IT Client Engineer

Figure-

San Jose (CA)

On-site

USD 120,000 - 180,000

Full time

26 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Figure, a San Jose based AI robotics company, seeks a Client Engineer to own the endpoint fleet across campus, factories, and field sites. You’ll lead zero-touch enrollment, enforce CIS-aligned configurations, and operate FleetDM across macOS, Windows, and Ubuntu, while partnering with Security to protect IP and data.

The role emphasizes coding over manual IT work—building scripts in Python, Bash, or PowerShell to automate onboarding, offboarding, provisioning, and audits.

Qualifications

  • Hands-on experience managing macOS, Windows, and Linux (Ubuntu LTS) endpoint fleets in production.
  • Experience with zero-touch enrollment and endpoint tooling: FleetDM or comparable osquery-based management, Apple Business Manager, Windows Autopilot or Microsoft Intune.
  • Experience turning security benchmarks into enforceable, validated configuration policy.
  • Strong scripting skills in Python, Bash, and/or PowerShell, with a track record of replacing manual processes with code.
  • Working knowledge of authentication fundamentals: SAML, OIDC, SCIM, and the tradeoffs between them.
  • Experience administering identity and SaaS platforms at scale: Okta, Google Workspace, Slack, Jira, including SCIM and API-driven provisioning.
  • Sound judgment on security and risk tradeoffs, and the ability to explain technical controls to non-technical stakeholders.
  • Detail-oriented and process-driven, particularly in documenting standards and policy.
  • Great communication, collaboration, and interpersonal skills.

Responsibilities

  • Own zero-touch enrollment end to end: Apple Business Manager for macOS, Windows Autopilot for Windows, and PXE provisioning for Ubuntu workstations.
  • Translate CIS Benchmarks into deployable configuration profiles across all platforms: deterministically applied settings accompanied with osquery validations to validate posture.
  • Operate FleetDM as the cross-platform management agent across macOS, Windows, and Ubuntu LTS.
  • Maintain standard, reproducible workstation builds with measured and enforced patch compliance.
  • Build hardened device configurations for factories, contract manufacturers, and low-connectivity sites: loaner and clean-device programs, encryption enforcement and escrow, conditional access, and remote wipe and recovery.
  • Deploy and maintain CrowdStrike Falcon coverage across the fleet in partnership with Security, closing gaps on unmanaged or drifted devices.
  • Translate data handling and IP protection requirements from Security, Legal, and Engineering leadership into enforceable technical controls.

Skills

macOS fleet
Windows fleet
Ubuntu Linux
FleetDM
Okta SSO
SAML/OIDC
PowerShell
Python

Tools

Apple Business Manager
Windows Autopilot
PXE provisioning
CrowdStrike Falcon
Google Workspace
Slack
Jira

Job description

Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It's time to build!

We are looking for a Client Engineer to own Figure's endpoint fleet everywhere it operates: our San Jose campus, our factories, our contract manufacturing partners, and connectivity-challenged field sites. Figure's most valuable asset is the design and software behind our humanoid, and this role is the technical owner of the controls that keep that IP on the devices, in the environments, and in the hands we intend. You will work closely with our Information Security team to define how devices are issued, hardened, monitored, and recovered; what data is allowed to land on them; and how quickly we can detect and cut off exposure when something goes wrong, whether the device sits on the corporate network or offline on a factory floor.

You are also the technical lead for client-side infrastructure company-wide. You will run endpoint management across macOS, Windows 11 Pro, and Ubuntu LTS, own SSO integration and identity lifecycle automation on Okta, and replace manual IT work with code. The ideal candidate is an engineer first and a systems administrator second: someone who responds to a repeated ticket by writing the script that eliminates it, documents the result, and is comfortable owning a security-sensitive program with real business consequences.

