IT Engineering Manager; Endpoint Engineering
Listed on 2026-05-10
-
IT/Tech
Systems Engineer, Cybersecurity -
Engineering
Systems Engineer, Cybersecurity
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
Our Client Platform Engineering (CPE) team owns affirm's endpoint platform end-to-end: from zero-touch provisioning and MDM architecture to patch management, automation pipelines, and compliance posture. We are the team that makes it possible for an affirm anywhere in the world to open a laptop on day one and get straight to work.
We're looking for a hands‑on technical manager to lead the Client Platform Engineering team. This is an engineering‑forward leadership role — you'll set the technical direction, establish the program operating model, and actively develop a team of three engineers (one L5, two L6) who are talented but need a clear owner to drive prioritization, consistency of delivery, and a repeatable way of working.
You will report directly to the Director of IT Engineering and be the first dedicated people leader this team has had in some time. That means you'll be building the program scaffolding largely from scratch: defining how work gets planned and tracked, establishing KPIs that give leadership and partner teams real visibility into health and progress, and creating the operating rhythm that lets your engineers do their best work.
You'll also be a credible technical voice in cross‑functional conversations with Security, Identity, Developer Productivity, and IT Support — able to engage substantively on architecture, tool choices, and tradeoffs without needing to run everything back to your team.
- Lead, coach, and develop a team of three engineers — setting clear expectations, providing regular candid feedback, and building individual growth plans tailored to each engineer’s strengths, gaps, and career goals.
- Establish and maintain healthy team operating rhythms: sprint cadence, backlog grooming, incident retrospectives, and async‑first communication practices that work across time zones.
- Build a culture of ownership, craft, and continuous improvement — where reducing toil and improving reliability is celebrated, not just expected.
- Serve as an escalation point for complex technical issues and a knowledge resource for the broader IT Engineering organization.
- Define and maintain the CPE roadmap in alignment with IT Engineering strategy, company‑wide security priorities, and affirm’s FY roadmap cycles.
- Establish a prioritization framework that balances project work, platform health (KTLO), compliance obligations, and stakeholder requests — with enough transparency that tradeoffs are visible and defensible.
- Build and own the KPIs and reporting that give you, your team, and leadership real visibility into endpoint compliance posture, patch currency, deployment reliability, and incident trends.
- Implement structured change control processes: communication, testing gates, rollback plans, and post‑deployment review for platform changes that affect a global workforce.
- Guide the architecture and long‑term strategy for affirm’s endpoint platform — macOS‑first, with Windows and mobile in scope — including MDM configuration, zero‑touch provisioning, and the automation pipelines that keep the fleet healthy at scale.
- Drive key technical initiatives including permission automation, third‑party patching, silent update delivery, and device lifecycle improvements.
- Champion infrastructure‑as‑code and automation‑first engineering practices across the team — reducing manual toil and creating durable, repeatable processes.
- Evaluate new tooling and approaches, run POCs, and make clear adoption recommendations grounded in security, reliability, and operational efficiency.
- Build strong working relationships with Security, Identity/IAM, Developer Productivity, and IT Support — acting as a reliable partner and technical peer, not just a fulfillment queue.
- Partner with Security to onboard and maintain endpoint security agents (EDR, AV, disk encryption) and enforce least‑privilege policies at scale.
- Represent CPE in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).