RDS Engineer
We design, operate, and continually improve a high-availability Remote Desktop Services (RDS) platform supporting mission-critical applications across the enterprise. Our team owns the full stack—Windows Server, RDS roles, identity & security, automation, monitoring, and service reliability. As an RDS Engineer, you will build and support enterprise-grade RDS environments—publishing applications, tuning performance, hardening security, and driving automation for scale and reliability. You'll collaborate with app owners, security, networking, and service desk to deliver a secure, fast, and resilient virtual app experience for our users.
In this role, you will:
As an RDS Engineer, you will build and support enterprise-grade RDS environments—publishing applications, tuning performance, hardening security, and driving automation for scale and reliability. You'll collaborate with security, networking, and application teams to deliver a secure, fast, and resilient virtual app experience for our users.
- RDS Platform Ownership: Deploy, configure, and administer RDS Connection Broker, Gateway, Session Host, Web Access, and Licensing roles across multi-site environments.
- App Publishing & Lifecycle: Package, publish, and maintain 50–100+ applications, ensuring proper dependencies, app compatibility, versioning, and change control.
- Profiles & User Experience: Implement and optimize FSLogix profile containers; tune GPOs, logon/logoff performance, printer/redirection policies, and session resiliency.
- Windows Server & Storage: Administer Windows Server (2022), DFS namespaces/replication, storage IOPS analysis, and capacity planning.
- Networking & Performance: Tune RDP protocol, configure/load-balance RDS gateways, and optimize for WAN/latency conditions; troubleshoot CPU/RAM, IOPS, GDI, and handle count issues.
- Identity & Security: Integrate with Active Directory / Entra ID, MFA, and certificates/PKI; apply OS hardening, patching, and vulnerability remediation in accordance with policy.
- Monitoring & Incident Response: Build dashboards/alerts; analyze Event Viewer, PerfMon, and Splunk telemetry; lead incident response, root-cause analysis (RCA), and corrective actions.
- Automation & Scripting: Develop PowerShell modules and scripts for provisioning, configuration drift detection, reporting, and operational tasks (e.g., image updates, app rollouts).
- Service Reliability: Design and maintain HA/DR for brokers, gateways, and dependent infrastructure; validate backups/restore and conduct failover testing.
- Documentation & Runbooks: Create and maintain runbooks, SOPs, diagrams, and as-built documentation; contribute to knowledge articles for Service Desk.
- Compliance & Audit: Ensure standards, baselines, and controls are met (security benchmarks, access reviews, change management).
- Collaboration: Partner with Networking, Security, EUC, and Application teams; provide Tier 3 escalation support and mentor junior engineers
Required Qualifications:
- 4+ years of Systems Engineering, Technology Architecture experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 4+ years of experience with Windows server operating systems
- Hands-on expertise with RDS roles including Connection Broker, Gateway, Session Host, Web Access, and Licensing.
- Experience publishing and managing applications in enterprise environments.
- Strong ability to diagnose performance issues related to CPU, RAM, IOPS, GDI objects, and handle counts.
- Proficient with Event Viewer, Performance Monitor, and log analytics tools such as Splunk.
- Capable of leading troubleshooting, root-cause analysis, and remediation.
- PowerShell scripting experience for automation, reporting, and operational efficiency.
Desired Qualifications:
- Advanced scripting (PowerShell).
- AVD hybrid knowledge.- Risk monitoring.- Observability tools (Sentinel, Grafana, Log Analytics).
- Proficiency with FSLogix profiles, GPO optimization, DFS, and advanced Windows Server administration.
- Skilled in RDP protocol tuning, load balancing, and WAN performance optimization.
- Experience with Active Directory, Entra ID, MFA, certificate management, and OS hardening best practices.
- Experience designing and supporting HA/DR configurations for RDS brokers, gateways, and dependent services.
- Ability to create and maintain runbooks, operational procedures, and backup/restore processes.
This role is not eligible for visa sponsorship