Senior Endpoint Security Engineer

Crusoe

San Francisco (CA)

On-site

USD 170,000 - 205,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Equity packages
Paid time off
Healthcare benefits
HSA contributions
Parental leave
Retirement plan
Tuition reimbursement
Wellness programs
Commuter benefits
Cell phone stipend
Travel benefits

Job summary

Crusoe is seeking a Security Engineer to join our Security Engineering team in San Francisco, Sunnyvale, or Denver. You’ll build secure-by-default endpoints, shape security posture, and drive architectural initiatives for macOS, Windows, iOS, and Android devices.

You’ll integrate with CIS SOC 2, EDR, and SIEM tools, own device trust policies, and automate protections with Bash, Python, or PowerShell. A strong, hands-on security mindset is essential.

Qualifications

  • Experience with OSQuery and CrowdStrike for endpoint visibility and threat detection.

Responsibilities

  • Administer and optimize Jamf and Microsoft Intune environments across macOS, Windows, iOS, and Android.
  • Build automated enrollment workflows including ABM and Windows Autopilot for zero-touch provisioning at scale.
  • Own patch management with SLAs for OS and app updates across platforms.
  • Define and enforce device compliance baselines aligned with CIS Benchmarks and SOC 2.
  • Collaborate on device trust policies, CA enforcement, and certificate-based Wi-Fi/VPN authentication.
  • Develop scripts to reduce workload and build self-service tooling for end users.
  • Maintain MDM runbooks, device policy docs, and enrollment workflows across platforms.
  • Serve as MDM escalation point and mentor junior IT staff.

Skills

OSQuery
CrowdStrike
Okta
Entra ID
Jamf/Kandji
Microsoft Intune
Autopilot
SCEP/PKCS
Certificate infrastructure
Bash
Python
PowerShell
Documentation
Bachelor’s degree

Education

Bachelor’s degree in IT, Computer Science, or equivalent

Tools

Jamf
Kandji
Microsoft Intune
Apple Business Manager
Windows Autopilot

Job description

Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster.

We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that — with an energy-first approach that makes AI infrastructure better for the world and faster for the people innovating with AI.

We're looking for problem‑solving, opportunity‑finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved — people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services.

If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high-performing team that believes in each other, come build with us at Crusoe.

About the Role

Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This is a strategic, architectural position focused on building secure-by-default endpoints that protect the organization as it scales. You will be responsible for security architecture, endpoint visibility, and maintaining our security posture across a rapidly growing global fleet of macOS, Windows, iOS, and Android devices. This role involves cross‑functional partnership with Security and People Operations, with genuine scope to shape how Crusoe manages and secures endpoints. This role is onsite in San Francisco, CA, Sunnyvale, CA or Denver CO.

