Systems Engineer, Corporate Security

Jobtailor

New York (NY)

On-site

USD 120,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobtailor in New York, NY is seeking a qualified Client Platform Engineer to manage macOS at scale, implement identity access controls, and automate via APIs.

You will collaborate with IT, Security, and AI DevX to enforce security controls, patching cadences, and risk-based decisions while evaluating tradeoffs.

Qualifications

  • 3–5 years of experience in Client Platform Engineering, Endpoint Engineering, IAM, or Corporate Security.
  • Hands-on macOS management at scale with MDMs like Jamf, Fleet, Kandji, or equivalent.
  • Knowledge of macOS update mechanisms and identity providers (Okta or similar).
  • Experience with SSO, authenticator policies, SCIM provisioning, and conditional access.
  • Scripting ability in Python, Go, or Bash and API automation.
  • Experience with EDR and endpoint vulnerability management (e.g., CrowdStrike).
  • Ability to balance enforcement, policy, and user friction; strong communication.

Responsibilities

  • Maintain update policies for operating systems and monitor the fleet so newly introduced applications enter the patching cadence.
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling.
  • Detect missing, stale, or unhealthy agents and restore devices to compliance.
  • Maintain device configuration baselines as code, including drift detection and hardening standards.
  • Configure Okta authentication and authenticator policies, including SSO, MFA, device trust, and conditional access.
  • Remediate identity posture gaps such as stale accounts, over-scoped OAuth grants, and MFA gaps.
  • Implement and operate enterprise AI usage controls, including identity-aware access, logging and retention, DLP, and enforcement.
  • Automate across platforms using APIs and build reporting on control coverage.
  • Document operation of the controls and report to Corporate Security lead, collaborating with IT, Security Engineering, and AI DevX.

Skills

MacOS Management
Identity Access Management
Automation Using APIs
Endpoint Vulnerability Management
MDM Experience
EDR Experience
Python Scripting
Go Scripting
Bash Scripting
Scripting (general)

Tools

Okta
Jamf
Kandji
CrowdStrike
Terraform
GitHub Actions

Job description

  • Maintain update policies for operating systems and software and monitor the fleet so newly introduced applications enter the patching cadence
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling
  • Detect missing, stale, or unhealthy agents and restore devices to compliance
  • Maintain device configuration baselines as code, including drift detection and hardening standards
  • Configure Okta authentication and authenticator policies, including SSO, MFA, authenticator enrollment, device trust, and conditional access
  • Remediate identity posture gaps such as stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges
  • Implement and operate enterprise AI usage controls, including identity-aware access, logging and retention, DLP, and enforcement
  • Automate across platforms using APIs
  • Build reporting on control coverage
  • Document operation of the controls
  • Report to the Corporate Security lead and collaborate with IT, Security Engineering, and AI DevX
Requirements
  • 3–5 years of experience in Client Platform Engineering, Endpoint Engineering, Identity Access & Management, or Corporate Security
  • Hands-on macOS management at scale
  • Experience with MDM such as Jamf, Fleet, Kandji, or equivalent
  • Knowledge of macOS update mechanisms
  • Working knowledge of an identity provider such as Okta or similar
  • Experience with SSO, authentication and authenticator policies, SCIM provisioning, and conditional access
  • Scripting ability in Python, Go, or Bash
  • Experience automating against platform APIs
  • Experience with EDR and endpoint vulnerability management, such as CrowdStrike
  • Ability to evaluate tradeoffs between technical enforcement, policy, and user friction and explain them clearly
  • osquery and Fleet or other query-based fleet visibility tooling (nice to have)
  • Identity posture management tooling or access review and governance platforms (nice to have)
  • Cloudflare Zero Trust or other proxy, DNS, or network-layer enforcement, including TLS inspection (nice to have)
  • Exposure to AI and LLM security concerns, including agent authorization, tool calls, model gateways, and data leakage through AI tooling (nice to have)
  • Infrastructure-as-code and CI/CD experience, including Terraform and GitHub Actions (nice to have)
  • Windows fleet management alongside macOS (nice to have)
  • Compliance frameworks such as SOC 2 and PCI as they apply to endpoints and access (nice to have)
Core Competencies

Demonstrates expertise in Client Platform Engineering and Endpoint Security, with a strong focus on macOS management, identity access management, and automation using APIs. Proficient in implementing security controls and compliance frameworks while effectively collaborating with cross-functional teams.

Highest-signal resume keywords
  • Client Platform Engineering
  • MacOS Management
  • Identity Access Management
  • Automation Using APIs
  • Endpoint Vulnerability Management
Hard Skills
  • Scripting in Python
  • Scripting in Go
  • Scripting in Bash
  • MDM Experience
  • EDR Experience
  • Identity Provider Knowledge
  • SSO Implementation
  • Conditional Access Configuration
  • Infrastructure-as-Code
  • CI/CD Experience
Soft Skills
  • Collaboration
  • Clear Communication
Industry Keywords
  • Endpoint Security
  • Compliance Frameworks
  • SOC 2
  • PCI
  • AI Security Concerns
Tools & Technologies
  • Okta
  • Jamf
  • CrowdStrike
  • Terraform
  • GitHub Actions
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Client Engineer
IT Client Engineer

Figure • San Jose (CA)

On-site
USD 180,000 - 210,000
IT Client Engineer
IT Client Engineer

Figure- • San Jose (CA)

On-site
USD 120,000 - 180,000
IT Client Engineer
IT Client Engineer

Figureai • San Jose (CA)

On-site
USD 120,000 - 180,000
Senior Solutions Engineer – IT
Senior Solutions Engineer – IT

Jobtailor • San Francisco (CA)

On-site
USD 120,000 - 170,000
IT Client Engineer
IT Client Engineer

Linuxcareers • San Jose (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Senior Manager, IT Security Operations
Senior Manager, IT Security Operations

Jobtailor • Washington

On-site
USD 140,000 - 180,000
Endpoint Engineer, IT
Endpoint Engineer, IT

thinkingmachines • San Francisco (CA)

On-site
USD 150,000 - 190,000
Senior Endpoint Engineer
Senior Endpoint Engineer

Jobtailor • Neptune Township (NJ)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Network and Cybersecurity Systems Engineer
Network and Cybersecurity Systems Engineer

Jobtailor • Waltham (MA)

On-site
USD 130,000 - 190,000