Staff Endpoint Engineer managing macOS devices for Affirm’s employee-facing IT experience. Responsibilities include scaling device management and leading automation initiatives to enhance security and productivity.
Responsibilities
Administer and scale macOS device management using Jamf Pro, ensuring endpoints meet company compliance standards (e.g., encryption, OS patching, configuration profiles, application management).
Guide architectural decisions to ensure endpoint management can easily scale with the company.
Drive key technical initiatives such as permission automation, third-party patching, silent updates, stability improvements, and streamlined device deployment.
Build automation and infrastructure-as-code pipelines using tools like Terraform (or similar), Bash/Python scripting, and Jamf/Okta/MDM APIs to minimize manual work and create “zero-touch” provisioning workflows.
Manage enterprise-grade software and package deployment, using tools like AutoPkgr or equivalent for packaging and silent rollout of updates at scale.
Implement and refine endpoint change control processes, with communication, testing, rollback plans, and compliance tracking. Create dashboards and reporting for visibility into compliance, patch levels, and device health.
Collaborate closely with Security, Support, Engineering, and IT to enforce policies (e.g. least-privilege), onboard security agents (AV, EDR, disk encryption), and integrate devices with Okta SSO, Oomnitza, Google Workspace, and other monitoring tools.
Serve as the escalation tier for complex endpoint issues—troubleshoot deep macOS, hardware, networking, or software issues and act as a knowledge source for IT Support.
Mentor junior engineers—share expertise, set best practices, and help elevate the team’s Jamf, scripting, and automation capabilities.
Explore and evaluate new endpoint-management and automation technologies, run POCs, and recommend adoption to improve platform efficiency, security, and user experience.
Work directly with Developer Productivity to support the unique needs of Affirm’s engineers.
Requirements
5+ years of hands-on experience managing macOS (and ideally other endpoints) at scale with enterprise MDM tools - Jamf Pro expertise required (Jamf 300+ level).
Strong scripting capabilities in Bash, with fluency in a second language like Python; ability to programmatically integrate with RESTful APIs (Jamf API, Okta API, etc.).
Proven proficiency in automation / infrastructure-as-code tools like Terraform, Ansible, or similar in an IT context.
Experience with Windows Intune and Windows Endpoint Management.
Deep understanding of enterprise security practices for endpoints, including vulnerability/patch management, enforcing least privilege, encryption, and compliance frameworks.
Experience building and managing package/software distribution pipelines, with tools like AutoPkg, Jamf, or others.
Exceptional troubleshooting skills and ability to debug complex endpoint issues; capable of representing the IT team in high-severity escalations.
Excellent cross-functional communication skills with a collaborative mindset—able to work with Security, Support, and Engineering teams effectively.
A positive, growth-oriented attitude, with strong written communication: documentation, runbooks, dashboards, and process guides.
Prior experience serving as a technical mentor or functional lead in a high-growth or enterprise environment is strongly preferred.
This position requires either equivalent practical experience or a Bachelor’s degree in a related field.
Benefits
Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
Principal Engineer leading the development of a new platform at Fulfillment IQ. Focused on technical design, system architecture, and engineering best practices.
Senior API/Platform Engineer at IDC responsible for developing AI - driven intelligence platforms. Lead a team of engineers while hands - on coding and shaping technology decision - making.
Platform Engineer joining Validus to enhance AWS infrastructure and developer tooling for the Horizon platform. Collaborating with technical teams on cloud - native projects.
Platform Engineer supporting cloud - based big data solutions at Fitch Group. Collaborating with architects and engineers to design a cutting - edge cloud data platform.
Senior Platform Engineer designing, improving, and scaling infrastructure for Stay22's platform. Collaborating with engineering teams to enhance system performance and reliability.
Mid - level Salesforce Functional/BSA contract in Toronto. Analyze and drive high - quality documentation for Salesforce definition and data migration.
M365 Platform Engineer contract role in Downtown Vancouver. Requires extensive M365 experience including Exchange Online, M365 Admin Center, MS Entra, MS Teams, SharePoint Online, OneDrive.
Senior Platform Engineer developing and maintaining web applications using Ruby on Rails and React. Join Lillio to empower early childhood educators with innovative solutions.
Senior AI Platform Engineer at Supernal building conversational AI systems for live business environments. Leading technical delivery of AI workflows on a proprietary platform in a remote global role.
Platform Engineer improving software delivery performance and availability by driving DevOps culture at Top Hat. Join a remote - first team helping product teams manage and achieve SLOs.