Apple/macOS Subject Matter Expert (Computer Engineering, Senior Associate)

The MIL Corporation

Washington (District of Columbia)

On-site

USD 131,000 - 145,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, life, and disability insurance
Paid time off
Tuition assistance
Professional growth opportunities

Job summary

The MIL Corporation is hiring an Apple/macOS Subject Matter Expert to provide advanced engineering support for managing macOS devices. The role focuses on strengthening endpoint security and ensuring compliance across macOS platforms. This on-site position requires a strong background in IT and cybersecurity.

The job includes responsibilities such as workstation imaging, patch management, and documentation. Key qualifications include 10+ years in the field and expertise in tools like JAMF Pro. A Bachelor's degree in IT or Cybersecurity is required.

Qualifications

  • 10+ years of professional work experience.
  • 8+ years in IT, endpoint engineering, or cybersecurity.
  • 6+ years performing engineering functions in enterprise environments.

Responsibilities

  • Design, build, maintain macOS workstation images.
  • Engineer macOS OS/application patching and version control.
  • Implement macOS enrollment workflows using Apple Business Manager.

Skills

macOS workstation image building
macOS patching and config management
Security governance
Change control discipline
Documentation and knowledge transfer
Forensic collection procedures

Education

Bachelor's degree in IT or Cybersecurity

Tools

Ivanti
JAMF Pro
KACE

Job description

Summary

The MIL Corporation is looking for an Apple/macOS Subject Matter Expert (Computer Engineering, Senior Associate). The Apple/macOS SME provides advanced engineering support for securing, configuring, imaging, patching, and managing macOS devices across the enterprise. This role focuses on designing, implementing, and maintaining technical controls that strengthen endpoint security, support device lifecycle operations, and ensure compliance across macOS platforms. The SME operates in a highly governed environment requiring change control discipline, detailed documentation, and collaboration with Service Desk Engineering, IAM, SOC, and Cybersecurity teams.

This position currently requires an on-site schedule. Schedule is subject to change based on company/contract requirements.

This position is currently unfunded and is being posted in anticipation of a future contract award and funding approval. We are proactively identifying and engaging with qualified candidates. While candidates may be contacted for pre-screening, any hiring decisions will be contingent upon funding availability and final program requirements or client approval.

Responsibilities
macOS Workstation Imaging & Baseline Engineering
  • Design, build, maintain, and secure standard macOS workstation images for onsite and remote/VDI use, ensuring alignment with approved baseline security controls.
  • Integrate macOS images with VDI clients, EDR agents, authentication mechanisms, and logging agents.
  • Maintain version control, image-release processes, validation steps, and rollback procedures for macOS workstation images.
  • Perform postimage validation testing (connectivity, authentication, app compatibility, security agents).
macOS Patch, Configuration, and Compliance Management
  • Engineer and maintain macOS OS/application patching, version control, and lifecycle management using tools such as Ivanti, KACE, or JAMF.
  • Remediate configuration drift and ensure compliance against secure macOS baseline standards.
  • Document macOS baseline configurations, deployment workflows, and compliance remediation paths.
macOS Device Enrollment & Provisioning
  • Implement and maintain macOS enrollment workflows using Apple Business Manager and JAMF Pro.
  • Enforce secure provisioning, conditional access posture, and baseline profile application before network access.
  • Support lifecycle operations: provisioning, reassignment, decommissioning, secure wipe, and FileVault recovery key escrow.
  • Ensure accurate macOS asset inventory, ownership mapping, and lifecycle visibility.
Logging, Monitoring, Telemetry & Audit Engineering (macOS Focus)
  • Configure macOS Unified Logs, endpoint agents, and log forwarding to SIEM/EDR platforms.
  • Ensure telemetry health, audit coverage, and reliable ingestion of macOS security-relevant events.
  • Support forensic collection procedures and maintain audit trails for macOS configuration changes and remediation actions.
Security Engineering for macOS Endpoints
  • Design/implement controls to prevent initial compromise, lateral movement, and persistence mechanisms on macOS devices.
  • Implement secure authentication, including passwordless methods and hardware-backed credentials (e.g., YubiKey, CAC, software-based keys).
  • Strengthen device enrollment, identity linkage, and endpoint visibility across macOS environments.
Documentation, Knowledge Transfer & Engineering Support
  • Develop macOS runbooks for imaging, patching, enrollment troubleshooting, validation, and remediation.
  • Maintain a versioned knowledge base covering macOS baselines, automation, and recovery procedures.
  • Conduct training for Service Desk, IAM, and SOC teams to ensure operational sustainability.
Required Qualifications
  • 10+ years of professional work experience
  • 8+ years in IT, endpoint engineering, or cybersecurity.
  • 6+ years performing engineering (not help desk) functions in enterprise environments.
  • Experience working under strict change control, security governance, and audit processes.
  • Extensive experience building and maintaining macOS workstation images (including automation, validation, rollback, version control).
  • Hands-on experience with macOS patching and config management using Ivanti, KACE, and especially JAMF Pro.
  • Experience with Apple Business Manager, FileVault key escrow, and macOS provisioning workflows.
  • Ability to configure macOS endpoint logging and telemetry ingestion into SIEM/EDR platforms.
  • Familiarity with passwordless authentication, YubiKeys, CAC, and hardware-backed identity mechanisms for macOS.
Desired Qualifications
  • Hands-on experience developing automation for macOS (e.g., JAMF scripting, Python, Zsh, or shell-based automation for imaging, patching, and compliance workflows).
  • Prior experience designing or operating macOS telemetry pipelines, including log normalization strategies for SIEM/EDR platforms (e.g., Sentinel, Splunk, CrowdStrike).
  • Familiarity with Apple enterprise ecosystem integrations, such as Apple Business Manager advanced workflows, MDM-driven zero-touch deployments, and certificate-based network access on macOS.
  • Experience supporting mixed-OS environments (macOS + Windows) with an emphasis on contributing macOS-focused engineering recommendations that improve overall enterprise endpoint posture.
Education

