Senior Endpoint Security Engineer

$170k - $205k San Francisco, CA - US FullTime

Posted 2mo ago

Job Location

San Francisco, CA - US

Tech Stack

Remote Work Policy

On-site

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This is a strategic, architectural position focused on building secure-by-default endpoints that protect the organization as it scales. You will be responsible for security architecture, endpoint visibility, and maintaining our security posture across a rapidly growing global fleet of macOS, Windows, iOS, and Android devices. This role involves cross-functional partnership with Security and People Operations, with genuine scope to shape how Crusoe manages and secures endpoints.

Responsibilities

  • Administer and continuously improve Jamf and Microsoft Intune environments across macOS, Windows, iOS, and Android, including configuration profiles, compliance policies, app deployment, and OS updates.
  • Build and maintain automated enrollment workflows using Apple Business Manager (ABM) and Windows Autopilot for zero-touch provisioning.
  • Own a structured patch management program with clear SLAs for OS and application updates across all device platforms.
  • Define and enforce device compliance baselines aligned with security standards and frameworks (e.g., CIS Benchmarks, SOC 2), integrating MDM telemetry with EDR and SIEM tooling.
  • Partner with Security on device trust policies, Conditional Access enforcement, certificate-based authentication rollout, and network-level access control.
  • Build and maintain scripts and automation in Bash, Python, or PowerShell to reduce manual IT workload and develop self-service tooling.
  • Own MDM runbooks, device policy documentation, and asset records, contributing to standardization across all platforms.
  • Serve as the MDM escalation point in the IT on-call rotation and partner with People Operations on device provisioning/deprovisioning.
  • Mentor junior IT team members on endpoint management practices.

Requirements

  • Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection.
  • Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access).
  • 3–6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection).
  • Proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls.
  • Proficiency in Bash, Python, or PowerShell for device policy automation, packaging, and remediation.
  • Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence.
  • Strong documentation habits and ownership mindset.
  • Ability to communicate technical policies to non-technical stakeholders.
  • Bachelor’s degree in IT, Computer Science, or equivalent practical experience.
  • Expertise in OSQuery and CrowdStrike for endpoint visibility, threat detection, and response.

Benefits

  • Competitive compensation and equity packages
  • Restricted Stock Units
  • Paid time off, paid holidays & leave of absence programs
  • Comprehensive health, dental & vision insurance
  • Employer contributions to HSA account
  • Paid parental leave
  • Paid life insurance, short-term and long-term disability
  • Professional development & tuition reimbursement
  • Mental health & wellness support
  • Commuter benefits (parking & transit)
  • Cell phone stipend
  • 401(k) Retirement plan with company match

About crusoe

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.