SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 152,000 - 210,000 / annual
Chime, a fintech company, is seeking an experienced Senior Systems Engineer to own the macOS platform and drive endpoint management and device trust standards across the IT ecosystem.
You will drive multi-system initiatives across endpoint management, identity, and security tooling with a primary focus on macOS and Jamf Pro. You'll establish technical standards that other engineers follow and partner cross-functionally with IT Support, Security, and all employees on programs affecting device management and access.
Key responsibilities include:
**macOS Platform & Endpoint Management:**
- Own the technical direction, operation, and continuous improvement of the Jamf Pro environment, including configuration profiles, smart groups, policies, MDM commands, and change standards
- Own the AutoPkg-based software pipeline: recipes, overrides, trust verification, and automated import into Jamf, alongside packaging, deployment, patch management, and disk encryption across the global macOS fleet
- Build automations and shared tooling that accelerate work across the IT organization—scripts, patterns, and integrations other engineers can adopt
- Own zero-touch provisioning and device enrollment (Automated Device Enrollment, Setup Assistant, bootstrap workflows)
- Use scripting and general-purpose languages (Python, Swift, Bash, Go) and vendor APIs to create custom integrations and eliminate manual IT operations
**Security, Governance & Compliance:**
- Partner with Security to identify and mitigate risks to the fleet, enforcing a Zero Trust / BeyondCorp model through device trust, adaptive authentication, and least-privilege access
- Connect device management to the identity provider (Okta) so device posture is a factor in authentication and application access
- Implement compliance processes and tooling to report configuration status and assess benchmark standards (e.g., CIS) against documented, risk-based rationale
- Develop metrics and reporting reflecting the inventory, health, and compliance state of all devices
- Serve as the Tier 3 escalation point for complex endpoint issues
**Standards, Collaboration & Mentorship:**
- Establish and document the endpoint standards the broader IT organization works to, raising the bar on testing, monitoring, and maintainability
- Lead initiatives spanning IT Support, Security, and People teams—reconciling competing priorities and keeping stakeholders aligned from planning through rollout
- Mentor peers, engineers, and technicians through technical guidance, documentation, enablement, and example
- Work with IT Support to identify pain points and implement systemic fixes that reduce ticket load
This role participates in an after-hours/on-call rotation for critical endpoint and device-management issues. Reports to the IT Engineering Manager.
The position offers a hybrid work arrangement with four days per week in the office and Fridays from home for those near an office location.
**Requirements:**
- 8+ years of hands-on experience managing macOS at scale with enterprise MDM (e.g., Jamf Pro, Kandji, Mosyle) and/or open-source tooling (e.g., Munki, Puppet, Chef)
- Production experience building and operating AutoPkg recipes, overrides, trust controls, and automated promotion into an enterprise MDM environment (required)
- In-depth understanding of Apple's MDM protocol and Configuration Profile specifications, including the shift to Declarative Device Management
- In-depth understanding of macOS fundamentals: installers and packages, LaunchDaemons and LaunchAgents, the preferences subsystem, system extensions, macOS built-in security tooling (Endpoint Security Framework, SIP, XProtect, Gatekeeper, openBSM), and unified logs
- Proficiency in at least one general-purpose or scripting language (e.g., Python, Swift, Bash, Go) for API interaction and automation
- Solid understanding of Zero Trust / BeyondCorp concepts and how endpoint posture feeds identity-based access decisions
- Track record of decisions spanning multiple systems, balancing scalability, compliance, cost, and long-term maintainability
- Comfort defining a problem before solving it and aligning stakeholders around a technical direction
- Excellent written and verbal communication for technical and non-technical audiences, including structured documentation that scales understanding across a distributed team
**Nice-to-have:**
- Jamf Certified Admin (300/400) or equivalent demonstrated mastery
- Familiarity with Windows endpoint management (Intune/Endpoint Manager, PowerShell, MSI packaging, WMI, registry)
- Experience with Infrastructure as Code (e.g., Terraform) for managing SaaS and MDM configuration
- Experience with osQuery, CrowdStrike, or comparable endpoint telemetry and EDR tooling
- Experience integrating endpoint management with Okta for device trust and conditional access