100%remote

Salary
—
Posted
Aug 13, 2026
Location
100%
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

This role focuses on designing, deploying, and securing enterprise Windows endpoints in government and Zero Trust environments, with a particular emphasis on supporting AI-enabled desktop applications. The engineer administers Microsoft Intune/Endpoint Manager, enforces STIG and federal security baselines, and automates endpoint tasks via PowerShell. It suits an experienced Windows endpoint specialist comfortable with compliance-heavy, government-cloud settings.

Senior level · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Quick apply — this platform usually takes a CV and a few fields.

Must have (11)
Microsoft Intune or Microsoft Endpoint ManagerWindows 10Windows 11Group PolicyPowerShellWindows AutopilotDISA STIGZero TrustMicrosoft Entra IDConditional AccessMicrosoft Government Cloud (GCC/GCC High)
Nice to have (4)
Microsoft GraphMicrosoft CopilotSIEMAWS

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Zero Trust3%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Microsoft Entra ID55%PowerShell50%Microsoft Intune45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $128,188 (middle half $100,819–$156,589).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 15, 2026. It is a model, not a headcount.

Why we read it this way (9)

SOC classification is a genuine judgment call: the role primarily operates and hardens Windows endpoints (15-1244), but the heavy STIG/compliance/Zero Trust security work and SIEM integration create a real pull toward 15-1212 Information Security Analysts.

No explicit years-of-experience requirement is stated at the role level; seniority is inferred from the breadth and depth of responsibilities (STIG baselines, Zero Trust architecture, government cloud, AI readiness).

The posting lists a Bachelor's degree as a hard requirement in the Qualifications section; no 'or equivalent experience' language is present.

Microsoft Graph and PowerShell automation appear together in a single qualifications bullet alongside Windows Autopilot; all three are listed under the qualifications block but the phrasing ('Experience with…') is less firm than the core Intune/Windows/GPO requirements — treated as required given their placement in the Qualifications section.

Microsoft Copilot and enterprise AI desktop application experience appear in the Qualifications section but are framed as 'Experience deploying…' without the same firmness as the core platform skills; included as preferred given the softer framing relative to the primary Intune/Windows requirements.

AWS appears only in the context of a desired-only certification ('desired only if the position supports or integrates with AWS environments') and is therefore preferred.

No compensation figures are provided in the posting.

No security clearance is explicitly required, though the role supports government/DoD environments; clearance is not stated as a gate.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Microsoft Defender for Endpoint.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