Senior Systems Engineer

United States Digital Space LLC

Chicago (IL)

On-site

USD 152,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

United States Digital Space LLC is seeking an experienced Senior Systems Engineer to own the macOS platform and drive endpoint management and device trust standards across the company’s IT ecosystem. You will lead initiatives across endpoint management, identity, and security tooling, focusing on Jamf Pro, AutoPkg, Okta, osQuery, and CrowdStrike, partnering with Security to enforce a Zero Trust model.

This role participates in after-hours on-call rotation and reports to the IT Engineering

Qualifications

  • 8+ years hands-on experience managing macOS at scale in enterprise environments.
  • Experience with enterprise MDM (Jamf Pro, Kandji, Mosyle) or open-source tooling (Munki, Puppet, Chef).
  • Deep understanding of Apple’s MDM protocol and Declarative Device Management.
  • Strong scripting skills (Python, Swift, Bash, Go) for API interaction and automation.
  • Knowledge of Zero Trust / BeyondCorp concepts and identity-based access control.
  • Ability to define problems clearly and align stakeholders on technical direction.

Responsibilities

  • Own the Jamf Pro environment: config profiles, smart groups, policies, MDM commands.
  • Manage AutoPkg-based software pipeline and deployment across macOS fleet.
  • Build automations and shared tooling for IT engineers.
  • Implement zero-touch provisioning and device enrollment workflows.
  • Provide Tier 3 escalation and cross-functional collaboration.

Skills

macOS at scale
Jamf Pro
AutoPkg
Apple MDM protocol
Scripting (Python/Swift/Bash/Go)
Zero Trust / BeyondCorp
Stakeholder alignment
Ambiguity navigation
Communication

Tools

Okta
osQuery
CrowdStrike
AutoPkg

Job description

About the role

We are seeking an experienced Senior Systems Engineer to own our macOS platform and drive endpoint management and device trust standards across the company’s IT ecosystem.

As a Senior Systems Engineer, you will drive multi-system initiatives across our IT domains – endpoint management, identity, and security tooling – with a primary focus on macOS and Jamf Pro. You’ll establish the technical standards other engineers work to, and partner cross-functionally on programs that affect IT Support, Security, and every Chimer with a laptop.

This is a role for someone who thrives in ambiguity: you’ll often define the problem before solving it, and align stakeholders around a technical direction rather than waiting for a specification. We believe a secure access platform can be built entirely in the cloud, leveraging tools such as Jamf, AutoPkg, Okta, osQuery, and CrowdStrike. Pairing closely with our Security team, this role makes sure our fleet stays in sync with all policies and posture checks before devices are allowed access to corporate data.

This role participates in an after-hours/on-call rotation for critical endpoint and device-management issues. Rotation frequency, response expectations, and escalation procedures will be communicated during the interview process. This position will report to the IT Engineering Manager.

The base salary offered for this role and level of experience will begin at $152,000.00 and up to $210,000.00. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.

