Senior Security Engineer, Endpoint
Architect endpoint security posture for macOS, Windows, and mobile fleets at Ramp. Build MDM policies as code with Terraform/GitOps, automate patching and software distribution, mine telemetry for detections, and shape security for an agentic AI future. Requires deep macOS/MDM experience and strong IaC skills.
About the job
What You’ll Do
- Write and ship MDM policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS, Windows, and mobile — with staged rollouts and rollback from day one
- Build patch automation that closes exposure windows fast without making employees' lives worse
- Manage software distribution across the fleet
- Mine fleet telemetry for signal — build dashboards, drift alerts, and AI-assisted automation that cuts toil before it compounds
- Own managed browser and extension policy: enforce what's allowed, block what isn't, and keep the control plane auditable as the surface grows
- Be the last line of defense on endpoint escalations that IT Operations can't crack
What You Need
- Deep macOS security experience — Jamf Pro, FleetDM, or equivalent MDM at scale
- Strong IaC fundamentals and a GitOps delivery model — Terraform modules, remote state, and CI pipelines shipped through MRs and code review, not tickets and manual steps
- Solid working knowledge of Google Workspace in a managed enterprise environment, including Chrome Browser Cloud Management and extension policy enforcement
- A point of view on how agentic AI changes the corporate security surface
Nice-to-Haves
- Have shipped real work with open source endpoint and device management tooling
- Have built automated, progressive rollout systems based on fleet telemetry
- Have managed a mixed fleet — macOS, Windows, and mobile — with real depth on at least one platform
- Have put AI to work on real operational problems, not just prototyped
Benefits
- Flexible PTO
- Unlimited AI token usage
- Centralized home-office equipment ordering
- Health and wellness stipend
- Budget for intra-office travel
- Weekly coffee stipend
- 100% medical, dental & vision insurance coverage (US)
- 401(k) with employer match
- Fertility HRA (up to $10,000 per year)
- Parental leave: up to 16 weeks at 100% pay
- Pet insurance
- In-office perks: lunch, snacks, drinks
- Relocation support to NYC or SF
Skills
Macos Security, MDM, Jamf Pro, Fleetdm, Terraform, GitOps, Iac, Google Workspace, Chrome Browser Cloud Management, Endpoint Security, Patch Management, Telemetry Analysis
Similar jobs
Security Engineering jobsBuild and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.