Endpoint Engineer, IT
Don't apply into the void.
Most applications for this Thinking Machines Lab role vanish into an ATS. With jobfinder-ai, your agent finds the actual hiring manager or founder behind this opening and sends a tailored email from your own inbox — so a real person reads your pitch and replies. We then follow up until you land on the calendar.
Reach the decision-maker — $5About the role
<div class="content-intro"><p data-pm-slice="1 1 []">Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals. </p> <p>We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.</p></div><h3><strong>About the Team</strong></h3> <p>The IT team builds secure infrastructure and efficient processes that enable our employees to move quickly. We operate an all-Mac environment and manage our endpoint fleet as a distributed platform, applying production-engineering practices to device management and security.</p> <p>Our endpoint configurations, security policies, scripts, and software deployments are increasingly managed through version-controlled workflows with testing, review, staged rollouts, and rollback capabilities. This role will work closely with IT, Security, Identity, and Infrastructure to deliver a secure and reliable employee computing experience.</p> <h3><strong>What You’ll Do</strong></h3> <ul> <li><strong>Endpoint Configuration as Code:</strong> Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts. Build code review, staging, canary, validation, and rollback processes into endpoint changes.</li> <li><strong>MDM Platform Engineering:</strong> Operate our MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.</li> <li><strong>MDM Migration:</strong> Lead the evaluation, design, testing, and execution of our planned migration from Iru to Fleet. Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.</li> <li><strong>Santa and Rudolph:</strong> Own the architecture and operation of Santa and its Rudolph synchronization service. Manage binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.</li> <li><strong>Zero Trust and Device Trust:</strong> Partner closely with Security and Identity to make device trust a core component of our Zero Trust architecture. Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.</li> <li><strong>Continuous Posture Evaluation:</strong> Build systems that continuously evaluate device health and security posture, including MDM enrollment, OS version, patch status, disk encryption, endpoint protection, security-control status, and configuration compliance. Automatically identify and remediate drift or restrict access when a device no longer meets requirements.</li> <li><strong>Patch Management:</strong> Build and maintain automated macOS patching workflows that support rapid enforcement timelines while providing a thoughtful employee experience.</li> <li><strong>Zero-Touch Provisioning:</strong> Design and improve Apple Business Manager and Automated Device Enrollment workflows that turn a new Mac into a secure, fully configured, and productive machine with minimal manual intervention.</li> <li><strong>Software Distribution:</strong> Own application packaging, deployment, updating, and removal across the Mac fleet.</li> <li><strong>Fleet Telemetry and Compliance:</strong> Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.</li> <li><strong>Automation:</strong> Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.</li> <li><strong>Endpoint Security:</strong> Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.</li> <li><strong>Advanced Troubleshooting:</strong> Serve as the escalation point for complex macOS and endpoint-platform issues that cannot be resolved through standard IT support processes.</li> <li><strong>Technical Leadership:</strong> Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.</li> </ul> <h3><strong>Basic Qualifications</strong></h3> <ul> <li>8+ years of experience building and operating secure IT or endpoint systems in complex environments.</li> <li>Experience managing a large fleet of macOS devices through a modern MDM platform.</li> <li>Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.</li> <li>Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.</li> <li>Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.</li> <li>Experience using device health and security signals to evaluate endpoint compliance.</li> <li>Experience successfully delivering complex technical projects from conception through production.</li> <li>Strong ability to solve ambiguous problems involving multiple teams and stakeholders.</li> <li>Ability to communicate technical concepts clearly to technical and nontechnical audiences.</li> <li>A product-engineering mindset toward IT systems, including testing, observability, reliability, and controlled change management.</li> <li>A consistent practice of creating clear technical documentation, architecture diagrams, runbooks, and operational procedures.</li> <li>Ability to work from either our New York or San Francisco office.</li> </ul> <h3><strong>Preferred Qualifications</strong></h3> <ul> <li><strong>Fleet:</strong> Experience deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities.</li> <li><strong>MDM Migration:</strong> Experience leading a production MDM migration, particularly in an environment using Apple Business Manager and Automated Device Enrollment.</li> <li><strong>Iru:</strong> Experience managing macOS devices with Iru, formerly Kandji.</li> <li><strong>Santa and Rudolph:</strong> Experience operating Santa at scale, including rule management, binary authorization, event telemetry, and a Rudolph synchronization service.</li> <li><strong>Zero Trust:</strong> Experience designing device-trust and continuous-posture-evaluation systems that integrate with identity providers, conditional access, or other Zero Trust controls.</li> <li><strong>MDM as a Service:</strong> Experience operating an MDM or device-management platform as a production service rather than only administering a SaaS console.</li> <li><strong>Progressive Delivery:</strong> Experience building automated endpoint rollout systems with staging, canary groups, rollback capabilities, and promotion decisions based on telemetry.</li> <li><strong>Open-Source Tooling:</strong> Experience deploying, operating, or contributing to open-source macOS endpoint-management or security tools.</li> <li><strong>Infrastructure as Code:</strong> Experience managing endpoint or cloud infrastructure through Terraform or another infrastructure-as-code framework.</li> <li><strong>Cloud Infrastructure:</strong> Experience operating AWS services such as Lambda, API Gateway, DynamoDB, containers, managed databases, and monitoring systems.</li> <li><strong>Endpoint Development:</strong> Proficiency in Swift or Go for building macOS endpoint tools, agents, or supporting services.</li> <li><strong>AI-Assisted Operations:</strong> Experience using LLMs to automate operational work or a strong interest in applying them to endpoint engineering.</li> </ul> <h3><strong>Technical Skills</strong></h3> <ul> <li>Python and shell scripting.</li> <li>macOS internals, including launchd, configuration profiles, Transparency, Consent, and Control (TCC), system extensions, Endpoint Security, FileVault, Secure Token, and bootstrap tokens.</li> <li>Apple Business Manager, Automated Device Enrollment, and Apple’s MDM and Declarative Device Management frameworks.</li> <li>Modern Apple MDM platforms, particularly Iru, Fleet, Jamf, or equivalent.</li> <li>Santa binary authorization and Rudolph synchronization infrastructure.</li> <li>Fleet-scale querying and osquery.</li> <li>Git, pull-request workflows, GitOps, and CI/CD for endpoint configuration.</li> <li>Terraform and infrastructure as code.</li> <li>Public-cloud fundamentals, including serverless infrastructure, containers, managed databases, and monitoring.</li> <li>Device lifecycle automation, including zero-touch enrollment, patching, software distribution, and secure deprovisioning.</li> <li>Endpoint security, Zero Trust, device trust, continuous posture evaluation, compliance, and automated remediation.</li> </ul> <h2>Logistics</h2> <ul> <li>Location: This role is based in San Francisco, California or New York, New York. </li> <li>Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $190,000 - $300,000.</li> <li>Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.</li> <li>Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.</li> <li>As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.</li> </ul><div class="content-conclusion"><p><em>As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law. </em></p> <p><em>Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.</em></p></div>
Ready to reach the decision-maker?
Set this role as a target and your agent does the sourcing, finds the verified email, writes the pitch, and follows up — on autopilot.
Start your hunt