The opportunity
Crusoe is on a mission to accelerate the abundance of energy and intelligence . As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads.
What you'll do
Administer and continuously improve Jamf and Microsoft Intune environments: across all managed device types: macOS, Windows, iOS, and Android; maintain configuration profiles, compliance policies, app deployment packages, and OS update enforcement across all platforms.
Build and maintain automated enrollment workflows including Apple Business: Manager (ABM) and Windows Autopilot for zero-touch provisioning at scale.
Own a structured patch management program with clear SLAs for OS and: application updates across all device platforms.
Define and enforce device compliance baselines aligned with Crusoe security: standards and frameworks including CIS Benchmarks and SOC 2; integrate MDM telemetry with EDR and SIEM tooling for compliance drift visibility and proactive remediation.
Partner with Security on device trust policies, Conditional Access: enforcement, certificate-based authentication rollout (SCEP/PKCS), and network-level access control for certificate-based Wi-Fi and VPN authentication.
Build and maintain scripts and automation in Bash, Python, or PowerShell to: reduce manual IT workload; develop self-service tooling that puts routine fixes and software requests directly in employees’ hands.
What they're looking for
- Own MDM runbooks, device policy documentation, and asset records; contribute: to the standardization of enrollment workflows, naming conventions, and configuration baselines across all platforms.
- Serve as the MDM escalation point in the IT on-call rotation; partner with: People Operations on seamless device provisioning and deprovisioning; mentor junior IT team members on endpoint management practices.
- Foundational Security Experience: Demonstrated experience with OSQuery and CrowdStrike (XDR/EDR) for endpoint visibility and threat detection.
- Identity & Access Management: Deep understanding of Okta (Device Trust/FastPass) and Entra ID (Conditional Access).