Endpoint Engineer, IT

Thinking Machines LabSan Francisco, CA
$190,000 - $300,000Onsite

About The Position

The IT team builds secure infrastructure and efficient processes that enable our employees to move quickly. We operate an all-Mac environment and manage our endpoint fleet as a distributed platform, applying production-engineering practices to device management and security. Our endpoint configurations, security policies, scripts, and software deployments are increasingly managed through version-controlled workflows with testing, review, staged rollouts, and rollback capabilities. This role will work closely with IT, Security, Identity, and Infrastructure to deliver a secure and reliable employee computing experience.

Requirements

  • 8+ years of experience building and operating secure IT or endpoint systems in complex environments.
  • Experience managing a large fleet of macOS devices through a modern MDM platform.
  • Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.
  • Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.
  • Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.
  • Experience using device health and security signals to evaluate endpoint compliance.
  • Experience successfully delivering complex technical projects from conception through production.
  • Strong ability to solve ambiguous problems involving multiple teams and stakeholders.
  • Ability to communicate technical concepts clearly to technical and nontechnical audiences.
  • A product-engineering mindset toward IT systems, including testing, observability, reliability, and controlled change management.
  • A consistent practice of creating clear technical documentation, architecture diagrams, runbooks, and operational procedures.
  • Ability to work from either our New York or San Francisco office.
  • Python and shell scripting.
  • macOS internals, including launchd, configuration profiles, Transparency, Consent, and Control (TCC), system extensions, Endpoint Security, FileVault, Secure Token, and bootstrap tokens.
  • Apple Business Manager, Automated Device Enrollment, and Apple’s MDM and Declarative Device Management frameworks.
  • Modern Apple MDM platforms, particularly Iru, Fleet, Jamf, or equivalent.
  • Santa binary authorization and Rudolph synchronization infrastructure.
  • Fleet-scale querying and osquery.
  • Git, pull-request workflows, GitOps, and CI/CD for endpoint configuration.
  • Terraform and infrastructure as code.
  • Public-cloud fundamentals, including serverless infrastructure, containers, managed databases, and monitoring.
  • Device lifecycle automation, including zero-touch enrollment, patching, software distribution, and secure deprovisioning.
  • Endpoint security, Zero Trust, device trust, continuous posture evaluation, compliance, and automated remediation.

Nice To Haves

  • Experience deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities.
  • Experience leading a production MDM migration, particularly in an environment using Apple Business Manager and Automated Device Enrollment.
  • Experience managing macOS devices with Iru, formerly Kandji.
  • Experience operating Santa at scale, including rule management, binary authorization, event telemetry, and a Rudolph synchronization service.
  • Experience designing device-trust and continuous-posture-evaluation systems that integrate with identity providers, conditional access, or other Zero Trust controls.
  • Experience operating an MDM or device-management platform as a production service rather than only administering a SaaS console.
  • Experience building automated endpoint rollout systems with staging, canary groups, rollback capabilities, and promotion decisions based on telemetry.
  • Experience deploying, operating, or contributing to open-source macOS endpoint-management or security tools.
  • Experience managing endpoint or cloud infrastructure through Terraform or another infrastructure-as-code framework.
  • Experience operating AWS services such as Lambda, API Gateway, DynamoDB, containers, managed databases, and monitoring systems.
  • Proficiency in Swift or Go for building macOS endpoint tools, agents, or supporting services.
  • Experience using LLMs to automate operational work or a strong interest in applying them to endpoint engineering.

Responsibilities

  • Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts.
  • Build code review, staging, canary, validation, and rollback processes into endpoint changes.
  • Operate our MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.
  • Lead the evaluation, design, testing, and execution of our planned migration from Iru to Fleet.
  • Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.
  • Own the architecture and operation of Santa and its Rudolph synchronization service.
  • Manage binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.
  • Partner closely with Security and Identity to make device trust a core component of our Zero Trust architecture.
  • Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.
  • Build systems that continuously evaluate device health and security posture, including MDM enrollment, OS version, patch status, disk encryption, endpoint protection, security-control status, and configuration compliance.
  • Automatically identify and remediate drift or restrict access when a device no longer meets requirements.
  • Build and maintain automated macOS patching workflows that support rapid enforcement timelines while providing a thoughtful employee experience.
  • Design and improve Apple Business Manager and Automated Device Enrollment workflows that turn a new Mac into a secure, fully configured, and productive machine with minimal manual intervention.
  • Own application packaging, deployment, updating, and removal across the Mac fleet.
  • Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.
  • Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.
  • Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.
  • Serve as the escalation point for complex macOS and endpoint-platform issues that cannot be resolved through standard IT support processes.
  • Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.

Benefits

  • generous health, dental, and vision benefits
  • unlimited PTO
  • paid parental leave
  • relocation support as needed
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service