Senior Security Engineer, Endpoint

Ramp · New York, NY (HQ) · $172K – $236K · Engineering

Posted 2026-07-08

17% above the median for Senior Engineering roles

Apply for this role →

ABOUT THE ROLE

You'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD mobile devices. You'll build secure-by-default controls with Terraform and GitOps, harden endpoints at scale, and automate the full device lifecycle so nothing depends on a human remembering to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers, and raise the bar on what "low-friction security" actually means. Everything you ship will be auditable, measurable, and built for the long run.

We're also thinking seriously about how corporate security evolves in an agentic world — where AI agents act on behalf of employees and traditional identity and endpoint assumptions break down. You'll help us shape that answer.

WHAT YOU’LL DO

- Write and ship MDM policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS, Windows, and mobile — with staged rollouts and rollback from day one

- Build patch automation that closes exposure windows fast without making employees' lives worse

- Manage software distribution across the fleet

- Mine fleet telemetry for signal — build dashboards, drift alerts, and AI-assisted automation that cuts toil before it compounds

- Own managed browser and extension policy: enforce what's allowed, block what isn't, and keep the control plane auditable as the surface grows

- Be the last line of defense on endpoint escalations that IT Operations can't crack

WHAT YOU NEED

- Deep macOS security experience — Jamf Pro, FleetDM, or equivalent MDM at scale

- Strong IaC fundamentals and a GitOps delivery model — Terraform modules, remote state, and CI pipelines shipped through MRs and code review, not tickets and manual steps

- Solid working knowledge of Google Workspace in a managed enterprise environment, including Chrome Browser Cloud Management and extension policy enforcement

- A point of view on how agentic AI changes the corporate security surface

NICE-TO-HAVES

- Have shipped real work with open source endpoint and device management tooling

- Have built automated, progressive rollout systems based on fleet telemetry.

- Have managed a mixed fleet — macOS, Windows, and mobile — with real depth on at least one platform

- Have put AI to work on real operational problems, not just prototyped

Apply for this role →

← Back to all jobs