> Markdown version of [/jobs/ext/1247922-endpoint-security-engineer](https://www.wearedevelopers.com/jobs/ext/1247922-endpoint-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Endpoint Security Engineer - **Company:** Crusoe's Inc - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Salary:** $170,000.0 - $205,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Android Software Development, Apple IOS, Apple Mac Systems, Bash Shell, Cyber Security, Linux, Identity and Access Management, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Windows PowerShell, Security Information and Event Management, Wi-Fi Technology, Okta, Microsoft InTune, Azure Security Center, Information Technology, Deployment Automation, Patch Management, Casper Suite, CIS Benchmarks, Puppet - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fb5a77fcf21ddf77 ## About the Role * Foundational Security Experience: Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection. * Identity & Access Management: Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access). * MDM/Endpoint Management: 3-6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection). * Independent Engineering: A "Security-First" mindset and proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls. * Scripting & Automation: Proficiency in Bash, Python, or PowerShell for device policy automation, packaging, and remediation. * Infrastructure Knowledge: Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence. * Strong documentation habits, ownership mindset, and ability to communicate technical policies to non-technical stakeholders. * Bachelor's degree in IT, Computer Science, or equivalent practical experience. * OSQuery and CrowdStrike expertise , demonstrable experience leveraging OSQuery for endpoint visibility and administering CrowdStrike for threat detection and response; these are foundational to our security visibility and enforcement strategy. Bonus Points * Jamf Pro administration experience: Smart Groups, configuration profiles, and Jamf Connect or equivalent SSO integration. * Experience with Jamf Protect, Microsoft Defender for Endpoint, or equivalent EDR tooling. * Familiarity with Linux endpoint management via Fleet, Puppet, or similar. * Apple Certified Support Professional (ACSP) or equivalent MDM certification. * Exposure to SIEM tooling and endpoint log pipelines. * Experience at a high-growth technology company through a period of rapid headcount scaling. ## Description Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This is a strategic, architectural position focused on building secure-by-default endpoints that protect the organization as it scales. You will be responsible for security architecture, endpoint visibility, and maintaining our security posture across a rapidly growing global fleet of macOS, Windows, iOS, and Android devices. This role involves cross-functional partnership with Security and People Operations, with genuine scope to shape how Crusoe manages and secures endpoints. This role is onsite in San Francisco, CA, Sunnyvale, CA or Denver CO., * Administer and continuously improve Jamf and Microsoft Intune environments across all managed device types: macOS, Windows, iOS, and Android; maintain configuration profiles, compliance policies, app deployment packages, and OS update enforcement across all platforms. * Build and maintain automated enrollment workflows including Apple Business Manager (ABM) and Windows Autopilot for zero-touch provisioning at scale. * Own a structured patch management program with clear SLAs for OS and application updates across all device platforms. * Define and enforce device compliance baselines aligned with Crusoe security standards and frameworks including CIS Benchmarks and SOC 2; integrate MDM telemetry with EDR and SIEM tooling for compliance drift visibility and proactive remediation. * Partner with Security on device trust policies, Conditional Access enforcement, certificate-based authentication rollout (SCEP/PKCS), and network-level access control for certificate-based Wi-Fi and VPN authentication. * Build and maintain scripts and automation in Bash, Python, or PowerShell to reduce manual IT workload; develop self-service tooling that puts routine fixes and software requests directly in employees' hands. * Own MDM runbooks, device policy documentation, and asset records; contribute to the standardization of enrollment workflows, naming conventions, and configuration baselines across all platforms. * Serve as the MDM escalation point in the IT on-call rotation; partner with People Operations on seamless device provisioning and deprovisioning; mentor junior IT team members on endpoint management practices. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Memory Leak That Ate Our Cluster: A Postmortem](https://www.wearedevelopers.com/videos/2057-the-memory-leak-that-ate-our-cluster-a-postmortem) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 139 - Soft and hard queries](https://www.wearedevelopers.com/magazine/487-dev-digest-139-soft-and-hard-queries)