Senior Endpoint Security Engineer
Crusoe Energy Systems · San Francisco, United States
About The Role
Join Crusoe, a rapidly growing technology company, as a Senior Endpoint Security Engineer. In this strategic, architectural position, you will be responsible for implementing security defaults and maintaining endpoint visibility across a global fleet of devices. You will work closely with cross-functional teams and have the opportunity to shape how Crusoe manages and secures endpoints. Key responsibilities include administering and improving Jamf and Microsoft Intune environments, building automated enrollment workflows, owning a structured patch management program, and defining device compliance baselines. You will also have the chance to mentor junior IT team members and contribute to the standardization of enrollment workflows and configuration baselines.
- Implement security defaults and endpoint visibility, focusing on building secure-by-default endpoints that protect the organization as it scales.
- Administer and continuously improve Jamf and Microsoft Intune environments across all managed device types, maintaining configuration profiles, compliance policies, app deployment packages, and OS update enforcement.
- Define and enforce device compliance baselines aligned with Crusoe security standards and frameworks, integrating MDM telemetry with EDR and SIEM tooling for compliance drift visibility and proactive remediation.
- Foundational Security Experience: Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection
- Independent Engineering: A "Security-First" mindset and proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls
- Scripting & Automation: Proficiency in Bash, Python, or PowerShell for device policy automation, packaging, and remediation
- Bachelor’s degree in IT, Computer Science, or equivalent practical experience
- Strong documentation habits, ownership mindset, and ability to communicate technical policies to non-technical stakeholders
- Infrastructure Knowledge: Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence
- Identity & Access Management: Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access)
- OSQuery and CrowdStrike expertise , demonstrable experience leveraging OSQuery for endpoint visibility and administering CrowdStrike for threat detection and response; these are foundational to our security visibility and enforcement strategy
- MDM/Endpoint Management: 3–6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection)
- Jamf Pro administration experience: Smart Groups, configuration profiles, and Jamf Connect or equivalent SSO integration
- Experience with Jamf Protect, Microsoft Defender for Endpoint, or equivalent EDR tooling
- Familiarity with Linux endpoint management via Fleet, Puppet, or similar
- Exposure to SIEM tooling and endpoint log pipelines
- Apple Certified Support Professional (ACSP) or equivalent MDM certification
- Experience at a high-growth technology company through a period of rapid headcount scaling
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring