Senior MECM Systems Administrator
1. General Overview:
The Digital Sector at Leidos is currently seeking a senior, hands-on Microsoft Endpoint Configuration Manager (MECM) Subject Matter Expert and Team Lead to support DISA J-6/J-9 in the Arlington, VA (Pentagon). This position leads enterprise MECM operations and a team of MECM administrators responsible for endpoint imaging, operating system deployment, application packaging, software update management, vulnerability remediation, configuration compliance, and MECM infrastructure sustainment.
The selected candidate will use MECM as a primary enterprise tool to rapidly remediate vulnerabilities and configuration deficiencies across Windows endpoints in OSD forest, OMS, and Platform Management domains operating on NIPRNet, SIPRNet, TS-C, and JWICS networks. The role requires strong technical leadership, extensive hands-on MECM expertise, and the ability to coordinate closely with Cyber Compliance, DCO, infrastructure teams, and government stakeholders to meet DISA STIG, IAVM, CTO, FRAGO, and other cyber-tasking suspense requirements.
2. Primary Responsibilities:
Team Leadership and MECM Operations-
• Lead the MECM team, including work assignment, technical oversight, mentoring, quality assurance, and escalation support for MECM Intermediate SMEs and System Administrators.
• Serve as the authoritative technical point of contact for MECM operations, enterprise endpoint-management capabilities, and vulnerability-remediation execution.
• Establish and maintain standard operating procedures, deployment standards, testing requirements, rollback plans, and change-control documentation for MECM services.
• Coordinate with DISA J-6/J-9, Cyber Compliance/IA personnel, DCO, server, network, database, and application teams to resolve endpoint-management issues and execute enterprise remediation initiatives.
• Brief MECM operational status, vulnerability-remediation progress, technical risks, and decisions required to DISA J-6/J-9 leadership and the Monthly Integrated Product Review (IPR).
Vulnerability Remediation and Patch Management-
• Own an aggressive vulnerability-remediation posture using MECM to package, test, deploy, validate, and report remediation for patches, hotfixes, cumulative updates, third-party software updates, configuration changes, and security baselines.
• Drive remediation of DISA Security Technical Implementation Guide (STIG) findings, Information Assurance Vulnerability Management (IAVM) notices, Cyber Tasking Orders (CTOs), FRAGOs, and other cyber tasking within or ahead of established suspense dates.
• Use MECM Software Update Management, compliance baselines, configuration items, PowerShell scripts, task sequences, and Group Policy changes to remediate vulnerabilities and configuration deficiencies.
• Establish and maintain automated deployment rings, phased rollout strategies, pilot groups, maintenance windows, and emergency-patching procedures that balance remediation speed with operational stability.
• Prioritize remediation based on vulnerability severity, exploitability, asset criticality, affected endpoint population, IAVM suspense, mission impact, and available compensating controls.
• Correlate MECM deployment and compliance data with ACAS/Tenable scan results, Trellix endpoint-security data, and other cyber-tool outputs to identify remediation gaps and validate closure.
• Support POA&M development and updates; provide technical evidence, deployment results, scan validation, and remediation artifacts for CCORI, inspections, audits, and cyber compliance reviews.
Imaging and Operating System Deployment-
• Design, develop, maintain, and troubleshoot MECM operating system deployment (OSD) capabilities for enterprise Windows endpoints.
• Build and sustain task sequences for new system deployment, hardware refresh, operating system upgrades, break/fix replacement, reimaging, security-tool installation, domain join, baseline configuration, and post-build application deployment.
• Manage and maintain operating system images, boot images, driver packages, driver-selection logic, PXE services, boot media, user-state migration processes, and supporting deployment content.
• Develop automated endpoint-build processes that reduce technician touch time, improve deployment consistency, and ensure systems are configured to approved security and operational standards.
• Troubleshoot OSD failures involving PXE, boot images, task sequences, driver injection, content availability, network connectivity, certificates, domain join, and post-build software installation.
• Coordinate imaging and deployment support during hardware lifecycle refreshes, Windows version upgrades, and major enterprise technology transitions.
Application Packaging and Software Deployment-
• Package, test, deploy, and maintain enterprise applications using MECM application-management capabilities, MSI, EXE, PowerShell, scripts, and other approved installation methods.
• Develop application detection methods, requirement rules, dependencies, relationships, return-code handling, uninstall procedures, and user-experience settings.
• Maintain application deployment standards and packaging documentation to ensure consistent, reliable, and auditable software delivery.
• Coordinate with application owners, cybersecurity personnel, and system stakeholders to deploy application upgrades, emergency patches, vulnerable-software removals, and security configuration changes.
• Validate applications in pilot and phased-deployment rings before broad enterprise release; monitor deployments and rapidly address failures or unintended operational impacts.
• Maintain software catalog accuracy, deployment content, and distribution-point availability to support timely enterprise application delivery.
MECM Infrastructure and Platform Sustainment-
• Administer, maintain, and modernize enterprise MECM infrastructure, including site servers, management points, distribution points, software update points, WSUS integration, SQL Server back-end components, reporting services, and associated Windows Server infrastructure.
• Ensure MECM infrastructure remains healthy, secure, patched, backed up, recoverable, and capable of meeting Group 1 restoration timelines.
