WHO WE ARE
Apex Fintech Solutions (Apex) powers innovation and the future of digital wealth management by building tech-forward solutions that help simplify, automate, and facilitate access to financial markets for all. Our robust suite of fintech software enables us to support clients such as Stash, Betterment, SoFi, Webull, and eToro, amongst many others; collectively, Apex powers access to the stock market for over 22+ million end customers.
At Apex, we are changing how the securities industry operates by reinventing the status quo, which was manual, slow, and accessible only by the ultra-wealthy. We're digitizing and democratizing systems so that everyone has an opportunity to invest.
When you're at Apex, you drive this change. You're part of a global team with a clear vision: to be the trusted technology that powers the digital economy. Our offices in Austin, Dallas, Chicago, New York, Portland, Belfast, and Manila are home to over 1,000 employees.
Together, we're shaping the future of financial innovation. Embrace change. Solve big. Win together. And be G.R.E.A.T. - grit, results, empathy, accountability, and teamwork - with Apex.
We're proud to be recognized for the innovative work we do, the purpose-driven nature of our work, and the collaborative culture we've created.
- Best Places to Work 2026, 2025, 2024, 2023 - Presented by BuiltIn
- WealthTech of the Year 2025 - Presented by US FinTech Awards
- The World's Top 250 Fintech Companies 2024 - Presented by CNBC
ABOUT THIS ROLE
About the Role
We're hiring a Systems/Integration Engineer to own the plumbing that connects our endpoints, identity platform, and cloud infrastructure. This person will design and build integrations across AWS WorkSpaces, Microsoft Intune, Kandji, Apple Business Manager, Entra ID, and Conditional Access - replacing legacy Group Policy dependencies with modern, cloud-native, policy-as-code management. Everything shipped must be automated and reproducible.
What You’ll Do
- Own and maintain integrations between AWS WorkSpaces and on-prem/cloud identity (Entra ID, AD Connect/Cloud Sync).
- Own end-to-end Intune administration: compliance policies, configuration profiles, app deployment, Autopilot/Windows enrollment, Scope Tags, and RBAC design across business units.
- Manage Apple device lifecycle via Kandji + Apple Business Manager (ABM): DEP enrollment, supervised device policies, app deployment, and zero-touch provisioning.
- Design and enforce Conditional Access policies in Entra ID (device compliance, location, risk-based sign-in, session controls) in coordination with security/identity teams.
- Work with Team on migration of legacy Group Policy Objects (GPOs) to Intune/Entra-based configuration and compliance policies, including translating GPO logic 1:1 where needed and documenting gaps.
- Build and maintain RBAC models across Intune, Entra ID, and AWS (least-privilege scoped admin roles, custom roles, Scope Tag-based delegation).
- Write and maintain AWS Lambda functions to automate device lifecycle events, cross-platform sync (e.g., Kandji Intune Entra WorkSpaces), reporting, and remediation workflows.
- Build all infrastructure using Infrastructure as Code (Terraform, Ansible, and/or CloudFormation) no manual console changes for anything reproducible, managed through version control with peer review.
- Develop automation/scripting for endpoint and identity workflows (PowerShell, Python, Microsoft Graph API).
- Implement and maintain MDM solutions for BYOD devices for Windows/Mac/Linux/Android devices.
Required Skills & Experience
- Bachelor's degree in Computer Science or related technical discipline (or equivalent work experience) required
- 2+ years in systems/endpoint engineering, including hands-on administration of both a modern MDM (Intune, plus Kandji or Jamf Pro) and AWS infrastructure.
- Deep, hands-on Microsoft Intune expertise: compliance policies, configuration profiles, app protection/app config policies, Autopilot, Scope Tags, RBAC (built-in and custom roles).
- Kandji or Jamf Pro administration (Blueprints/policies, Library Items/config profiles, Liftoff or equivalent zero-touch enrollment).
- Apple Business Manager (ABM): DEP, VPP, device assignment, MDM server integration.
- Hands-on Group Policy (GPO) experience and proven experience migrating GPO logic to cloud-native MDM/compliance policy equivalents.
- Entra ID (Azure AD) administration: users/groups, dynamic groups, app registrations, enterprise apps, hybrid identity.
- Conditional Access policy design and troubleshooting (sign-in logs, what-if tool, break-glass account practices).
- RBAC design across Microsoft and AWS environments - custom roles, least privilege, scoped administration.
- AWS WorkSpaces provisioning, directory integration (AWS Directory Service / AD Connector), and related networking.
- Infrastructure as Code: Terraform, Ansible, and/or AWS CloudFormation, used for all provisioned infrastructu