About the Role
Thinking Machines Lab is advancing collaborative general intelligence to empower humanity, creating a future where everyone can leverage AI for their unique needs. We are a team of scientists and engineers behind influential AI products and open-source projects.
Responsibilities
- Author, review, test, and deploy macOS configuration profiles, security policies, queries, and remediation scripts.
- Build code review, staging, canary, validation, and rollback processes into endpoint changes.
- Operate the MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations.
- Lead the evaluation, design, testing, and execution of the MDM migration from Iru to Fleet.
- Own the architecture and operation of Santa and its Rudolph synchronization service.
- Integrate device trust signals into authentication, authorization, and conditional-access decisions.
- Build systems for continuous evaluation of device health and security posture.
- Build and maintain automated macOS patching workflows.
- Design and improve zero-touch provisioning workflows.
- Own application packaging, deployment, updating, and removal across the Mac fleet.
- Query live device state at scale and translate endpoint telemetry into actionable insights.
- Build tools and AI-assisted workflows to reduce operational work.
- Partner with Security on macOS hardening, vulnerability management, and compliance.
- Serve as the escalation point for complex macOS and endpoint-platform issues.
- Help define the endpoint roadmap, evaluate technologies, and lead complex initiatives.
Requirements
- 8+ years of experience building and operating secure IT or endpoint systems.
- Experience managing a large fleet of macOS devices through a modern MDM platform.
- Experience managing endpoint configuration through scripted deployments, Git-based workflows, or GitOps.
- Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.
- Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.
- Experience using device health and security signals to evaluate endpoint compliance.
- Experience successfully delivering complex technical projects.
- Strong ability to solve ambiguous problems involving multiple teams and stakeholders.
- Ability to communicate technical concepts clearly.
- A product-engineering mindset toward IT systems.
- Consistent practice of creating clear technical documentation.
- Ability to work from either our New York or San Francisco office.
Skills
- Python and shell scripting.
- macOS internals (launchd, configuration profiles, TCC, system extensions, Endpoint Security, FileVault, Secure Token, bootstrap tokens).
- Apple Business Manager, Automated Device Enrollment, MDM, and Declarative Device Management frameworks.
- Modern Apple MDM platforms (Iru, Fleet, Jamf, or equivalent).
- Santa binary authorization and Rudolph synchronization infrastructure.
- Fleet-scale querying and osquery.
- Git, pull-request workflows, GitOps, and CI/CD for endpoint configuration.
- Terraform and infrastructure as code.
- Public-cloud fundamentals (serverless infrastructure, containers, managed databases, monitoring).
- Device lifecycle automation (zero-touch enrollment, patching, software distribution, secure deprovisioning).
- Endpoint security, Zero Trust, device trust, continuous posture evaluation, compliance, and automated remediation.
- Swift or Go for building macOS endpoint tools, agents, or supporting services.
- Using LLMs to automate operational work or applying them to endpoint engineering.
Location
- San Francisco, California
Work Type
- Onsite
Experience Level
- 8+ years of experience
Salary/Compensations
- $190,000 - $300,000
Benefits
- Generous health, dental, and vision benefits
- Unlimited PTO
- Paid parental leave
- Relocation support
About the Company
- Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence.
- We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.
- We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.
Equal Opportunity
- As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.
- Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.
