IT Systems Engineer, Client Platform Engineer, macOS
About the role
The Endpoint team (Client Platform Engineering) treats Anthropic's device fleet as a platform we build and run. We run our own MDM as a production service and manage every piece of device configuration as code. Policies, configuration profiles, queries, remediation scripts, and software all ship through pull requests, CI, a staging environment, and a canary group before they reach the fleet. The fleet is mostly macOS, plus a small number of Linux machines and a growing mobile footprint.
You'll own that platform end to end: the infrastructure underneath the MDM, the configuration on top of it, the patching and software pipelines that keep thousands of devices patched and secure, and the telemetry that tells us what is actually true on every device. You'll also build automation that cuts down on manual operational work. You'll work with Security teams on hardening, compliance controls, and detection and response, and with developer and infrastructure teams to make sure those controls don't get in the way of their work. Your work will let us base access decisions on whether a device can be trusted.
We value people who double check a compliance report before they believe it. The team is deliberately lean and runs with high autonomy. You'll help define the endpoint roadmap, make architecture decisions, and own the platform every Anthropic employee's work runs on. You'll also help us meet the security standards our Responsible Scaling Policy requires as models advance.
Responsibilities
Own endpoint configuration as code: author, review, test, and progressively roll out MDM policies, configuration profiles, and remediation scripts across macOS and mobile, with canary stages and rollback built in
Operate the MDM platform itself as a production service, including infrastructure as code, observability, upgrades, and incident response
Build patch management automation with rapid enforcement timelines while maintaining good user experience
Design zero touch provisioning that turns a sealed box into a productive machine on day one
Support a small number of Linux machines alongside the Mac fleet
Turn fleet telemetry into policy, dashboards, and early drift warnings, and use Claude to automate manual ops work
Partner with Corporate Security on endpoint hardening, binary authorization, and compliance controls
Take shifts on the team's rotation for incoming requests and escalations, and serve as the deep escalation tier for endpoint issues IT Operations can't resolve
You may be a good fit if you
Have 8+ years building secure IT systems in complex environments, including leading projects across multiple teams
Have managed endpoint fleets of thousands of macOS devices through a modern MDM
Treat endpoint configuration as code that is version controlled and peer reviewed, rather than clicking in consoles
Go deep on macOS internals such as launchd, configuration profiles, TCC, and system extensions
Write Python and shell scripts
Write design docs and runbooks so teammates can review and support what you build
Strong candidates may also have
Have operated an MDM or device management platform as a service, not only consumed one as SaaS
Have worked with open source endpoint and device management tooling (Munki, osquery, AutoPkg)
Have built automated, progressive rollout systems with promotion gated on telemetry
Have experience running infrastructure as code in a public cloud
Have working knowledge of Linux administration (packaging, systems, config management)
Have used LLMs to automate ops work
Deadline to apply: None. Applications will be received on a rolling basis.
The annual compensation range for this role is listed below.
For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.
Annual Salary:
$285,000—$325,000 USD