More jobs:
Endpoint Security Engineer
Job in
San Francisco, San Francisco County, California, 94199, USA
Listed on 2026-07-18
Listing for:
Crusoe Energy Systems
Full Time
position Listed on 2026-07-18
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Job Description & How to Apply Below
Responsibilities
- Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility
- This is a strategic, architectural position focused on building secure-by-default endpoints that protect the organization as it scales
- You will be responsible for security architecture, endpoint visibility, and maintaining our security posture across a rapidly growing global fleet of macOS, Windows, iOS, and Android devices
- This role involves cross-functional partnership with Security and People Operations, with genuine scope to shape how Crusoe manages and secures endpoints
- Administer and continuously improve Jamf and Microsoft Intune environments across all managed device types: macOS, Windows, iOS, and Android; maintain configuration profiles, compliance policies, app deployment packages, and OS update enforcement across all platforms
- Build and maintain automated enrollment workflows including Apple Business Manager (ABM) and Windows Autopilot for zero-touch provisioning at scale
- Own a structured patch management program with clear SLAs for OS and application updates across all device platforms
- Define and enforce device compliance baselines aligned with Crusoe security standards and frameworks including CIS Benchmarks and SOC 2; integrate MDM telemetry with EDR and SIEM tooling for compliance drift visibility and proactive remediation
- Partner with Security on device trust policies, Conditional Access enforcement, certificate-based authentication rollout (SCEP/PKCS), and network-level access control for certificate-based Wi-Fi and VPN authentication
- Build and maintain scripts and automation in Bash, Python, or Power Shell to reduce manual IT workload; develop self-service tooling that puts routine fixes and software requests directly in employees’ hands
- Own MDM runbooks, device policy documentation, and asset records; contribute to the standardization of enrollment workflows, naming conventions, and configuration baselines across all platforms
- Serve as the MDM escalation point in the IT on-call rotation; partner with People Operations on seamless device provisioning and deprovisioning; mentor junior IT team members on endpoint management practices
- Health & wellbeing:
Comprehensive health benefits designed to support your overall wellness - Time away:
Paid time off for vacations, family bonding, and unexpected needs - 401(k) match:
Build your financial future with our 401(k) matching program - Mental wellness:
Resources and support for your emotional wellbeing and navigating life’s challenges
- Foundational Security
Experience:
Demonstrated experience with OSQuery and Crowd Strike (XDR/EDR) for endpoint visibility and threat detection - Independent Engineering: A “Security-First” mindset and proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls
- Scripting & Automation:
Proficiency in Bash, Python, or Power Shell for device policy automation, packaging, and remediation - Bachelor’s degree in IT, Computer Science, or equivalent practical experience
- Strong documentation habits, ownership mindset, and ability to communicate technical policies to non-technical stakeholders
- Infrastructure Knowledge:
Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence - Identity & Access Management:
Deep understanding of Okta (Device Trust/Fast Pass) and Entra (Conditional Access) - OSQuery and Crowd Strike expertise, demonstrable experience leveraging OSQuery for endpoint visibility and administering Crowd Strike for threat detection and response; these are foundational to our security visibility and enforcement strategy
- MDM/Endpoint Management: 3–6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection)
- Jamf Pro administration experience:
Smart Groups, configuration profiles, and Jamf Connect or equivalent SSO integration - Experience with Jamf Protect, Microsoft Defender for Endpoint, or equivalent EDR tooling
- Familiarity with Linux endpoint management via Fleet, Puppet, or similar
- Exposure to SIEM tooling and endpoint log pipelines
- Apple Certified Support Professional (ACSP) or equivalent MDM certification
- Experience at a high-growth technology company through a period of rapid headcount scaling
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×