Azure Virtual Desktop (part-time) (R-00201)
About the role
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence. The Endpoint Engineer – AI Desktop Deployment is responsible for designing, deploying, securing, and maintaining enterprise Windows endpoints that support AI-enabled desktop capabilities in highly regulated, government, and Zero Trust environments. This role combines traditional Windows desktop engineering with modern endpoint management, security compliance, application deployment, performance optimization, and device health monitoring. The engineer will work closely with cybersecurity, cloud, identity, infrastructure, and application teams to ensure endpoints are secure, compliant, performant, and ready to support AI-enabled applications and workloads. The ideal candidate has strong hands-on experience with Microsoft Intune, Microsoft Endpoint Manager, Windows 10/11, Group Policy, application packaging, and Zero Trust endpoint controls.
Job Responsibilities
- Administer and maintain Azure Virtual Desktop and Nerdio Manager for Enterprise, including platform health, automation jobs, autoscaling, roles, scopes, delegated permissions, host pools, session hosts, and workspaces.
- Troubleshoot and resolve AVD/Nerdio issues involving session host provisioning, connectivity, FSLogix profiles, performance, failed automation jobs, configuration issues, and access or policy assignments.
- Maintain, patch, test, version, and deploy centralized golden/master desktop images, coordinating operating system, security, and application updates across AVD and physical workstation environments.
- Review and optimize Microsoft Intune configuration profiles, compliance policies, security baselines, device groups, assignments, and policy architecture to reduce conflicts, duplication, and configuration drift.
- Assess and improve Windows Autopilot provisioning, enrollment status pages, deployment profiles, device assignments, and zero-touch workstation deployment processes.
- Support Microsoft Entra ID security and identity capabilities, including Conditional Access, RBAC, Privileged Identity Management (PIM), Just-in-Time administration, Windows LAPS, and least-privilege access practices.
- Integrate and support endpoint lifecycle operations involving Tanium and CrowdStrike Falcon, including endpoint visibility, patching, software deployment, inventory, compliance reporting, and endpoint protection.
- Monitor platform capacity, utilization, image compliance, service health, incidents, and operational trends; develop recurring reports and participate in service review meetings.
- Support onboarding of new agencies or business units into the centrally governed AVD/Nerdio environment, including subscription readiness, connectivity, configuration standards, host pool alignment, and operational readiness.
- Develop and maintain Standard Operating Procedures (SOPs), Operations & Maintenance documentation, administrative runbooks, onboarding procedures, governance standards, and technical support documentation.
- Identify and implement appropriate automation and process improvements that improve scalability, platform consistency, administrative efficiency, monitoring, reporting, and desktop lifecycle management.
- Collaborate with customer technical teams, project stakeholders, and agency administrators; participate in technical reviews, change-management activities, maintenance windows, knowledge-transfer sessions, and incident resolution.
Job Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related technical discipline preferred.
- Equivalent combination of relevant technical education, professional certifications, and significant hands-on enterprise engineering experience may be considered in lieu of a degree. Preferred Certifications:
- Relevant Nerdio Manager for Enterprise / Nerdio certification or demonstrated equivalent enterprise implementation and operational experience.
- Relevant Microsoft Azure Virtual Desktop / Azure certification or demonstrated equivalent enterprise AVD experience.
- Relevant Microsoft Intune / Endpoint Manager certification or demonstrated equivalent enterprise endpoint-management experience.
- Tanium certification appropriate to the assigned engineering responsibilities.