In this role, you can expect tomacOS Platform and Endpoint Management
  • Platform Ownership: Own the technical direction, operation, and continuous improvement of our Jamf Pro environment, including configuration profiles, smart groups, policies, MDM commands, and change standards.
  • Software Delivery: Own our AutoPkg-based software pipeline: recipes, overrides, trust verification, and automated import into Jamf, alongside packaging, deployment, patch management, and disk encryption across the global macOS fleet.
  • Automation & Reusable Tooling: Build automations and shared tooling that accelerate work beyond your own – scripts, patterns, and integrations other IT engineers can adopt rather than rebuild.
  • Provisioning: Own zero-touch provisioning and device enrollment (Automated Device Enrollment, Setup Assistant, bootstrap workflows) so new Chimers are productive on day one.
  • Scripting & API Integration: Use scripting and general-purpose languages (Python, Swift, Bash, Go) and vendor APIs to create custom integrations and eliminate manual IT operations.
Security, Governance, and Compliance
  • Security Posture: Partner with Security to identify and mitigate risks to the fleet, enforcing a Zero Trust / BeyondCorp model through device trust, adaptive authentication, and least-privilege access.
  • Device Trust: Connect device management to our identity provider (Okta) so device posture is a factor in authentication and application access.
  • Compliance: Implement compliance processes and tooling to report configuration status, and assess and implement benchmark standards (e.g., CIS) against a documented, risk-based rationale.
  • Reporting: Develop metrics and reporting reflecting the inventory, health, and compliance state of all devices.
  • Troubleshooting: Serve as the Tier 3 escalation point for complex endpoint issues.
Standards, Collaboration, and Mentorship
  • Technical Standards: Establish and document the endpoint standards the broader IT organization works to, and raise the bar on testing, monitoring, and maintainability through example and influence.
  • Cross-Functional Delivery: Lead initiatives spanning IT Support, Security, and People teams – reconciling competing priorities and keeping stakeholders aligned from planning through rollout.
  • Mentorship: Mentor peers, engineers, and technicians through technical guidance, documentation, enablement, and example.
  • Support Enablement: Work with IT Support to identify pain points and implement systemic fixes that reduce ticket load rather than absorbing it.
To thrive in this role, you have
  • Experience: 8+ years of hands‑on experience managing macOS at scale with enterprise MDM (e.g., Jamf Pro, Kandji, Mosyle) and/or open-source tooling (e.g., Munki, Puppet, Chef).
  • AutoPkg: Production experience building and operating AutoPkg recipes, overrides, trust controls, and automated promotion into an enterprise MDM environment is required.
  • Apple Platform Depth: In‑depth understanding of Apple’s MDM protocol and Configuration Profile specifications, including the shift to Declarative Device Management.
  • macOS Fundamentals: In‑depth understanding of installers and packages, LaunchDaemons and LaunchAgents, the preferences subsystem, system extensions, macOS built‑in security tooling (Endpoint Security Framework, SIP, XProtect, Gatekeeper, openBSM), and unified logs.
  • Scripting: Proficiency in at least one general‑purpose or scripting language (e.g., Python, Swift, Bash, Go) for API interaction and automation.
  • Security Model: Solid understanding of Zero Trust / BeyondCorp concepts and how endpoint posture feeds identity‑based access decisions.
  • Cross-Domain Judgment: Track record of decisions spanning multiple systems, balancing scalability, compliance, cost, and long‑term maintainability.
  • Working in Ambiguity: Comfort defining a problem before solving it, and aligning stakeholders around a technical direction.
  • Communication: Excellent written and verbal communication for technical and non‑technical audiences, including the structured documentation that scales understanding across a distributed team.
Nice-to-have
  • Jamf Certified Admin (300/400) or equivalent demonstrated mastery of those knowledge domains.
  • Familiarity with Windows endpoint management (Intune/Endpoint Manager, PowerShell, MSI packaging, WMI, registry) – Windows is a smaller part of our fleet.
  • Experience with Infrastructure as Code (e.g., Terraform) for managing SaaS and MDM configuration.
  • Experience with osQuery, CrowdStrike, or comparable endpoint telemetry and EDR tooling.
  • Experience integrating endpoint management with Okta for device trust and conditional access.

#LI-Onsite #LI-WS1

A little about us

At the company, we believe that everyone can achieve financial progress. We created the company—a financial technology company, not a bank*—on the premise that core banking services should be helpful, easy, and free. Through our user-friendly tools and intuitive platforms, we empower our members to take control of their finances and work towards their goals. Whether it's starting a savings account, purchasing a first car or home, launching a business, or pursuing higher education, we're prou

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Systems Engineer
Senior Systems Engineer

Engg • Chicago (IL), New York (NY), San Francisco (CA)

On-site
USD 152,000 - 210,000
Senior Systems Engineer
Senior Systems Engineer

Chime Financial, Inc • San Francisco (CA)

On-site
USD 152,000 - 210,000
Bonus eligibility
Equity package
Benefits
Senior Systems Engineer
Senior Systems Engineer

Menlo Ventures • United States

On-site
USD 152,000 - 210,000
Backup child/elder/pet care
Subsidized commuter benefits
Comprehensive health and wellbeing
+3
Senior Systems Engineer
Senior Systems Engineer

Chime Financial, Inc • Chicago (IL)

On-site
USD 152,000 - 210,000
Bonus
Equity package
Benefits
MacOS Systems Engineer
MacOS Systems Engineer

Intellect Solutions LLC • Rockville (MD), Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Systems Engineer
Senior Systems Engineer

Chime • San Francisco (CA)

On-site
USD 152,000 - 210,000
Health and wellbeing benefits
Generous vacation policy
Wellness stipend
+1
Senior Software Engineer (Frontend)
Senior Software Engineer (Frontend)

Jamf • United States

Hybrid
USD 104,000 - 150,000
Senior Software Engineer (Swift)
Senior Software Engineer (Swift)

Jamf • United States

Hybrid
USD 58,000 - 96,000
30 days paid time off
Volunteer days (3 per year)
Benefit Plus cafeteria
+1
MacOS Platform Lead: Jamf Pro & Endpoint Security
MacOS Platform Lead: Jamf Pro & Endpoint Security

Chime Financial, Inc • San Francisco (CA)

On-site
USD 152,000 - 210,000
Bonus eligibility
Equity package
Benefits
Senior MacOS Systems Engineer: Jamf Pro & Security Lead
Senior MacOS Systems Engineer: Jamf Pro & Security Lead

Chime Financial, Inc • Chicago (IL)

On-site
USD 152,000 - 210,000
Bonus
Equity package
Benefits