining accurate Configuration Item records within the ServiceNow CMDB, including validating relationships between hardware assets, software, users, and compliance status, supporting ServiceNow Discovery and ITOM processes, and ensuring CMDB data accurately reflects the current state of HRSA''s managed endpoint environment.
§ Scripting and Automation Development: Ability to develop, test, and maintain PowerShell and Bash automation scripts to support vulnerability correlation, patch compliance validation, cross-platform data reconciliation, and custom reporting workflows within Tanium, Intune, Jamf, and ServiceNow ITOM environments.
§ macOS Endpoint Engineering: Demonstrated hands-on proficiency with Jamf Pro or Jamf Cloud administration, including policy configuration, smart group management, configuration profiles, Apple Business Manager enrollment workflows, and troubleshooting of macOS patch deployment issues and policy conflicts in a federal enterprise environment.
§ Federal Cybersecurity Compliance and Reporting: Knowledge of federal information security requirements applicable to endpoint vulnerability and configuration management, including FISMA, NIST SP 800-53, HHS IS2P, and HRSA continuous monitoring requirements, with the ability to support GSS accreditation activities, provide compliance evidence for audits, and respond to out-of-band patching directives from the HRSA CISO.
§ Cross-Team Coordination and Engineering Communication: Ability to collaborate effectively with the Patch Management Engineer, Federal Desktop Engineering Team, HRSA SOC, ISSO, and DEUS leadership to coordinate vulnerability remediation activities, communicate compliance trends, and translate technical findings into actionable recommendations for program leadership and executive reporting.
Tools and Technology Requirements (May not be exhaustive)
§ Windows and Cross-Platform Environment:
o Vulnerability Management: Tenable (Nessus), including CVE correlation, severity analysis, and remediation tracking
o Endpoint Management: Tanium, Microsoft Intune
o Identity and Configuration: Microsoft Active Directory, Group Policy Objects (GPOs), Microsoft Entra ID
o ITSM and CMDB: ServiceNow (ITOM, Discovery, CMDB, incident and change management modules)
o Scripting and Automation: PowerShell, Tanium scripting modules
o Security Baselines: CIS Benchmarks for Windows, SCAP-compliant scanning tools
§ macOS Environment:
o macOS Endpoint Management: Jamf Pro / Jamf Cloud (policies, smart groups, configuration profiles)
o Apple Ecosystem: Apple Business Manager (ABM), Apple device enrollment workflows
o Scripting: Bash, Python, zsh scripting for macOS automation
o Security Baselines: CIS Benchmarks for macOS, Jamf compliance policies
o Reporting and Collaboration:
o Reporting: ServiceNow dashboards, Microsoft Excel, PowerPoint
o Collaboration: Microsoft 365 (Teams, SharePoint, Outlook)
Note: This is not an exhaustive list. Tools and technologies may vary by project and evolve over time. The ideal candidate demonstrates flexibility and the ability to lead teams regardless of the specific platform.
Supervisory and Mentor Responsibilities
No direct supervisory authority over other contract staff. Serves as a technical resource and escalation point for Desktop Support Technicians on vulnerability-related troubleshooting, compliance verification, and CMDB documentation requirements. Collaborates closely with the Desktop Engineer, Patch Management as the validation and compliance intelligence counterpart in a two-engineer closed-loop model — one deploys, one verifies. Contributes to knowledge base articles in coordination with the Knowledge Management Specialist, documenting vulnerability analysis procedures, configuration standards, and remediation guidance for the DEUS Internal Technical Knowledge Base. Coordinates with the Program Manager and Deputy PM to communicate compliance trends, SLA risks, and corrective action recommendations for inclusion in weekly and monthly reporting deliverables.
Work Environment and Physical Requirements
Work Location: HRSA Headquarters, Rockville, MD (Onsite)
Travel: Occasional travel to regional offices and NHDP Baton Rouge, LA. Approximately 10% to 15% travel.
Physical Demands:
§ Prolonged periods of sitting at a desk and working on a computer.
§ Frequent use of hands and fingers to operate computer equipment and other office tools.
§ Must be able to communicate verbally and in writing clearly and effectively.
§ Occasionally required to stand, walk, and reach with hands and arms.
§ May occasionally lift or move up to 10 pounds (e.g., laptop, documents).
Work Conditions:
§ Work is performed in a standard office or home-office environment with moderate noise levels.
§ Must be able to manage stress associated with deadlines and evolving project requirements.
Skills
Similar jobs
Network Administrator with Security Clearance
TEKsystems c/o Allegis Group · Pensacola, United States
1 minute agoHardware Security Module (HSM) Migration Engineer
Galaxy i Technologies, Inc. · Phoenix, United States
19 minutes agoTechnical Writer with Security Clearance
GovCIO · Fort Meade, United States
19 minutes ago$113k - $123k/yrMission IT Operator with Security Clearance
Dexian Signature Federal · Denver, United States
20 minutes agoIAM Security Architect, Security Engs
New York Technology Partners · Chicago, United States
20 minutes agoSenior Flight Test Engineer, Maneuver Dominance with Security Clearance
Anduril Industries · Costa Mesa, United States
24 minutes ago$145k - $200k/yr