IT Client Engineer
full-time
lead
Posted 19 hours ago
Before you apply
Build my evidence-backed draft — free Apply on company site →Paste your relevant resume section or 2–4 true bullets. See supported requirements and honest gaps. No account and no application sent.
About this role
Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It's time to build!
We are looking for a Client Engineer to own Figure's endpoint fleet everywhere it operates: our San Jose campus, our factories, our contract manufacturing partners, and connectivity-challenged field sites. Figure's most valuable asset is the design and software behind our humanoid, and this role is the technical owner of the controls that keep that IP on the devices, in the environments, and in the hands we intend. You will work closely with our Information Security team to define how devices are issued, hardened, monitored, and recovered; what data is allowed to land on them; and how quickly we can detect and cut off exposure when something goes wrong, whether the device sits on the corporate network or offline on a factory floor.
You are also the technical lead for client-side infrastructure company-wide. You will run endpoint management across macOS, Windows 11 Pro, and Ubuntu LTS, own SSO integration and identity lifecycle automation on Okta, and replace manual IT work with code. The ideal candidate is an engineer first and a systems administrator second: someone who responds to a repeated ticket by writing the script that eliminates it, documents the result, and is comfortable owning a security-sensitive program with real business consequences.
Responsibilities
Endpoint Engineering
Own zero-touch enrollment end to end: Apple Business Manager for macOS, Windows Autopilot for Windows, and PXE provisioning for Ubuntu workstations
Translate CIS Benchmarks into deployable configuration profiles across all platforms: deterministically applied settings accompanied with osquery validations to validate posture
Operate FleetDM as the cross-platform management agent across macOS, Windows, and Ubuntu LTS
Maintain standard, reproducible workstation builds with measured and enforced patch compliance
Build hardened device configurations for factories, contract manufacturers, and low-connectivity sites: loaner and clean-device programs, encryption enforcement and escrow, conditional access, and remote wipe and recovery
Deploy and maintain CrowdStrike Falcon coverage across the fleet in partnership with Security, closing gaps on unmanaged or drifted devices
Translate data handling and IP protection requirements from Security, Legal, and Engineering leadership into enforceable technical controls
Identity and SSO Engineering
Own SSO integration of applications into Okta (SAML and OIDC), including internal tools with no vendor documentation
Design application authentication and RBAC from first principles, in coordination with Security
Automate the identity lifecycle end to end: provisioning, entitlement, and deprovisioning driven by Okta Workflows and integrated with Google Workspace, Slack, and Jira
SaaS Operations and Automation
Build tooling in Python, Bash, or PowerShell to eliminate manual work across onboarding, offboarding, provisioning, reporting, and audit
Run license and access audits, surface inactive accounts and orphaned entitlements, and drive cost recovery with Procurement
Formalize change management for endpoint and SaaS changes and participate in the Change Advisory Board
Document standards, runbooks, and automation so the broader IT team can operate and extend what you build
Act as escalation point for complex client-side issues and mentor Operations Specialists
Qualifications
Hands-on experience managing macOS, Windows, and Linux (Ubuntu LTS) endpoint fleets in production
Practical experience with zero-touch enrollment and modern endpoint tooling: FleetDM or comparable osquery-based management, Apple Business Manager, Windows Autopilot or Microsoft Intune
Experience turning security benchmarks (CIS or similar) into enforced, validated configuration policy
Strong scripting skills in Python, Bash, and/or PowerShell, with a track record of replacing manual processes with code
Working knowledge of authentication fundamentals: SAML, OIDC, SCIM, and the tradeoffs between them
Experience administering identity and SaaS platforms at scale: Okta, Google Workspace, Slack, Jira, including SCIM and API-driven provisioning
Sound judgment on security and risk tradeoffs, and the ability to explain technical controls to non-technical stakeholders
Detail-oriented and process-driven, particularly in documenting standards and policy
Great communication, collaboration, and interpersonal skills
Bonus Qualifications
Experience supporting devices or users at manufacturing sites, contract manufacturers, or other high-IP-risk environments
Familiarity with export control, data residency, or IP protection frameworks in hardware and software R&D
Experience with employee-built AI applications: assess authentication and permissions risk, and redirec
Similar Jobs
Related searches:
Get jobs like this delivered weekly
Free AI jobs newsletter. No spam.