Staff Endpoint Engineer managing macOS devices for Affirm’s employee-facing IT experience. Responsibilities include scaling device management and leading automation initiatives to enhance security and productivity.
Responsibilities
Administer and scale macOS device management using Jamf Pro, ensuring endpoints meet company compliance standards (e.g., encryption, OS patching, configuration profiles, application management).
Guide architectural decisions to ensure endpoint management can easily scale with the company.
Drive key technical initiatives such as permission automation, third-party patching, silent updates, stability improvements, and streamlined device deployment.
Build automation and infrastructure-as-code pipelines using tools like Terraform (or similar), Bash/Python scripting, and Jamf/Okta/MDM APIs to minimize manual work and create “zero-touch” provisioning workflows.
Manage enterprise-grade software and package deployment, using tools like AutoPkgr or equivalent for packaging and silent rollout of updates at scale.
Implement and refine endpoint change control processes, with communication, testing, rollback plans, and compliance tracking. Create dashboards and reporting for visibility into compliance, patch levels, and device health.
Collaborate closely with Security, Support, Engineering, and IT to enforce policies (e.g. least-privilege), onboard security agents (AV, EDR, disk encryption), and integrate devices with Okta SSO, Oomnitza, Google Workspace, and other monitoring tools.
Serve as the escalation tier for complex endpoint issues—troubleshoot deep macOS, hardware, networking, or software issues and act as a knowledge source for IT Support.
Mentor junior engineers—share expertise, set best practices, and help elevate the team’s Jamf, scripting, and automation capabilities.
Explore and evaluate new endpoint-management and automation technologies, run POCs, and recommend adoption to improve platform efficiency, security, and user experience.
Work directly with Developer Productivity to support the unique needs of Affirm’s engineers.
Requirements
5+ years of hands-on experience managing macOS (and ideally other endpoints) at scale with enterprise MDM tools - Jamf Pro expertise required (Jamf 300+ level).
Strong scripting capabilities in Bash, with fluency in a second language like Python; ability to programmatically integrate with RESTful APIs (Jamf API, Okta API, etc.).
Proven proficiency in automation / infrastructure-as-code tools like Terraform, Ansible, or similar in an IT context.
Experience with Windows Intune and Windows Endpoint Management.
Deep understanding of enterprise security practices for endpoints, including vulnerability/patch management, enforcing least privilege, encryption, and compliance frameworks.
Experience building and managing package/software distribution pipelines, with tools like AutoPkg, Jamf, or others.
Exceptional troubleshooting skills and ability to debug complex endpoint issues; capable of representing the IT team in high-severity escalations.
Excellent cross-functional communication skills with a collaborative mindset—able to work with Security, Support, and Engineering teams effectively.
A positive, growth-oriented attitude, with strong written communication: documentation, runbooks, dashboards, and process guides.
Prior experience serving as a technical mentor or functional lead in a high-growth or enterprise environment is strongly preferred.
This position requires either equivalent practical experience or a Bachelor’s degree in a related field.
Benefits
Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
Platform Engineer managing AWS infrastructure and CI/CD pipelines for Kento Health's cardiac care solution. Collaborating with engineers to ensure scalability and reliability of services.
Développeur logiciel pour l’équipe Platform Engineering de Genetec, responsable du système d’authentification unique. Travaillant sur des solutions d’architecture de microservices dans un environnement cloud, avec des technologies à jour.
Platform Engineer developing robust data and ML platform components at Homebase. Collaborating with teams to enable data - driven features and ensure seamless integration.
Platform Engineering Manager overseeing hybrid and cloud infrastructures for a tech company. Leading team improvements in production and developer experience across multiple regions.
Data Platform Engineer Intern at Canada Life designing cloud - based data solutions. Contributing to analytics enablement and partnering with stakeholders to enhance data platform capabilities.
Senior Power Platform Developer responsible for enhancing certification platforms and integrating cloud services. Collaborating with engineering teams to enable auto - certification and seamless integration in the Toronto office.
Senior Platform Engineer at Float, designing and maintaining cloud infrastructure and developer platforms. Focus on high performance, scalability, security, and automation for financial services.
AI Platform Engineer at Circle leveraging AI technology to enhance customer experience. Focused on production AI systems and infrastructure for measuring performance and accuracy.
AI Platform Engineer at Kayzen designing internal AI frameworks and enabling integration of AI features. Working on AI tooling for rapid deployment of AI - powered solutions across teams.