Endpoint Engineer, IT

Thinking Machines LabSan Francisco, CA
$190,000 - $300,000Onsite

About The Position

Thinking Machines Lab is seeking an Endpoint Engineer to join their IT team. The IT team is responsible for building secure infrastructure and efficient processes to enable employees to work quickly. They operate in an all-Mac environment and manage their endpoint fleet as a distributed platform, applying production-engineering practices to device management and security. This role will collaborate with IT, Security, Identity, and Infrastructure to ensure a secure and reliable employee computing experience. The position involves managing endpoint configurations, security policies, scripts, and software deployments through version-controlled workflows with testing, review, staged rollouts, and rollback capabilities.

Requirements

  • 8+ years of experience building and operating secure IT or endpoint systems in complex environments.
  • Experience managing a large fleet of macOS devices through a modern MDM platform.
  • Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.
  • Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.
  • Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.
  • Experience using device health and security signals to evaluate endpoint compliance.
  • Experience successfully delivering complex technical projects from conception through production.
  • Strong ability to solve ambiguous problems involving multiple teams and stakeholders.
  • Ability to communicate technical concepts clearly to technical and nontechnical audiences.
  • A product-engineering mindset toward IT systems, including testing, observability, reliability, and controlled change management.
  • A consistent practice of creating clear technical documentation, architecture diagrams, runbooks, and operational procedures.
  • Ability to work from either our New York or San Francisco office.
  • Python and shell scripting.
  • macOS internals, including launchd, configuration profiles, Transparency, Consent, and Control (TCC), system extensions, Endpoint Security, FileVault, Secure Token, and bootstrap tokens.
  • Apple Business Manager, Automated Device Enrollment, and Apple’s MDM and Declarative Device Management frameworks.
  • Modern Apple MDM platforms, particularly Iru, Fleet, Jamf, or equivalent.
  • Santa binary authorization and Rudolph synchronization infrastructure.
  • Fleet-scale querying and osquery.
  • Git, pull-request workflows, GitOps, and CI/CD for endpoint configuration.
  • Terraform and infrastructure as code.
  • Public-cloud fundamentals, including serverless infrastructure, containers, managed databases, and monitoring.
  • Device lifecycle automation, including zero-touch enrollment, patching, software distribution, and secure deprovisioning.
  • Endpoint security, Zero Trust, device trust, continuous posture evaluation, compliance, and automated remediation.

Nice To Haves

  • Experience deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities.
  • Experience leading a production MDM migration, particularly in an environment using Apple Business Manager and Automated Device Enrollment.
  • Experience managing macOS devices with Iru, formerly Kandji.
  • Experience operating Santa at scale, including rule management, binary authorization, event telemetry, and a Rudolph synchronization service.
  • Experience designing device-trust and continuous-posture-evaluation systems that integrate with identity providers, conditional access, or other Zero Trust controls.
  • Experience operating an MDM or device-management platform as a production service rather than only administering a SaaS console.
  • Experience building automated endpoint rollout systems with staging, canary groups, rollback capabilities, and promotion decisions based on telemetry.
  • Experience deploying, operating, or contributing to open-source macOS endpoint-management or security tools.
  • Experience managing endpoint or cloud infrastructure through Terraform or another infrastructure-as-code framework.
  • Experience operating AWS services such as Lambda, API Gateway, DynamoDB, containers, managed databases, and monitoring systems.
  • Proficiency in Swift or Go for building macOS endpoint tools, agents, or supporting services.
  • Experience using LLMs to automate operational work or a strong interest in applying them to endpoint engineering.

Responsibilities

  • Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts.
  • Build code review, staging, canary, validation, and rollback processes into endpoint changes.
  • Operate the MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.
  • Lead the evaluation, design, testing, and execution of the migration from Iru to Fleet.
  • Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.
  • Own the architecture and operation of Santa and its Rudolph synchronization service, including managing binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.
  • Partner closely with Security and Identity to make device trust a core component of the Zero Trust architecture.
  • Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.
  • Build systems that continuously evaluate device health and security posture.
  • Automatically identify and remediate drift or restrict access when a device no longer meets requirements.
  • Build and maintain automated macOS patching workflows.
  • Design and improve Apple Business Manager and Automated Device Enrollment workflows.
  • Own application packaging, deployment, updating, and removal across the Mac fleet.
  • Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.
  • Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.
  • Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.
  • Serve as the escalation point for complex macOS and endpoint-platform issues.
  • Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.

Benefits

  • generous health, dental, and vision benefits
  • unlimited PTO
  • paid parental leave
  • relocation support as needed
  • Visa sponsorship
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service