We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

ENDPOINT ENGINEER - (MAC SME)

Empower AI
United States, Virginia, Quantico
Oct 01, 2026

ENDPOINT ENGINEER - (MAC SME)


Job ID

2026-9666




Job Locations

US-VA-Quantico

Category
IT: Administrator / Analyst / Architect / Engineer

Type
Regular Full-Time



Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.

Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company's commitment to hiring and supporting active-duty and veteran employees.



Responsibilities

Description

Empower AI is seeking an Endpoint Engineer - MAC SME to engineer and sustain the MAC (macOS / iOS/ Jamf) endpoint systems and infrastructure on the NIPRNet, SIPRNet and JWICS (as available) enclaves of a Department of War agency, where the same standards of automation, hardening, and RMF compliance apply but tooling, connectivity, and handling procedures differ. The engineer operates the classified-enclave endpoint management infrastructure (e.g., Jamf), engineers and validates hardened images and Group Policy baselines, executes CAT I/II/III patching within enclave constraints, supports classified VDI and cross-domain considerations, and produces RMF evidence for the classified endpoint systems. This TS/SCI privileged-user role is the Tier III escalation point for classified endpoint incidents. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.

THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

JOB DUTIES:

    Engineer, operate, and maintain the NIPIRNet, SIPRNet and JWICS endpoint systems and management infrastructure (macOS / iOS/ Jamf, imaging, provisioning, Group Policy) in accordance with enclave-specific security, transfer, and handling procedures.
  • Plan and execute CAT I/II/III patch and software deployments on the classified enclaves within PRS timeframes, managing media transfer and disconnected/air-gapped update workflows where required.
  • Engineer and validate hardened images and configuration baselines for classified endpoints against DISA STIGs and enclave authority requirements, and provide RMF control evidence and POA&M inputs in eMASS for the classified endpoint systems.
  • Serve as the Tier III escalation point for classified-enclave endpoint incidents and coordinate with the enclave network, cybersecurity, and communications teams.
  • Lead the engineering design, implementation, and lifecycle of the enterprise endpoint infrastructure: hardened image pipelines, automated provisioning, endpoint management platform architecture (Jamf), configuration baselines, and VDI integration across all enclaves.
  • Lead the evaluation, cost-benefit analysis, and phased implementation of the Digital Twin capability for network and system modeling; author the Digital Twin Evaluation and Implementation Plan; and establish the practice that every significant change is tested in the digital replica before deployment.
  • Lead engineering for AI, automation, and analytics initiatives approved by the Government, including predictive analytics on service data, intelligent automation across support tiers, and integrations with the ITSM platform, and deliver Proof of Concept Reports documenting feasibility, risks, and benefits.
  • Conduct market research and produce Market Research Reports and Rough Orders of Magnitude (ROMs) for emerging technologies and proposed solutions to support Government planning and IT Capability Request analysis.


Qualifications

REQUIREMENTS:

  • Bachelor's degree and a minimum of 3 years of related experience (a Master's degree with 8 years of related experience, or an additional 4 years of related experience in lieu of a degree, may be substituted). 7 years (education/experience) overall minimum required.
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level I baseline certification (e.g., CompTIA A+ CE, Network+ CE, Security+ CE, CCNA-Security, or SSCP) prior to performing cybersecurity-related duties.
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 5 years of experience in systems or infrastructure engineering for enterprise MAC OS environments.
  • Current Apple Certified Support Professional (ACSP) Badge.
  • Expert knowledge of macOS / iOS/ Jamf and/or MAC architecture, Active Directory, Group Policy, and MAC automation.
  • Demonstrated experience designing and leading implementation of lab, pre-production, or digital twin environments and formal test-before-deploy practices.
  • Experience leading proof-of-concept evaluations, market research, and cost-benefit/ROM development for Government or enterprise decision-makers.
  • Extensive experience with DISA STIGs, ACAS/Nessus, RMF control implementation, POA&Ms, and eMASS.
  • Experience leading engineering teams, establishing standards, and executing changes through formal Change Management.
  • Excellent technical writing, briefing, and stakeholder communication skills; ability to participate in after-hours emergency on-call response.
  • Experience working on NIPRNet, SIPRNet and/or JWICS enclaves and with classified media handling procedures.

DESIRED SKILLS:

  • CISSP, CASP+ CE, or GCED; AWS or Azure architect certification.
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across NIPRNet, SIPRNet, and JWICS enclaves.
  • Experience applying AI/ML, RPA, or AIOps to IT service management and endpoint operations, including ServiceNow integrations.
  • Familiarity with DoD Zero Trust Strategy and Reference Architecture, DoDAF 2.02, DoD ICAM Strategy, and Technology Business Management (TBM).
  • ITIL 4 Foundation or Managing Professional; PMP.
  • Experience supporting IT Capability Request (ITCR) analysis and governance briefings.


About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm's overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.



Pay Band Min

USD $100,410.00/Yr.


Pay Band Max

USD $155,410.00/Yr.


Need help finding the right job?

We can recommend jobs specifically for you!
Click here to get started.
Applied = 0

(web-9db6c7984-m8w6w)