What You’ll Be Working On
  • Administer and continuously improve Jamf and Microsoft Intune environments across all managed device types: macOS, Windows, iOS, and Android; maintain configuration profiles, compliance policies, app deployment packages, and OS update enforcement across all platforms.
  • Build and maintain automated enrollment workflows including Apple Business Manager (ABM) and Windows Autopilot for zero-touch provisioning at scale.
  • Own a structured patch management program with clear SLAs for OS and application updates across all device platforms.
  • Define and enforce device compliance baselines aligned with Crusoe security standards and frameworks including CIS Benchmarks and SOC 2; integrate MDM telemetry with EDR and SIEM tooling for compliance drift visibility and proactive remediation.
  • Partner with Security on device trust policies, Conditional Access enforcement, certificate‑based authentication rollout (SCEP/PKCS), and network‑level access control for certificate‑based Wi‑Fi and VPN authentication.
  • Build and maintain scripts and automation in Bash, Python, or PowerShell to reduce manual IT workload; develop self‑service tooling that puts routine fixes and software requests directly in employees’ hands.
  • Own MDM runbooks, device policy documentation, and asset records; contribute to the standardization of enrollment workflows, naming conventions, and configuration baselines across all platforms.
  • Serve as the MDM escalation point in the IT on‑call rotation; partner with People Operations on seamless device provisioning and deprovisioning; mentor junior IT team members on endpoint management practices.
What You’ll Bring to the Team
  • Foundational Security Experience: Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection.
  • Identity & Access Management: Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access).
  • MDM/Endpoint Management: 3–6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection).
  • Independent Engineering: A "Security-First" mindset and proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls.
  • Scripting & Automation: Proficiency in Bash, Python, or PowerShell for device policy automation, packaging, and remediation.
  • Infrastructure Knowledge: Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence.
  • Strong documentation habits, ownership mindset, and ability to communicate technical policies to non‑technical stakeholders.
  • Bachelor’s degree in IT, Computer Science, or equivalent practical experience.
  • OSQuery and CrowdStrike expertise, demonstrable experience leveraging OSQuery for endpoint visibility and administering CrowdStrike for threat detection and response; these are foundational to our security visibility and enforcement strategy.
Bonus Points
  • Jamf Pro administration experience: Smart Groups, configuration profiles, and Jamf Connect or equivalent SSO integration.
  • Experience with Jamf Protect, Microsoft Defender for Endpoint, or equivalent EDR tooling.
  • Familiarity with Linux endpoint management via Fleet, Puppet, or similar.
  • Apple Certified Support Professional (ACSP) or equivalent MDM certification.
  • Exposure to SIEM tooling and endpoint log pipelines.
  • Experience at a high‑growth technology company through a period of rapid headcount scaling.
Benefits
  • Competitive compensation and equity packages
  • Restricted Stock Units
  • Paid time off, paid holidays & leave of absence programs
  • Comprehensive health, dental & vision insurance
  • Employer contributions to HSA account
  • Paid parental leave
  • Paid life insurance, short‑term and long‑term disability
  • Professional development & tuition reimbursement
  • Mental health & wellness support
  • Commuter benefits (parking & transit)
  • Cell phone stipend
  • 401(k) Retirement plan with company match up to 4% of salary
  • Volunteer time off
  • Global travel insurance & emergency assistance
  • Daily meals allowance
  • Additional perks & programs specific to location
Compensation Range

Compensation will be paid in the range of up to $170,000 – $205,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant’s knowledge, education, and abilities, as well as internal equity and alignment with market data.

Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer, Security
Senior Software Engineer, Security

Crusoe • San Francisco (CA)

On-site
USD 175,000 - 210,000
Competitive compensation
401(k) plan with company match
Paid parental leave
+1
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Epoch Biodesign • San Francisco (CA)

On-site
USD 210,000 - 255,000
Comprehensive health, dental & vision insurance
401(k) Retirement plan with company match
Paid parental leave
+2
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Crusoe Energy Systems LLC • San Francisco (CA)

On-site
USD 210,000 - 255,000
Competitive compensation and equity packages
401(k) Retirement plan with company match
Paid parental leave
+2
Principal Infrastructure Security Engineer
Principal Infrastructure Security Engineer

Crusoe • San Francisco (CA)

On-site
USD 280,000 - 330,000
Competitive compensation and equity packages
Comprehensive health, dental & vision insurance
401(k) Retirement plan with company match
+2
Senior Software Engineer, IAM
Senior Software Engineer, IAM

Crusoe • San Francisco (CA)

On-site
USD 175,000 - 220,000
Competitive compensation and equity packages
Paid time off and leave of absence programs
Comprehensive health, dental & vision insurance
+1
Senior Microsoft Cloud Infrastructure Engineer
Senior Microsoft Cloud Infrastructure Engineer

Crusoe • San Francisco (CA)

On-site
USD 160,000 - 195,000
Competitive compensation
Equity packages
Paid time off and holidays
+4
Staff Software Engineer, Developer Experience
Staff Software Engineer, Developer Experience

Epoch Biodesign • San Francisco (CA)

On-site
USD 208,000 - 253,000
Restricted Stock Units
Comprehensive health, dental & vision insurance
401(k) Retirement plan with company match
+2
Senior Enterprise AI Automation Engineer
Senior Enterprise AI Automation Engineer

Crusoe • San Francisco (CA)

On-site
USD 195,000 - 225,000
Competitive compensation and equity packages
Paid time off
Comprehensive health, dental & vision insurance
+2
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

ProducePay • San Francisco (CA)

On-site
USD 170,000 - 205,000
Health insurance
Restricted Stock Units (RSU)
401(k) with match
+1
Senior Manager, Engineering Operations
Senior Manager, Engineering Operations

Crusoe • San Francisco (CA)

On-site
USD 230,000 - 280,000
Equity
Paid time off
Health insurance
+4