Senior Endpoint Security Engineer
Crusoe — Tracked from its ashby job board
About the role
Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster.
We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that — with an energy-first approach that makes AI infrastructure better for the world and faster for the people innovating with AI.
We're looking for problem-solving, opportunity-finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved — people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services.
If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high-performing team that believes in each other, come build with us at Crusoe.
About the Role:
Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This is a strategic, architectural position focused on building secure-by-default endpoints that protect the organization as it scales. You will be responsible for security architecture, endpoint visibility, and maintaining our security posture across a rapidly growing global fleet of macOS, Windows, iOS, and Android devices. This role involves cross-functional partnership with Security and People Operations, with genuine scope to shape how Crusoe manages and secures endpoints. This role is onsite in San Francisco, CA, Sunnyvale, CA or Denver CO.
What You'll Be Working On:
- Administer and continuously improve Jamf and Microsoft Intune environments across all managed device types: macOS, Windows, iOS, and Android; maintain configuration profiles, compliance policies, app deployment packages, and OS update enforcement across all platforms.
- Build and maintain automated enrollment workflows including Apple Business Manager (ABM) and Windows Autopilot for zero-touch provisioning at scale.
- Own a structured patch management program with clear SLAs for OS and application updates across all device platforms.
- Define and enforce device compliance baselines aligned with Crusoe security standards and frameworks including CIS Benchmarks and SOC 2; integrate MDM telemetry with EDR and SIEM tooling for compliance drift visibility and proactive remediation.
- Partner with Security on device trust policies, Conditional Access enforcement, certificate-based authentication rollout (SCEP/PKCS), and network-level access control for certificate-based Wi-Fi and VPN authentication.
- Build and maintain scripts and automation in Bash, Python, or PowerShell to reduce manual IT workload; develop self-service tooling that puts routine fixes and software requests directly in employees’ hands.
- Own MDM runbooks, device policy documentation, and asset records; contribute to the standardization of enrollment workflows, naming conventions, and configuration baselines across all platforms.
- Serve as the MDM escalation point in the IT on-call rotation; partner with People Operations on seamless device provisioning and deprovisioning; mentor junior IT team members on endpoint management practices.
What You'll Bring to the Team:
- Foundational Security Experience: Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection.
- Identity & Access Management: Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access).
- MDM/Endpoint Management: 3–6 years of experience with Jamf/Kandji and Microsoft Intune (Autopilot, Compliance Policies, App Protection).
- Independent Engineering: A "Security-First" mindset and proven ability to drive R&D initiatives from planning through implementation independently, with a focus on automating security controls.
- Scripting & Automation: Proficiency in Bash, Python, or PowerShell for device policy automation, packaging, and remediation.
- Infrastructure Knowledge: Strong understanding of certificate infrastructure (SCEP, PKCS) and experience with Absolute for Windows persistence.
- Strong documentation habits, ownership mindset, and ability to communicate technical policies to non-technical stakeholders.
- Bachelor’s degree in IT, Computer Science, or equivalent practical experience.
- OSQuery and CrowdStrike expertise , demonstrable experience leveraging OSQuery for endpoint visibility and administering CrowdStrike for threat detection and response; these are foundational to our security visibility and enforcement strategy.
Bonus Points
- Jamf Pro administration experience: Smart Groups, configuration profiles, and Jamf Connect or equivalent SSO integration.
- Experience with Jamf Protect, Microsoft Defender for Endpoint, or equivalent EDR tooling.
- Familiarity with Linux endpoint management via Fleet, Puppet, or similar.
- Apple Certified Support Professional (ACSP) or equivalent MDM certification.
- Exposure to SIEM tooling and endpoint log pipelines.
- Experience at a high-growth technology company through a period of rapid headcount scaling.
Benefits:
- Competitive compensation and equity packages
- Restricted Stock Units
- Paid time off, paid holidays & leave of absence programs
- Comprehensive health, dental & vision insurance
- Employer contributions to HSA account
- Paid parental leave
- Paid life insurance, short-term and long-term disability
- Professional development & tuition reimbursement
- Mental health & wellness support
- Commuter benefits (parking & transit)
- Cell phone stipend
- 401(k) Retirement plan with company match up to 4% of salary
- Volunteer time off
- Global travel insurance & emergency assistance
- Daily meals allowance
- Additional perks & programs specific to location
Compensation Range
Compensation will be paid in the range of up to $170,000 - $205,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicants knowledge, education, and abilities, as well as internal equity and alignment with market data.
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
What the index says about this role
- First seen by JobLarper — Aug 2, 2026, 6 days ago. Older postings collect hundreds of applicants — a tailored résumé matters more the longer a role has been live.
- No pay range in our index for this listing. Across 108 indexed Security Engineer roles in US that do publish one, the middle half sits between $190k and $300k, median $247k — JobLarper's read of the market, not a figure from Crusoe.
- What Security Engineer roles ask for — across 643 indexed openings: Cloud (45%), Python (41%), REST/APIs (40%), Go (31%), AI/LLM (29%). This posting names Python, REST/APIs, React Native.
- Crusoe is hiring actively — 202 open roles indexed.
Derived from the 27,000 roles JobLarper indexes daily from official company boards — not from the job description above.
More open roles at Crusoe
- Senior Engineering Manager, SDN Control PlaneSan Francisco, CA - US · Sunnyvale, CA - US · Bellevue, WA - US · Manager
- Engineering Manager, SDN Control PlaneSan Francisco, CA - US · Sunnyvale, CA - US · Bellevue, WA - US · Manager
- Commissioning Engineer IIDallas, TX - US · Junior
- AV EngineerSan Francisco, CA - US · Mid
- Operations and Maintenance Technician IAbilene, TX - US · Junior
- Senior Manager, Network & Cloud ArchitectureSan Francisco, CA - US · Sunnyvale, CA - US · Bellevue, WA - US · Manager
- Senior Director, ConstructionSan Francisco, CA - US · Dallas, TX - US · Director+
- Principal Systems Software EngineerSan Francisco, CA - US · Senior+
All 202 open roles at Crusoe →
Similar Security Engineer roles at other companies
- Senior Product Security EngineerFunction Health · US - Remote · Canada - Remote · Remote
- Senior Security Engineer, Incident ResponseAirbnb · United States
- Staff Product Security EngineerChainguard · United States - Remote · Remote
- Security EngineerCognition · San Francisco
- Staff Security Engineer - IAMAledade · Austin, TX · Remote
- Endpoint Security EngineerSapphire Digital, Part of Zelis · India Hyderabad
- Senior Database Security EngineerAmerican Express · Phoenix, AZ, United States
- Data Security EngineerFiserv · Columbus, Ohio, United States of America
Browse all security engineer jobs in united states — 373 open roles across 191 companies.