Lead Service Engineer
Organization Background:
The Endpoint Engineering Services team manages all the client endpoints and Thin Clients across our enterprise: Windows and Apple desktops, laptops, iPhones, and iPads. We are responsible for ensuring that endpoints and their software are up to date with the latest approved OS version, patched, application delivery is maintained, and overall health is maintained. We ensure a seamless experience for caregivers through a centralized tool that automates many of these transactions.
What is this position all about?
We are seeking a hands-on IGEL Platform Engineer to design, implement, and operate secure, scalable, and highly available end-user compute (EUC) solutions using IGEL OS, IGEL Universal Management Suite (UMS), and IGEL Cloud Gateway (ICG). The role partners closely with EUC, VDI, Security, and Network teams to deliver seamless access to virtual desktops and apps (Citrix, VMware Horizon, Azure Virtual Desktop) while driving automation, policy governance, and proactive service reliability.
The Lead Enterprise IGEL Administrator will work independently with other Information Services (IS) professionals (e.g. Operational, Engineering, Architecture, and Application teams) to ensure the IGEL environment is optimized for the delivery of clinical and business services in support of the IS Strategic Plan. This requires close collaboration with clinical and non-clinical caregivers, project managers, and other IS professionals to enumerate requirements from various stakeholders. The Lead Enterprise IGEL Administrator will use their expert knowledge of IGEL/Citrix/Thin Clients/VDI to determine the optimal configuration of the IGEL environment and configure it accordingly. They will also author new or modify existing documentation related to IGEL and serve as an in-house operational escalation point for troubleshooting complex issues and developing and implementing solutions.
What will you be responsible for?
- Design and deploy IGEL OS–based endpoints at scale across sites and remote users using UMS and ICG for internet-managed devices.
- Define golden images, profiles, firmware customizations (Custom Partitions), and layered configurations for different personas/use cases.
- Integrate IGEL with Citrix DaaS/CVAD, VMware Horizon, and/or Azure Virtual Desktop (AVD) including protocol tuning (ICA/HDX, Blast, PCoIP, RDP), peripherals, and multimedia redirection.
- Implement HA/DR patterns for UMS (Load balancer, HA pairs), secure backups, and certificate lifecycle management (TLS, client certs, SCEP).
- Own day‑to‑day operations: firmware lifecycle (pilot → ringed rollout), profile governance, endpoint posture, and incident/problem management (ITIL).
- Build automation for configuration, assignments, and compliance reporting (e.g., UMS REST API, PowerShell, bash, Python).
- Maintain logging and observability (UMS logs, syslog, event correlation) and drive SLO/SLI dashboards for uptime, performance, and user experience.
- Manage peripheral enablement (printers, scanners, headsets, webcams, smartcards/HID) and USB policies.
- Ensure Zero Trust aligned configurations—secure boot, read‑only OS, MFA/SSO (SAML/OIDC), and conditional access integrations (e.g., with IdP).
- Enforce device hardening, secure Wi‑Fi/VPN profiles, proxy settings, and locked‑down kiosk modes where needed.
- Coordinate with InfoSec for vulnerability management, pen‑test remediation, and audit readiness (SOX/ISO27001).
- Create and maintain SOPs, runbooks, and RACI aligned with change, release, and problem management processes.
- Act as SME for IGEL in architecture reviews, change advisory boards, and major incident bridges.
- Partner with VDI/EUC teams to optimize session launch times, protocol QoS, and client-side policies.
- Deliver training, knowledge transfers, and clear documentation for support tiers.
Who are we looking for?
- Experience: 6–8 years in EUC/VDI engineering with at least 3+ years hands‑on IGEL (IGEL OS, UMS, ICG) in enterprise scale (50,000+ endpoints).
- Platforms: Strong with Citrix (DaaS/CVAD), VMware Horizon, and/or Azure Virtual Desktop client-side integration and optimization.
- Scripting/Automation: PowerShell, bash (and/or Python) for UMS API usage, configuration-as-code, and reporting.
- Operations: Proven track record with firmware lifecycle, ringed deployments, HA/DR for UMS, and structured change management (ITIL).
- Troubleshooting: Advanced log analysis (UMS, client logs), protocol trace basics (Wireshark), and performance tuning.