Responsibilities
Endpoint Engineering
  • Own zero-touch enrollment end to end: Apple Business Manager for macOS, Windows Autopilot for Windows, and PXE provisioning for Ubuntu workstations
  • Translate CIS Benchmarks into deployable configuration profiles across all platforms: deterministically applied settings accompanied with osquery validations to validate posture
  • Operate FleetDM as the cross-platform management agent across macOS, Windows, and Ubuntu LTS
  • Maintain standard, reproducible workstation builds with measured and enforced patch compliance
  • Build hardened device configurations for factories, contract manufacturers, and low-connectivity sites: loaner and clean-device programs, encryption enforcement and escrow, conditional access, and remote wipe and recovery
  • Deploy and maintain CrowdStrike Falcon coverage across the fleet in partnership with Security, closing gaps on unmanaged or drifted devices
  • Translate data handling and IP protection requirements from Security, Legal, and Engineering leadership into enforceable technical controls
Identity and SSO Engineering
  • Own SSO integration of applications into Okta (SAML and OIDC), including internal tools with no vendor documentation
  • Design application authentication and RBAC from first principles, in coordination with Security
  • Automate the identity lifecycle end to end: provisioning, entitlement, and deprovisioning driven by Okta Workflows and integrated with Google Workspace, Slack, and Jira
SaaS Operations and Automation
  • Build tooling in Python, Bash, or PowerShell to eliminate manual work across onboarding, offboarding, provisioning, reporting, and audit
  • Run license and access audits, surface inactive accounts and orphaned entitlements, and drive cost recovery with Procurement
  • Formalize change management for endpoint and SaaS changes and participate in the Change Advisory Board
  • Document standards, runbooks, and automation so the broader IT team can operate and extend what you build
  • Act as escalation point for complex client-side issues and mentor Operations Specialists
Qualifications
  • Hands‑on experience managing macOS, Windows, and Linux (Ubuntu LTS) endpoint fleets in production
  • Practical experience with zero‑touch enrollment and modern endpoint tooling: FleetDM or comparable osquery‑based management, Apple Business Manager, Windows Autopilot or Microsoft Intune
  • Experience turning security benchmarks (CIS or similar) into enforced, validated configuration policy
  • Strong scripting skills in Python, Bash, and/or PowerShell, with a track record of replacing manual processes with code
  • Working knowledge of authentication fundamentals: SAML, OIDC, SCIM, and the tradeoffs between them
  • Experience administering identity and SaaS platforms at scale: Okta, Google Workspace, Slack, Jira, including SCIM and API‑driven provisioning
  • Sound judgment on security and risk tradeoffs, and the ability to explain technical controls to non‑technical stakeholders
  • Detail‑oriented and process‑driven, particularly in documenting standards and policy
  • Great communication, collaboration, and interpersonal skills
Bonus Qualifications
  • Experience supporting devices or users at manufacturing sites, contract manufacturers, or other high‑IP‑risk environments
  • Familiarity with export control, data residency, or IP protection frameworks in hardware and software R&D
  • Experience with employee‑built AI applications: assess authentication and permissions risk, and redirect requests to a Security consult
  • Experience deploying or operating EDR agents at fleet scale (CrowdStrike Falcon or similar)
  • Experience building integrations against SaaS APIs and identity providers
  • Experience supporting engineering workloads on Linux, including workstation and build‑host management
  • Experience standing up IT capability at new sites, or supporting international growth remotely from a central location
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Client Engineer
IT Client Engineer

Figure • San Jose (CA)

On-site
USD 180,000 - 210,000
IT Client Engineer
IT Client Engineer

Figureai • San Jose (CA)

On-site
USD 120,000 - 180,000
IT Client Engineer
IT Client Engineer

Linuxcareers • San Jose (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
IT Support Engineer New Austin, TX
IT Support Engineer New Austin, TX

Future Secure AI Inc. • Austin (TX)

On-site
USD 90,000 - 120,000
Endpoint Engineer, IT
Endpoint Engineer, IT

Thinking Machines Lab • New York (NY), San Francisco (CA)

On-site
USD 190,000 - 300,000
Health, dental & vision insurance
Unlimited PTO
Paid parental leave
+1
System Administrator - Level 4
System Administrator - Level 4

Sophia Space • Pasadena (CA)

On-site
USD 120,000 - 170,000
Senior Solutions Engineer – IT
Senior Solutions Engineer – IT

Jobtailor • San Francisco (CA)

On-site
USD 120,000 - 170,000
IT Support Engineer
IT Support Engineer

Future Secure AI • Austin (TX)

On-site
USD 90,000 - 120,000
Lead Security Engineer - Platform Engineer - Endpoint Security
Lead Security Engineer - Platform Engineer - Endpoint Security

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 130,000 - 180,000
IT Engineer
IT Engineer

Seven AI • Boston (MA)

On-site
USD 110,000 - 150,000
None