About the TeamThe IT team builds secure infrastructure and efficient processes that enable our employees to move quickly. We operate an all-Mac environment and manage our endpoint fleet as a distributed platform, applying production-engineering practices to device management and security.
Our endpoint configurations, security policies, scripts, and software deployments are increasingly managed through version-controlled workflows with testing, review, staged rollouts, and rollback capabilities. This role will work closely with IT, Security, Identity, and Infrastructure to deliver a secure and reliable employee computing experience.
What You'll Do- Endpoint Configuration as Code: Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts. Build code review, staging, canary, validation, and rollback processes into endpoint changes.
- MDM Platform Engineering: Operate our MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.
- MDM Migration: Lead the evaluation, design, testing, and execution of our planned migration from Iru to Fleet. Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.
- Santa and Rudolph: Own the architecture and operation of Santa and its Rudolph synchronization service. Manage binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.
- Zero Trust and Device Trust: Partner closely with Security and Identity to make device trust a core component of our Zero Trust architecture. Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.
- Continuous Posture Evaluation: Build systems that continuously evaluate device health and security posture, including MDM enrollment, OS version, patch status, disk encryption, endpoint protection, security-control status, and configuration compliance. Automatically identify and remediate drift or restrict access when a device no longer meets requirements.
- Patch Management: Build and maintain automated macOS patching workflows that support rapid enforcement timelines while providing a thoughtful employee experience.
- Zero-Touch Provisioning: Design and improve Apple Business Manager and Automated Device Enrollment workflows that turn a new Mac into a secure, fully configured, and productive machine with minimal manual intervention.
- Software Distribution: Own application packaging, deployment, updating, and removal across the Mac fleet.
- Fleet Telemetry and Compliance: Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.
- Automation: Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.
- Endpoint Security: Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.
- Advanced Troubleshooting: Serve as the escalation point for complex macOS and endpoint-platform issues that cannot be resolved through standard IT support processes.
- Technical Leadership: Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.
Basic Qualifications- 8+ years of experience building and operating secure IT or endpoint systems in complex environments.
- Experience managing a large fleet of macOS devices through a modern MDM platform.
- Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.
- Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.
- Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.
- Experience using device health and security signals to evaluate endpoint compliance.
- Experience successfully delivering complex technical projects from conception through production.
- Strong ability to solve ambiguous problems involving multiple teams and stakeholders.
- Ability to communicate technical concepts clearly to technical and nontechnical audiences.
- A product-engineering mindset toward IT systems, including testing, observability, reliability, and controlled change management.
- A consistent practice of creating clear technical documentation, architecture diagrams, runbooks, and operational procedures.
- Ability to work from either our New York or San Francisco office.
Preferred Qualifications- Fleet: Experience deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities.
- MDM Migration: Experience leading a production MDM migration, particularly in an environment using Apple Business Manager and Automated Device Enrollment.
- Iru: Experience managing macOS devices with Iru, formerly Kandji.
- Santa and Rudolph: Experience operating Santa at scale, including rule management, binary authorization, event telemetry, and a Rudolph synchronization service.
- Zero Trust: Experience designing device-trust and continuous-posture-evaluation systems that integrate with identity providers, conditional access, or other Zero Trust controls.
- MDM as a Service: Experience operating an MDM or device-management platform as a production service rather than only administering a SaaS console.
- Progressive Delivery: Experience building automated endpoint rollout systems with staging, canary groups, rollback capabilities, and promotion decisions based on telemetry.
- Open-Source Tooling: Experience deploying, operating, or contributing to open-source macOS endpoint-management or security tools.
- Infrastructure as Code: Experience managing endpoint or cloud infrastructure through Terraform or another infrastructure-as-code framework.
- Cloud Infrastructure: Experience operating AWS services such as Lambda, API Gateway, DynamoDB, containers, managed databases, and monitoring systems.
- Endpoint Development: Proficiency in Swift or Go for building macOS endpoint tools, agents, or supporting services.
- AI-Assisted Operations: Experience using LLMs to automate operational work or a strong interest in applying them to endpoint engineering.
Technical Skills- Python and shell scripting.
- macOS internals, including launchd, configuration profiles, Transparency, Consent, and Control (TCC), system extensions, Endpoint Security, FileVault, Secure Token, and bootstrap tokens.
- Apple Business Manager, Automated Device Enrollment, and Apple's MDM and Declarative Device Management frameworks.
- Modern Apple MDM platforms, particularly Iru, Fleet, Jamf, or equivalent.
- Santa binary authorization and Rudolph synchronization infrastructure.
- Fleet-scale querying and osquery.
- Git, pull-request workflows, GitOps, and CI/CD for endpoint configuration.
- Terraform and infrastructure as code.
- Public-cloud fundamentals, including serverless infrastructure, containers, managed databases, and monitoring.
- Device lifecycle automation, including zero-touch enrollment, patching, software distribution, and secure deprovisioning.
- Endpoint security, Zero Trust, device trust, continuous posture evaluation, compliance, and automated remediation.
Logistics- Location: This role is based in San Francisco, California or New York, New York.
- Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $190,000 - $300,000.
- Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
- Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.