IT Helpdesk Specialist
Job Description
This on-site IT Help Desk Specialist role provides technical support, ticketing, and conference room IT assistance for the Congressional Budget Office under Terrestris Global Solutions, with potential project work and a contingent contract award.
Responsibilities
- Inspect computer equipment and prepare systems for deployment according to onboarding documentation and division-specific requirements, ensuring proper imaging, configuration, and inventory registration prior to delivery.
- Deploy and configure Windows desktops, macOS systems, and mobile devices following the imaging process, validating inventory, security baselines, and readiness for end-user delivery per division requirements and IRM standards.
- Install, configure, troubleshoot, and maintain employee hardware, software, and peripherals across Windows and macOS, including upgrades, patches, firmware updates, and approved security configurations to meet Zero Trust and Defense-in-Depth standards.
- Register and configure mobile devices (iOS, Android) within enterprise MDM platforms; provide training and troubleshooting on authentication, MFA, and secure remote connectivity.
- Load and verify software packages and configuration baselines through automated imaging and patching tools such as Ivanti EPM, KACE, or equivalent, ensuring accuracy and adherence to division templates.
- Execute system verification tests by running administrative commands and monitoring logs to validate image integrity, patch levels, and compliance with endpoint security policies; confirm log reception per Sentinel, VSOC, and related monitoring platforms.
- Diagnose and resolve complex system issues, including MFA failures, identity anomalies, network connectivity problems, and endpoint irregularities, applying independent judgment to identify root causes and corrective actions while protecting data.
- Support Tier I personnel by enforcing best practices, creating and validating SOPs, reviewing escalations, and collaborating on issue resolution. Utilize JAMF and Microsoft Intune for endpoint automation and configuration management; analyze Windows Event Viewer and macOS Console logs to develop evidence-based solutions.
- Instruct users on effective use of equipment, collaboration software, cloud services, and self-service resources; contribute to end-user documentation and knowledge base updates.
- Coordinate activities with the Service Desk, Network Operations, Cloud Services, and Cybersecurity teams to ensure timely issue resolution and alignment with IRM standards.
- Provide clear and timely communication on ticket status, updates, and resolutions through the official tracking system, voicemail, email, or direct user interaction in accordance with customer service performance metrics.
- Replace defective or obsolete hardware and software components; document changes and verify asset records per CBO asset management procedures.
- Identify and analyze recurring problem trends, develop mitigation strategies, and present findings and improvement recommendations to IRM management.
- Ensure rigorous application of information security and information assurance principles in all support activities, including encryption, data loss prevention, and secure credential handling.
- Administer Microsoft Entra ID / Active Directory environments, including user provisioning, group policy adjustments, and identity lifecycle management, in coordination with IAM governance.
- Support macOS and iOS administration, including device enrollment, configuration profile deployment, FileVault management, and integration with enterprise authentication and compliance frameworks.
- Perform secure drive sanitization and destruction using BitRaser or approved tools, maintaining required documentation and destruction certificates.
- Use approved hard drive cloning devices and software to support workstation deployments, refreshes, data migrations, and recovery operations.
- Assist with assigned tasks in line with COR guidance and guidance provided.
- Recommend and implement advanced remedial measures such as driver updates, policy adjustments, or imaging corrections to restore full functionality and prevent recurrence; coordinate reviews with the CIO / DCIO and automate solutions where feasible.
- Implement and document imaging strategies that leverage automation, scripting, and division baselines to deliver secure, consistent workstation builds across all platforms.
- Participate in patch management and vulnerability remediation cycles, ensuring timely updates and adherence to configuration management policies; coordinate with Nessus findings to prioritize remediation of critical and high-severity vulnerabilities.
- Collaborate with IRM technical leads to assess environment readiness, validate permissions, and confirm appropriate administrative access for Tier II and escalation functions.
- Assist in responding to outages, service disruptions, and other emergencies, including participation in incident response activities.
Requirements
- Must be a U.S. citizen, lawful permanent resident, or H1B visa holder; must demonstrate work eligibility.
