Senior Endpoint Engineer - Jamf
Genesys
IndiaremotePosted 8 days ago
Skill Required
Endpoint-EngineeringJAMF-AdministrationMacOS-Systems-EngineeringEnterprise-Endpoint-ManagementAI-Endpoint-AutomationJamf-EngineerEndpoint-Management-EngineerEndpoint-EngineerInformation-Technology-Endpoint-EngineerUnified-Endpoint-Management-EngineerSOCIAMPower Appsrelated fieldEngineeringCloud SecuritynetworkingautomationShell ScriptingObservabilityCryptographyLangChainsecuritybuildingAndroidTestNGPythondesignLinuxISO 27001RustSIEMITILAPIsiOSFulltime
Key highlights
- Required Experience: 5+ years IT / 3+ years endpoint engineering
- Key Requirement: JAMF 400 Certification or equivalent expert experience
- Key Requirement: Ability to work until 1:00 PM EST
- Notable Benefit: August Free Fridays
- Notable Benefit: Flexible-first culture
Role overview
Genesys is seeking a highly skilled Senior Endpoint & JAMF Engineer to join their global Endpoint Management / End User Services team. This role combines broad expertise in managing cross-platform endpoints (macOS, Windows, Ubuntu, iOS, Android) with deep specialization in JAMF and Apple macOS device management. The successful candidate will design, deploy, and maintain enterprise-scale endpoint solutions for 10,000+ devices worldwide. As a subject matter expert, they will drive automation, AI-powered workflows, compliance, and integration initiatives, collaborating with Security, Identity, and Infrastructure teams to deliver secure, scalable, and user-centric endpoint environments at global scale.
Responsibilities
- Engineer, configure, and optimize endpoint environments across Windows, macOS, Ubuntu, iOS, and Android platforms.
- Manage enterprise MDM platforms including JAMF Pro, Microsoft Intune, Autopilot, Entra ID, and Active Directory.
- Lead endpoint patching strategies for OS and third-party applications, minimizing downtime while ensuring compliance.
- Champion ITIL-aligned process improvement, embedding AI and agentic automation to drive continuous operational efficiency.
- Serve as a subject matter expert during audits, incident response, and vulnerability remediation exercises.
- Architect, deploy, and administer JAMF Pro across a complex enterprise environment of 3,000+ macOS endpoints.
- Build automated workflows for device provisioning, application deployment, patch management, and compliance reporting.
- Develop and maintain scripts in Bash, Python, AppleScript, and PowerShell to extend and automate JAMF functionality.
- Manage JAMF configuration profiles, policies, smart groups, and operational dashboards.
- Partner with Security to enforce FileVault encryption, CIS benchmark hardening, and Zero Trust policy controls.
- Maintain Apple Business Manager (ABM/DEP), VPP licensing, APNs certificates, and MDM enrollment pipelines.
- Design and deploy AI-assisted endpoint automation pipelines to reduce manual operational overhead and accelerate response times.
- Build and maintain autonomous agents (LangChain, AutoGen, or custom LLM integrations) to handle routine endpoint tasks including compliance checks, self-healing workflows, and incident triage.
- Integrate LLM APIs into endpoint tooling for natural-language policy authoring, log analysis, and intelligent alert summarization.
- Develop event-driven automation using JAMF Pro webhooks, Microsoft Power Automate, or custom Python/API pipelines to trigger remediation workflows without manual intervention.
- Evaluate and adopt AIOps platforms to predict device health issues, proactively surface compliance drift, and optimize patch scheduling.
- Define an AI automation roadmap for endpoint operations, establishing governance, testing, and rollback standards for agentic workflows.
- Continuously assess emerging AI tooling and agent frameworks for applicability to endpoint management use cases.
- Integrate endpoint tooling with SIEM and SOAR platforms for proactive threat monitoring and automated incident response.
- Design and enforce Conditional Access policies, identity frameworks, and data loss prevention controls.
- Ensure endpoint posture meets regulatory requirements including GDPR, HIPAA, and PCI-DSS.
- Participate in Zero Trust architecture reviews, risk assessments, and compliance audits.
- Implement and validate encryption standards across platforms (BitLocker for Windows, FileVault for macOS).
- Mentor junior engineers through knowledge sharing, code reviews, and coaching, including upskilling the team on AI-assisted and agentic operations.
- Serve as the escalation point for complex endpoint and macOS issues across global teams.
- Partner with Security, Networking, and Identity teams to integrate MDM platforms with tools such as Okta and AWS VDI.
- Produce and maintain technical documentation, architecture decision records, and end-user guides.
- Strong communication skills for both technical and non-technical audiences; able to clearly convey complex concepts to stakeholders at all levels.
- Maintain endpoint compliance of 95%+ across all managed platforms.
- Reduce provisioning and onboarding time through streamlined automation and self-service workflows.
- Deliver measurable improvements in endpoint security posture and end-user satisfaction scores.
- Reduce manual endpoint management tasks through scripting, automation, and agentic AI workflows.
- Align endpoint strategies with organizational goals and evolving industry best practices.
Requirements
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent professional experience.
- 5+ years of IT experience with at least 3 years in endpoint engineering or EUC roles.
- Demonstrated expertise managing large-scale endpoint environments (10,000+ devices).
- JAMF 400 Certification (JAMF Certified Expert) or equivalent expert-level hands-on experience.
- Proficiency in scripting: Bash, Python, AppleScript, and PowerShell.
- Deep knowledge of the Apple ecosystem: ABM/DEP, VPP, MDM protocol, APNs.
- Strong understanding of endpoint compliance, encryption (BitLocker, FileVault), and Zero Trust frameworks.
- Experience with vulnerability remediation, patch lifecycle management, and endpoint security tooling.
- Excellent written and verbal communication and cross-team collaboration skills.
- Available to work until 1:00 PM EST.
Nice to have
- Experience working in regulated industries such as finance, healthcare, or government.
- Hands-on experience with AWS VDI image creation and deployment pipelines.
- Familiarity with modern identity and access management frameworks (Zero Trust, Conditional Access, Okta).
- Practical experience building AI agents or LLM-integrated workflows (LangChain, AutoGen, Claude, OpenAI API, or similar).
- Understanding of prompt engineering, retrieval-augmented generation (RAG), or fine-tuning for IT operations use cases.
Benefits
- Flexible-first culture with flexible ways of working.
- Mentorship, learning programs, leadership development and education support.
- Paid volunteer time.
- August Free Fridays.
- Well-being resources and regionally tailored programs for employees and their families.
Additional details
- Company helps organizations create better customer experiences through AI-powered experience orchestration.
- Platform used by more than 8,000 organizations in over 100 countries.
- Application process typically involves a Talent Acquisition review, a Zoom interview, and meetings with the hiring manager and interview team (no more than five interviews in most cases).
- Every application is reviewed by a person.
- Genesys is an equal opportunity employer committed to fairness in the workplace.
- Reasonable accommodations are available for the application process via contact email with a 24–48 hour expected response time.
- Recruiters will never ask for sensitive personal or financial information during the application phase.