8+ years building and operating secure endpoint or IT systems in complex environments, including a large macOS fleet on a modern MDM, owning the platform as the final escalation point, with no endpoint engineer above you to hand it to
A builder first: you write production-grade code (Python at least; Swift or Go for endpoint tooling is a bonus) and treat endpoint configuration as software you own, with tests, review, and observability, not a console you administer
AI-first by conviction: you already reach for agents and LLMs (Claude Code and the like) to compress operational toil, and you have a clear view on where they’re trustworthy and where a human owns the call. Show us something you automated that used to eat your week
Deep on macOS internals: launchd, configuration profiles, TCC, system extensions, Endpoint Security, FileVault, Secure Token and bootstrap tokens
Fluent in declarative device management, not just profiles: you know where Apple has moved configuration to declarations and can plan a migration off the payloads being retired. Legacy software update management no longer functions in the 27 release, so declarative enforcement is the only supported path
Disciplined about change: you’ve shipped endpoint changes through Git-based workflows with staging, canary, and rollback, and you’d rather find a regression in a canary group than in the all-hands channel
A product-engineering mindset toward IT: reliability, observability, controlled change, and documentation others can operate from: architecture diagrams, runbooks, and decisions written down
Clear with both audiences: you can take a technical stakeholder through the architecture and a non-technical colleague through what’s changing on their laptop and why
Fleet: deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities
Leading a production MDM migration, particularly with Apple Business Manager and Automated Device Enrollment in play
Operating Santa at scale: rule management, binary authorization policy, event telemetry, and a Rudolph synchronisation service
Managing macOS through Jamf or Kandji (now Iru), and Windows through Intune where the fleet calls for it
Fleet-scale querying with osquery, and turning that data into compliance and drift reporting
Declarative credentials: ACME, SCEP, and identity credentials declared once as reusable assets and referenced across network configurations, rather than embedded per profile
Moving network, VPN/DNS, extensible SSO, content caching, and web content filtering onto declarative configurations
Operating an MDM service against Apple’s stricter TLS and App Transport Security requirements
Progressive delivery for endpoints: automated rollout with staging, canary groups, telemetry-based promotion, and rollback
Device trust and continuous posture evaluation integrated with an identity provider and conditional access
Infrastructure as code (Terraform or similar) and public-cloud fundamentals: serverless, containers, managed databases, monitoring
Deploying, operating, or contributing to open-source macOS endpoint management and security tooling
Experience with Okta, Microsoft Entra ID, 1Password, CrowdStrike, Jamf, Apple Business Manager, Lumos, and our AI-native ITSM (Serval)