- Ability to obtain favorable FBI criminal checks and be fingerprinted at the U.S. Capitol Police headquarters in Washington, DC prior to starting the contract.
- Proven enterprise-level administration and support for macOS and Windows, including imaging, deployment, configuration management, and adherence to security baselines.
- Experience with endpoint management and automation platforms such as Ivanti, KACE, Microsoft Intune, and JAMF to deploy software, manage devices, enforce policies, and streamline tasks.
- Ability to manage and troubleshoot identity and access management services, including Microsoft Entra ID/Active Directory, MFA, RBAC, and AWS-integrated identity solutions.
- Skill in diagnosing authentication, connectivity, and endpoint performance issues by analyzing system logs, Event Viewer data, macOS Console diagnostics, and other monitoring tools.
- Ability to coordinate cross-team incident response with Service Desk, Network Operations, and Cybersecurity to ensure timely investigation, escalation, and remediation.
- Strong understanding of advanced system administration including patch management, baseline configuration, automated imaging, and improving endpoint deployment workflows.
- Solid understanding of cloud and hybrid environment management, with experience supporting AWS-hosted resources, identity services, and on-premises to cloud integrations.
- Solid understanding of Zero Trust security principles and ensuring security, compliance, and configuration standards across endpoints and networks.
- Clear and effective communication, with ability to document procedures, create user guides, and mentor Level I technicians.
- Excellent customer service and problem-solving skills, with the ability to prioritize tasks to meet tight deadlines while maintaining professionalism and responsiveness.
Technologies
- Ivanti EPM
- KACE
- JAMF
- Microsoft Intune
- Microsoft Entra ID
- Active Directory
- BitRaser
- Nessus
- Sentinel
- VSOC
- Windows Event Viewer
- macOS Console
- Enterprise MDM platforms
Benefits
- Health, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Award programs acknowledge employees for exceptional performance and service standards
- Full-time and part-time employees working at least 20 hours per week are eligible for benefit programs
- Other offerings may be provided for employees not within this category
What qualifications do you look for?
- Must be a U.S. citizen, lawful permanent resident, or H1B visa holder; must demonstrate work eligibility.
- Ability to obtain FBI criminal checks and fingerprinting at the U.S. Capitol Police headquarters in Washington, DC prior to starting the contract.
- Enterprise-level administration and support for macOS and Windows, including imaging, deployment, configuration management, and security baselines.
- Experience with endpoint management and automation platforms such as Ivanti, KACE, Microsoft Intune, and JAMF.
- Ability to manage and troubleshoot identity and access management services including Microsoft Entra ID/Active Directory, MFA, RBAC, and AWS-integrated identity solutions.
- Ability to diagnose authentication, connectivity, and endpoint performance issues via system logs and monitoring tools.
- Ability to coordinate cross-team incident response with Service Desk, Network Operations, and Cybersecurity.
- Strong understanding of patch management, baseline configuration, automated imaging, and endpoint deployment workflows.
- Strong understanding of cloud and hybrid environment management, with AWS experience.
- Strong understanding of Zero Trust security principles and compliance standards.
- Clear and effective communication; ability to document procedures and mentor Level I technicians.
- Excellent customer service and problem-solving skills with the ability to prioritize tasks under deadlines.
We will be extra impressed if you have
- Bachelor's degree in information technology, Computer Science, or a related field
- CompTIA Security+
- Microsoft Certified: Endpoint Administrator Associate (or equivalent)
- Apple Certified IT Professional
- AWS Certified Cloud Practitioner (or higher)
- ITIL Foundation or equivalent service management certification
- Certified SysOps Administrator – Associate
What kind of benefits does Terrestris offer?
- Outstanding benefits including health, financial, and retirement options
- Paid leave, professional development, tuition assistance, and work-life programs
- Award programs recognizing exceptional performance and service standards
- Eligibility for benefit programs for full-time and part-time employees working at least 20 hours weekly
- Additional offerings may be provided for employees outside this category