Skip to content
Thinking Machines LabThinking Machines LabSan Francisco, CA

Endpoint Engineer, IT

Build and operate secure macOS endpoint infrastructure as code using MDM platforms, GitOps, and production engineering practices. Lead migration to Fleet, own Santa/Rudolph, implement Zero Trust device posture, patching, zero-touch provisioning, and telemetry-driven compliance for a large fleet.

Salary not listed
On-site8+ YOEIT Support

About the role

What You’ll Do

  • Endpoint Configuration as Code: Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts. Build code review, staging, canary, validation, and rollback processes into endpoint changes.
  • MDM Platform Engineering: Operate our MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.
  • MDM Migration: Lead the evaluation, design, testing, and execution of our planned migration from Iru to Fleet. Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.
  • Santa and Rudolph: Own the architecture and operation of Santa and its Rudolph synchronization service. Manage binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.
  • Zero Trust and Device Trust: Partner closely with Security and Identity to make device trust a core component of our Zero Trust architecture. Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.
  • Continuous Posture Evaluation: Build systems that continuously evaluate device health and security posture, including MDM enrollment, OS version, patch status, disk encryption, endpoint protection, security-control status, and configuration compliance. Automatically identify and remediate drift or restrict access when a device no longer meets requirements.
  • Patch Management: Build and maintain automated macOS patching workflows that support rapid enforcement timelines while providing a thoughtful employee experience.
  • Zero-Touch Provisioning: Design and improve Apple Business Manager and Automated Device Enrollment workflows that turn a new Mac into a secure, fully configured, and productive machine with minimal manual intervention.
  • Software Distribution: Own application packaging, deployment, updating, and removal across the Mac fleet.
  • Fleet Telemetry and Compliance: Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.
  • Automation: Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.
  • Endpoint Security: Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.
  • Advanced Troubleshooting: Serve as the escalation point for complex macOS and endpoint-platform issues that cannot be resolved through standard IT support processes.
  • Technical Leadership: Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.

Basic Qualifications

  • 8+ years of experience building and operating secure IT or endpoint systems in complex environments.
  • Experience managing a large fleet of macOS devices through a modern MDM platform.
  • Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.
  • Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.
  • Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.
  • Experience using device health and security signals to evaluate endpoint compliance.
  • Experience successfully delivering complex technical projects from conception through production.
  • Strong ability to solve ambiguous problems involving multiple teams and stakeholders.
  • Ability to communicate technical concepts clearly to technical and nontechnical audiences.
  • A product-engineering mindset toward IT systems, including testing, observability, reliability, and controlled change management.
  • A consistent practice of creating clear technical documentation, architecture diagrams, runbooks, and operational procedures.
  • Ability to work from either our New York or San Francisco office.

Preferred Qualifications

  • Fleet: Experience deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities.
  • MDM Migration: Experience leading a production MDM migration, particularly in an environment using Apple Business Manager and Automated Device Enrollment.
  • Iru: Experience managing macOS devices with Iru, formerly Kandji.
  • Santa and Rudolph: Experience operating Santa at scale, including rule management, binary authorization, event telemetry, and a Rudolph synchronization service.
  • Zero Trust: Experience designing device-trust and continuous-posture-evaluation systems that integrate with identity providers, conditional access, or other Zero Trust controls.
  • MDM as a Service: Experience operating an MDM or device-management platform as a production service rather than only administering a SaaS console.
  • Progressive Delivery: Experience building automated endpoint rollout systems with staging, canary groups, rollback capabilities, and promotion decisions based on telemetry.
  • Open-Source Tooling: Experience deploying, operating, or contributing to open-source macOS endpoint-management or security tools.
  • Infrastructure as Code: Experience managing endpoint or cloud infrastructure through Terraform or another infrastructure-as-code framework.
  • Cloud Infrastructure: Experience operating AWS services such as Lambda, API Gateway, DynamoDB, containers, managed databases, and monitoring systems.
  • Endpoint Development: Proficiency in Swift or Go for building macOS endpoint tools, agents, or supporting services.
  • AI-Assisted Operations: Experience using LLMs to automate operational work or a strong interest in applying them to endpoint engineering.

Technical Skills

  • Python and shell scripting.
  • macOS internals, including launchd, configuration profiles, Transparency, Consent, and Control (TCC), system extensions, Endpoint Security, FileVault, Secure Token, and bootstrap tokens.
  • Apple Business Manager, Automated Device Enrollment, and Apple’s MDM and Declarative Device Management frameworks.
  • Modern Apple MDM platforms, particularly Iru, Fleet, Jamf, or equivalent.
  • Santa binary authorization and Rudolph synchronization infrastructure.
  • Fleet-scale querying and osquery.
  • Git, pull-request workflows, GitOps, and CI/CD for endpoint configuration.
  • Terraform and infrastructure as code.
  • Public-cloud fundamentals, including serverless infrastructure, containers, managed databases, and monitoring.
  • Device lifecycle automation, including zero-touch enrollment, patching, software distribution, and secure deprovisioning.
  • Endpoint security, Zero Trust architecture, vulnerability management, and compliance controls.

Skills

macOSMDMfleetosquerysantarudolphGitOpsTerraformPythonSwiftGoAWSZero Trustendpoint security

Similar roles

IT Support jobs
Anthropic

IT Support Engineer

AnthropicNew York, NY +1

Provides hands-on technical support for employee devices, SaaS applications, identity systems, and workplace technology in a primarily macOS environment. The role requires 7+ years of IT support experience, strong Google Workspace and Slack administration skills, scripting ability, and a service-oriented approach.

180k – 230k/yrHybrid7+ YOEIT Support
Nerdio

Team Lead, Internal Support

NerdioUnited States

Leads a distributed Internal Support team while overseeing ticket queues, SLAs, coaching, escalations, and process improvement. The role requires 7+ years of IT support or systems administration experience and deep expertise across Microsoft identity, endpoint management, and Microsoft 365.

Salary not listedRemote7+ YOEIT Support
Crusoe

Senior Systems Engineer, IAM Operations

CrusoeSan Francisco, CA

Own day-to-day IAM operations, including Okta administration, user lifecycle automation, SaaS access governance, and Tier 2 escalation support. The role requires 5+ years of systems, IT operations, or IAM experience and strong skills in automation, APIs, and scripting.

165k – 200k/yrOn-site5+ YOEIT Support
Vanta

Senior Manager, Systems Engineering

VantaUnited States

Leads a systems engineering team responsible for identity, endpoint management, ITSM, SaaS procurement, and enterprise AI infrastructure. Requires 8+ years in IT or systems engineering and 3+ years managing and developing engineers.

210k – 247k/yrRemote8+ YOEIT Support
Addepar

Senior IT Support Specialist

AddeparNew York, NY

Provides advanced, on-site IT support across Mac and Windows environments while administering SaaS platforms, endpoint management, networking, and security workflows. Requires 4+ years of corporate IT experience, strong troubleshooting skills, and familiarity with scripting and MDM solutions.

Salary not listedOn-site4+ YOEIT Support