Desktop Engineer - Windows
Role summary
Computer World Services Corp (CWS) is seeking a Desktop Engineer - Windows for an enterprise federal IT setting. This role focuses on engineering, configuring, securing, and maintaining Windows environments, with a primary emphasis on identifying and remediating security vulnerabilities using tools like SCCM/MECM, NinjaOne, and PowerShell. Responsibilities include developing and deploying remediation packages, analyzing vulnerability findings, supporting federal cybersecurity requirements, and managing application lifecycles. The engineer will also provide Tier 3 support for complex Windows issues, troubleshoot operating systems and applications, and contribute to reporting and dashboards for vulnerability remediation progress. A Bachelor's degree and 5+ years of relevant experience are required.
Computer World Services Corp (CWS) is seeking a detail-oriented and results-driven Desktop Engineer – Windows responsible for engineering, configuring, securing, and maintaining Windows-based environments in an enterprise federal IT setting.
A primary focus of this position is the identification and remediation of security vulnerabilities through Microsoft System Center Configuration Manager (SCCM/MECM), NinjaOne, PowerShell, and other enterprise management technologies. The Desktop Engineer develops, tests, deploys, and maintains SCCM application and remediation packages designed to correct software vulnerabilities, configuration deficiencies, outdated applications, and other security exposures.
Key Tasks & Responsibilities
Windows Vulnerability Remediation
- Analyze Windows vulnerability findings and determine appropriate technical remediation strategies.
- Develop and implement remediation solutions for vulnerabilities affecting Windows operating systems, third-party applications, drivers, utilities, and configurations.
- Translate vulnerability findings, CVEs, security advisories, and remediation requirements into deployable technical solutions.
- Support remediation activities associated with applicable CISA Binding Operational Directives, including BOD 26-04, and other federal cybersecurity requirements.
- Coordinate with cybersecurity and vulnerability management teams to validate vulnerability findings and determine appropriate remediation actions.
- Design, develop, test, deploy, and maintain SCCM/MECM application packages, programs, task sequences, scripts, and remediation packages.
- Monitor SCCM deployment status and produce reports identifying successful, failed, pending, and non-compliant devices.
- Support the use and evaluation of NinjaOne as an enterprise endpoint management,
- Troubleshoot operating system, application, hardware, driver, security, and performance problems.
- Perform root cause analysis and develop sustainable solutions for recurring issues.
- Test scripts to ensure they operate safely across supported Windows configurations.
- Maintain reusable PowerShell libraries and documented automation procedures.
- Support development of dashboards and metrics showing vulnerability remediation progress.
- Assist management and cybersecurity teams in measuring remediation performance against established service levels and federal requirements.
- Package enterprise applications for automated deployment.
- Test application compatibility with supported Windows configurations.
- Maintain current versions of enterprise applications and identify obsolete or unsupported software.
- Develop upgrade and migration packages to replace vulnerable or end-of-life applications.
- Develop automated removal packages for prohibited, unsupported, or vulnerable applications.
- Coordinate application testing with application owners and technical stakeholders before enterprise deployment.
- Maintain documentation covering packaging standards, installation procedures, dependencies, rollback procedures, and known issues.
- Provide Tier 3 technical support for complex Windows issues.
- Support Active Directory, Group Policy, configuration, and user environment troubleshooting.
- Resolve issues resulting from application deployments, security remediation, operating system updates, and configuration changes.
- Coordinate with Tier 1 and Tier 2 support teams to resolve incidents and recurring problems.
- Provide technical guidance and knowledge transfer to desktop support personnel.
- Strong knowledge of Microsoft Windows desktop operating systems.
- Hands-on experience with Microsoft SCCM/MECM, particularly application packaging and software deployment.
- Experience creating and troubleshooting SCCM applications, packages, deployment collections, detection methods, and task sequences.
- Experience developing PowerShell automation and remediation scripts.
- Understanding of Windows vulnerability remediation and patch management.
- Ability to interpret vulnerability findings and translate them into technical remediation actions.
- Understanding of CVEs, security advisories, vulnerability severity, and remediation concepts.
- Knowledge of Active Directory and Group Policy.
Monitoring & Reporting
Application Packaging & Software Lifecycle Management
User Support & System Access
Required Skills & Competencies
Education & Experience
Education
Experience
- 5+ years of experience in desktop engineering, Windows system administration, management, or enterprise IT support.
- Demonstrated experience supporting Windows operating systems in enterprise client/server environments.
- Demonstrated experience with SCCM/MECM application packaging, deployment, or administration.
- Advanced PowerShell scripting experience.
- NinjaOne administration or engineering experience.
- Experience working in federal government IT environments.
Certifications
- Desired: Microsoft Endpoint, Windows, Azure, or related technical certifications.
- Desired: ITIL Foundation certification.
Security Clearance