Bachelor's degree in IT, Cybersecurity, or related field (or equivalent experience).

Clearance

Active Top Secret (TS) clearance.

Compensation

The MIL Corporation values your contributions and offers a range of benefits to support your overall well-being. We are pleased to offer a comprehensive range of benefits to our full-time employees which include health, life, disability, and retirement plans, as well as paid time off, opportunities for professional growth and tuition assistance. Additional benefits and incentives may also apply, which will be communicated during the hiring process. For this position, the projected compensation range is $131,000 - $145,000 per year. This estimate represents the typical salary range and is just one part of MIL's complete compensation package. Final salary for this position is determined based on factors such as individual qualifications, education, experience, and contractual limitations. Learn more on the MIL Careers page.

Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by state or federal law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Apple/macOS Subject Matter Expert (Computer Engineering, Senior Associate)
Apple/macOS Subject Matter Expert (Computer Engineering, Senior Associate)

RPMGlobal • Washington

On-site
USD 131,000 - 145,000
Health insurance
Paid time off
Tuition assistance
+1
Apple/macOS SME
Apple/macOS SME

Digital Management Llc • United States

On-site
USD 100,000 - 130,000
MAC OS Engineer Team Lead
MAC OS Engineer Team Lead

Njvc LLC • Arlington (VA)

On-site
USD 131,000 - 178,000
MacOS Endpoint Engineer - Imaging, Patch & Security
MacOS Endpoint Engineer - Imaging, Patch & Security

The MIL Corporation • Washington

On-site
USD 131,000 - 145,000
Health, life, and disability insurance
Paid time off
Tuition assistance
+1
Senior Microsoft Cloud Engineer (Computer Engineering, Senior Associate)
Senior Microsoft Cloud Engineer (Computer Engineering, Senior Associate)

RPMGlobal • Washington

On-site
USD 195,000 - 215,000
Health benefits
Retirement plans
Tuition assistance
+1
Offensive Security Engineer, Advanced (Security Engineering, Senior Associate)
Offensive Security Engineer, Advanced (Security Engineering, Senior Associate)

RPMGlobal • Lexington Park (MD)

On-site
USD 130,000 - 193,000
Endpoint Engineer, IT
Endpoint Engineer, IT

Socket.dev • New York (NY), San Francisco (CA)

On-site
USD 190,000 - 300,000
Health, dental & vision
Unlimited PTO
Parental leave
+1
MAC OS Engineer Team Lead
MAC OS Engineer Team Lead

Chenega MIOS SBU • Arlington (VA)

On-site
USD 131,000 - 178,000
Endpoint Engineer, IT
Endpoint Engineer, IT

Thinking Machines Lab • New York (NY), San Francisco (CA)

On-site
USD 190,000 - 300,000
Health, dental & vision insurance
Unlimited PTO
Paid parental leave
+1
Senior Mac Endpoint Engineer
Senior Mac Endpoint Engineer

Brooksource • Detroit (MI)

On-site
USD 110,000 - 160,000
Competitive benefits
401k with company match
Paid time off
+1