• Monitor and troubleshoot MECM site health, component status, client communication, content distribution, replication, software update synchronization, database performance, certificate status, and endpoint-management service availability.
• Lead root-cause analysis and service restoration for MECM outages and performance issues, including failures related to SQL Server, WSUS, site components, distribution points, boundary groups, PKI, Active Directory, Group Policy, and client communication.
• Maintain MECM current branch releases, hotfixes, cumulative updates, management packs, supporting Windows Server updates, and required security configurations.
• Manage MECM backup, recovery, and restoration processes, ensuring backups are retained and stored away from the physical system in accordance with applicable policy and continuity requirements.
• Plan, coordinate, test, and execute MECM upgrades, server refreshes, distribution-point migrations, and infrastructure lifecycle activities through the DISA J-6/J-9 Enterprise Change Management framework.
Automation, Reporting, and Compliance Metrics-
• Develop and maintain PowerShell automation for patch deployment, vulnerability remediation, client-health correction, application deployment, inventory collection, reporting, and administrative tasks.
• Create and sustain MECM task sequences, compliance baselines, configuration items, collections, queries, and deployment workflows that automate endpoint remediation at scale.
• Produce weekly Microsoft Endpoint Operational Status and vulnerability-remediation metrics, including client health, software update compliance, deployment success rates, imaging status, application deployment status, and aging vulnerabilities.
• Develop and maintain reports and dashboards using MECM reporting, SQL Server Reporting Services (SSRS), SQL queries, and/or Power BI.
• Analyze remediation trends and recurring deployment failures; recommend process, automation, infrastructure, or policy improvements to improve compliance and reduce vulnerability aging
3. Basic Qualifications:
• Bachelor’s degree in Computer Engineering, Computer Information Systems, Telecommunications, Management Information Systems, Cybersecurity, or a related field; 8 – 12 years of prior relevant experience or Masters with 6 – 10 years of prior relevant experience. Specific experience, education and training may be considered in lieu of degree.
• U.S. Citizenship is a must.
• Active Top Secret clearance or higher at time of consideration.
• Must have a current DoD 8570.01-M / DoD 8140 IAT Level II baseline certification requirements before start date, such as Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent.
• Computing Environment certification appropriate to the role, such as a current Microsoft endpoint-management or Windows Server certification, is required.
• 100% onsite at a government facility within the National Capital Region, primarily at the Pentagon, Crystal Gateway, Taylor Building, Mark Center, or another DISA J-6/J-9-designated alternate site.
• Candidate must reside in the DC Metro Area and have reliable transportation.
• Must comply with all DoD, DISA, and DISA J-6/J-9 security and access protocols, including the ability to access NIPRNet and SIPRNet environments.
• Seven (7) or more years of hands-on experience administering MECM/SCCM at enterprise scale, including experience serving as a senior technical authority, technical lead, or team lead.
• Demonstrated experience leading or mentoring systems administrators, endpoint-management personnel, or technical teams.
• Demonstrated experience using MECM to execute vulnerability remediation and improve patch compliance against DoW STIGs, IAVMs, DTOs, FRAGOs, or comparable cyber tasking within mandated timelines.
• Expert-level knowledge of MECM software update management, application packaging, application deployment, OS deployment/imaging, task sequences, compliance baselines, client health, and endpoint troubleshooting.
• Hands-on experience building and supporting MECM operating system deployment solutions, including task sequences, boot images, driver packages, PXE, and endpoint provisioning workflows.
• Hands-on experience packaging and deploying enterprise applications, including detection methods, dependencies, supersede, installation scripting, and deployment troubleshooting.
• Strong experience administering MECM infrastructure, including site servers, management points, distribution points, software update points/WSUS, SQL Server, SSRS, Active Directory, Group Policy, Windows Server, and PKI.
• Strong PowerShell scripting skills for automation of endpoint remediation, software deployment, reporting, and administrative operations.
• Experience producing and interpreting MECM operational reporting through SSRS, SQL Server, Power BI, or equivalent reporting tools.
• Experience integrating or correlating MECM data with cyber tools, including ACAS/Tenable and Trellix EDR or equivalent vulnerability-management and endpoint-security platforms.
• Working knowledge of RMF, POA&M management, CCORI/inspection readiness, and DoD cyber tasking processes.
• Excellent troubleshooting, written communication, verbal communication, leadership, and customer-briefing skills.
4. Preferred Qualifications:
• Experience with WSUS/SUP architecture, Automated Deployment Rules (ADRs), patch compliance, deployment rings and troubleshooting failed updates.
• Working knowledge of Microsoft SQL Server, MECM databases, queries, WQL/CMPivot, and reporting technologies such as SSRS.
• Experience troubleshooting MECM using client/server logs, CMTrace, WMI, registry, PowerShell and network troubleshooting tools.
• Experience with Microsoft Intune, Entra ID and MECM/Intune co-management is highly desirable. Microsoft supports moving workloads such as compliance, Windows Update, endpoint protection, device configuration and client applications between Configuration Manager and Intune.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
October 8, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $92,300.00 - $166,850.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Source: the employer's careers page. Last checked 2026-10-09. Posted 2026-10-08.
More jobs at Leidos · On-site jobs in United States · Software development jobs