Senior Systems Engineer
Chime- Base salary
- $152k–$210k Published base salary range
- Location
- Hybrid - Chicago, IL, New York, NY, or San Francisco, CA, 4 days/week in office Remote eligibility
- Employment
- Full-time Senior
About the job
About the role
We are seeking an experienced Senior Systems Engineer to own our macOS platform and drive endpoint management and device trust standards across Chime’s IT ecosystem. You will drive multi-system initiatives across IT domains – endpoint management, identity, and security tooling – with a primary focus on macOS and Jamf Pro. You’ll establish technical standards, partner cross-functionally on programs affecting IT Support, Security, and every Chimer with a laptop. This role participates in an after-hours/on-call rotation for critical endpoint and device-management issues.
Responsibilities
- Own the technical direction, operation, and continuous improvement of our Jamf Pro environment, including configuration profiles, smart groups, policies, MDM commands, and change standards.
- Own our AutoPkg-based software pipeline: recipes, overrides, trust verification, and automated import into Jamf, alongside packaging, deployment, patch management, and disk encryption across the global macOS fleet.
- Build automations and shared tooling that accelerate work beyond your own – scripts, patterns, and integrations other IT engineers can adopt.
- Own zero-touch provisioning and device enrollment (Automated Device Enrollment, Setup Assistant, bootstrap workflows).
- Use scripting and general-purpose languages (Python, Swift, Bash, Go) and vendor APIs to create custom integrations and eliminate manual IT operations.
- Partner with Security to identify and mitigate risks to the fleet, enforcing a Zero Trust / BeyondCorp model through device trust, adaptive authentication, and least-privilege access.
- Connect device management to our identity provider (Okta) so device posture is a factor in authentication and application access.
- Implement compliance processes and tooling to report configuration status, and assess and implement benchmark standards (e.g., CIS).
- Develop metrics and reporting reflecting the inventory, health, and compliance state of all devices.
- Serve as the Tier 3 escalation point for complex endpoint issues.
- Establish and document endpoint standards, lead cross-functional initiatives, mentor peers, and work with IT Support to reduce ticket load.
Qualifications
- 8+ years of hands-on experience managing macOS at scale with enterprise MDM (e.g., Jamf Pro, Kandji, Mosyle) and/or open-source tooling (e.g., Munki, Puppet, Chef).
- Production experience building and operating AutoPkg recipes, overrides, trust controls, and automated promotion into an enterprise MDM environment is required.
- In-depth understanding of Apple’s MDM protocol and Configuration Profile specifications, including Declarative Device Management.
- In-depth understanding of installers and packages, LaunchDaemons and LaunchAgents, preferences subsystem, system extensions, macOS built-in security tooling (Endpoint Security Framework, SIP, XProtect, Gatekeeper, openBSM), and unified logs.
- Proficiency in at least one general-purpose or scripting language (e.g., Python, Swift, Bash, Go) for API interaction and automation.
- Solid understanding of Zero Trust / BeyondCorp concepts and how endpoint posture feeds identity-based access decisions.
- Track record of decisions spanning multiple systems, balancing scalability, compliance, cost, and long-term maintainability.
- Comfort defining a problem before solving it, and aligning stakeholders around a technical direction.
- Excellent written and verbal communication for technical and non-technical audiences.
Nice-to-have
- Jamf Certified Admin (300/400) or equivalent demonstrated mastery.
- Familiarity with Windows endpoint management (Intune/Endpoint Manager, PowerShell, MSI packaging, WMI, registry).
- Experience with Infrastructure as Code (e.g., Terraform) for managing SaaS and MDM configuration.
- Experience with osQuery, CrowdStrike, or comparable endpoint telemetry and EDR tooling.
- Experience integrating endpoint management with Okta for device trust and conditional access.
Compensation & Benefits
Base salary offered for this role and level of experience: $152,000—$210,000 USD. Full-time employees may also be eligible for bonus(es), competitive equity, and benefits. Benefits include backup child, elder, and pet care, subsidized commuter benefits, comprehensive health/financial/wellbeing benefits, generous vacation policy and company-wide paid days off, annual wellness stipend, up to 22 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents, and family planning reimbursement.
Application Instructions
Apply via the provided Greenhouse link.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.