The Endpoint Engineering team at CoreWeave manages end-user compute for all employees running macOS and Windows 11 — application deployment, patching, and configuration management to keep the environment secure and reliable
We're expanding that scope with a cloud-based VDI offering (Ubuntu and Windows 11) to meet growing customer needs. This role owns that expansion as the sole DRI for the Next Gen VDI platform: the remote-compute infrastructure powering hundreds of engineers, network operators, and support teams company-wide. You'll own everything from the underlying cloud infrastructure to the OS images running on it, delivering a secure, self-service, operationally excellent platform as CoreWeave scales
As the Systems Engineer for Next Gen VDI, you will own both the cloud infrastructure buildout and the OS lifecycle for CoreWeave’s next-generation remote compute platform. This is a hands-on engineering role with end-to-end scope: you will design and stand up the platform from scratch—integrating Teleport, Okta SSO, audit logging, cost governance, and self-service tooling—and you will own the image pipelines, patch cadence, configuration management, and security agent stack that keep the fleet healthy
Design and deliver the end-to-end VDI platform architecture—covering cloud infrastructure, access controls, OS lifecycle, security posture, and network topology—and drive peer review and sign-off before build commences
Integrate cloud infrastructure into CoreWeave’s Teleport cluster: IAM node joining, RBAC role definitions, access policies per user persona, and break-glass/OOB node setup and validation
Configure Okta SAML/OIDC SSO with MFA enforcement, session policy, and access review workflows for the VDI fleet
Build and maintain the audit logging pipeline (cloud logging → CoreWeave SIEM), legal hold and forensic snapshot-on-demand workflows, and compliance-aligned session activity retention policies
Own cost governance: implement instance tagging and cost center chargeback attribution, build idle detection and cleanup automation, and deliver self-service and admin portals for instance lifecycle management
Own the Ubuntu LTS and Windows 11 base image pipelines—code-defined builds (Packer or equivalent), automated regression test suites covering agent health, network reachability, and security posture, versioned release promotion, and rollback procedures
Write and maintain Chef cookbooks (or equivalent) for post-provision configuration: user setup, mounts, and toolchain
Bake security and network agents (CrowdStrike, Netskope, BlastShield) and the PCoIP client/agent into Ubuntu and Windows 11 base images; own group/policy configuration, fleet enrollment, and alert routing
Lead end-to-end integration testing (provision → auth → tool access → teardown) and platform security review prior to launch; remediate and drive sign-off
Sustain steady-state operations: monthly patch releases, config management updates, infrastructure health checks, incident response, and user ticket triage
Produce and maintain runbooks for image release, Teleport onboarding, break-glass procedures, and incident response