Endpoint Engineer, IT
full-time
lead
Posted 15 hours ago
Apply Now
Stand out: build a proof-of-work pitch →
Free GitHub-based preview. Direct apply stays one click away.
Get weekly job alerts like this →Hiring for this role?
AI Market Demand Pack · $29 one-time
Compare this role's skills with the full AI hiring market. Get ranked demand, salary bands, leading companies, public source URLs, and a decision brief.
About this role
Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.
We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.
About the Team
The IT team builds secure infrastructure and efficient processes that enable our employees to move quickly. We operate an all-Mac environment and manage our endpoint fleet as a distributed platform, applying production-engineering practices to device management and security.
Our endpoint configurations, security policies, scripts, and software deployments are increasingly managed through version-controlled workflows with testing, review, staged rollouts, and rollback capabilities. This role will work closely with IT, Security, Identity, and Infrastructure to deliver a secure and reliable employee computing experience.
What You’ll Do
Endpoint Configuration as Code: Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts. Build code review, staging, canary, validation, and rollback processes into endpoint changes.
MDM Platform Engineering: Operate our MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.
MDM Migration: Lead the evaluation, design, testing, and execution of our planned migration from Iru to Fleet. Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.
Santa and Rudolph: Own the architecture and operation of Santa and its Rudolph synchronization service. Manage binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.
Zero Trust and Device Trust: Partner closely with Security and Identity to make device trust a core component of our Zero Trust architecture. Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.
Continuous Posture Evaluation: Build systems that continuously evaluate device health and security posture, including MDM enrollment, OS version, patch status, disk encryption, endpoint protection, security-control status, and configuration compliance. Automatically identify and remediate drift or restrict access when a device no longer meets requirements.
Patch Management: Build and maintain automated macOS patching workflows that support rapid enforcement timelines while providing a thoughtful employee experience.
Zero-Touch Provisioning: Design and improve Apple Business Manager and Automated Device Enrollment workflows that turn a new Mac into a secure, fully configured, and productive machine with minimal manual intervention.
Software Distribution: Own application packaging, deployment, updating, and removal across the Mac fleet.
Fleet Telemetry and Compliance: Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.
Automation: Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.
Endpoint Security: Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.
Advanced Troubleshooting: Serve as the escalation point for complex macOS and endpoint-platform issues that cannot be resolved through standard IT support processes.
Technical Leadership: Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.
Basic Qualifications
8+ years of experience building and operating secure IT or endpoint systems in complex environments.
Experience managing a large fleet of macOS devices through a modern MDM platform.
Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.
Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.
Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.
Experience using device health and security signals to evaluate endpoint compliance.
Experience successfully delivering complex technical projects from conception through production.
Strong ability to solve ambiguous problems involving multiple teams and stakeholders.
Ability to communicate
Similar Jobs
Related searches:
On-site Jobs
Lead Jobs
On-site Lead Jobs
Lead Backend & SystemsLead Machine LearningLead NLP & Language AILead AI Infrastructure
AI Jobs in San Francisco
Backend & Systems in San FranciscoMachine Learning in San FranciscoNLP & Language AI in San FranciscoAI Infrastructure in San Francisco
cloudpytorchapi-designllm
Get jobs like this delivered weekly
Free AI jobs newsletter. No spam.