Senior Endpoint Security Engineer
$170k - $205k • San Francisco, CA - US • FullTime
Posted 2mo ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This is a strategic, architectural position focused on building secure-by-default endpoints that protect the organization as it scales. You will be responsible for security architecture, endpoint visibility, and maintaining our security posture across a rapidly growing global fleet of macOS, Windows, iOS, and Android devices. This role involves cross-functional partnership with Security and People Operations, with genuine scope to shape how Crusoe manages and secures endpoints.
Responsibilities
- Administer and continuously improve Jamf and Microsoft Intune environments across macOS, Windows, iOS, and Android, including configuration profiles, compliance policies, app deployment, and OS updates.
- Build and maintain automated enrollment workflows using Apple Business Manager (ABM) and Windows Autopilot for zero-touch provisioning.
- Own a structured patch management program with clear SLAs for OS and application updates across all device platforms.
- Define and enforce device compliance baselines aligned with security standards and frameworks (e.g., CIS Benchmarks, SOC 2), integrating MDM telemetry with EDR and SIEM tooling.
- Partner with Security on device trust policies, Conditional Access enforcement, certificate-based authentication rollout, and network-level access control.
- Build and maintain scripts and automation in Bash, Python, or PowerShell to reduce manual IT workload and develop self-service tooling.
- Own MDM runbooks, device policy documentation, and asset records, contributing to standardization across all platforms.
- Serve as the MDM escalation point in the IT on-call rotation and partner with People Operations on device provisioning/deprovisioning.
- Mentor junior IT team members on endpoint management practices.
Requirements
- Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection.
- Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access).
- 3–6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection).
- Proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls.
- Proficiency in Bash, Python, or PowerShell for device policy automation, packaging, and remediation.
- Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence.
- Strong documentation habits and ownership mindset.
- Ability to communicate technical policies to non-technical stakeholders.
- Bachelor’s degree in IT, Computer Science, or equivalent practical experience.
- Expertise in OSQuery and CrowdStrike for endpoint visibility, threat detection, and response.
Benefits
- Competitive compensation and equity packages
- Restricted Stock Units
- Paid time off, paid holidays & leave of absence programs
- Comprehensive health, dental & vision insurance
- Employer contributions to HSA account
- Paid parental leave
- Paid life insurance, short-term and long-term disability
- Professional development & tuition reimbursement
- Mental health & wellness support
- Commuter benefits (parking & transit)
- Cell phone stipend
- 401(k) Retirement plan with company match