IT Client Engineer

Figure AI
San Jose, CA
On-site

Who this role is best for

Best suited to engineers with endpoint management and identity automation expertise working in AI robotics and commercial manufacturing environments.

Best fit for

  • Candidates with cross-platform endpoint automation and security benchmark implementation experience
    — “Translate CIS Benchmarks into deployable configuration profiles across all platforms
  • Individuals who can replace manual IT processes with code and enforce technical controls
    — “replace manual IT work with code
  • Engineers comfortable with high-IP-risk environments and device lifecycle management
    — “Build hardened device configurations for factories, contract manufacturers, and low-connectivity sites

Things to consider

  • Requires consistent in-office presence for collaboration and hands-on work
    — “require 5 days/week in-office collaboration
  • Strong emphasis on security-sensitive systems with real business consequences
    — “owning a security-sensitive program with real business consequences

How to stand out

  • Highlight experience with zero-touch enrollment and endpoint automation tools like FleetDM
    — “Own zero-touch enrollment end to end: Apple Business Manager for macOS, Windows Autopilot for Windows
  • Demonstrate ability to translate security and compliance policies into technical implementations
    — “Translate data handling and IP protection requirements into enforceable technical controls
  • Showcase scripting experience in Python, Bash, or PowerShell with automation examples
    — “Build tooling in Python, Bash, or PowerShell to eliminate manual work
  • Emphasize experience with SSO integration and identity lifecycle automation on Okta
    — “Own SSO integration of applications into Okta (SAML and OIDC)
  • Demonstrate track record of documenting standards and runbooks for IT teams
    — “Document standards, runbooks, and automation so the broader IT team can operate
Pace · Fast PacedCollaboration · HighAutonomy · MediumDecision Impact · Team

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • secure device management
  • automated identity lifecycle
  • reduced manual IT work
Typical background
systems administrationsoftware engineering

Skills & requirements

Required

Endpoint ManagementSSO IntegrationAutomationScripting

Preferred

Cloud ServicesNetwork Security

About the role

Original posting from Figure AI via Greenhouse

Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It's time to build!

We are looking for a Client Engineer to own Figure's endpoint fleet everywhere it operates: our San Jose campus, our factories, our contract manufacturing partners, and connectivity-challenged field sites. Figure's most valuable asset is the design and software behind our humanoid, and this role is the technical owner of the controls that keep that IP on the devices, in the environments, and in the hands we intend. You will work closely with our Information Security team to define how devices are issued, hardened, monitored, and recovered; what data is allowed to land on them; and how quickly we can detect and cut off exposure when something goes wrong, whether the device sits on the corporate network or offline on a factory floor.

You are also the technical lead for client-side infrastructure company-wide. You will run endpoint management across macOS, Windows 11 Pro, and Ubuntu LTS, own SSO integration and identity lifecycle automation on Okta, and replace manual IT work with code. The ideal candidate is an engineer first and a systems administrator second: someone who responds to a repeated ticket by writing the script that eliminates it, documents the result, and is comfortable owning a security-sensitive program with real business consequences.

Responsibilities

Endpoint Engineering

Own zero-touch enrollment end to end: Apple Business Manager for macOS, Windows Autopilot for Windows, and PXE provisioning for Ubuntu workstations

Translate CIS Benchmarks into deployable configuration profiles across all platforms: deterministically applied settings accompanied with osquery validations to validate posture

Operate FleetDM as the cross-platform management agent across macOS, Windows, and Ubuntu LTS

Maintain standard, reproducible workstation builds with measured and enforced patch compliance

Build hardened device configurations for factories, contract manufacturers, and low-connectivity sites: loaner and clean-device programs, encryption enforcement and escrow, conditional access, and remote wipe and recovery

Deploy and maintain CrowdStrike Falcon coverage across the fleet in partnership with Security, closing gaps on unmanaged or drifted devices

Translate data handling and IP protection requirements from Security, Legal, and Engineering leadership into enforceable technical controls

Identity and SSO Engineering

Own SSO integration of applications into Okta (SAML and OIDC), including internal tools with no vendor documentation

Design application authentication and RBAC from first principles, in coordination with Security

Automate the identity lifecycle end to end: provisioning, entitlement, and deprovisioning driven by Okta Workflows and integrated with Google Workspace, Slack, and Jira

SaaS Operations and Automation

Build tooling in Python, Bash, or PowerShell to eliminate manual work across onboarding, offboarding, provisioning, reporting, and audit

Run license and access audits, surface inactive accounts and orphaned entitlements, and drive cost recovery with Procurement

Formalize change management for endpoint and SaaS changes and participate in the Change Advisory Board

Document standards, runbooks, and automation so the broader IT team can operate and extend what you build

Act as escalation point for complex client-side issues and mentor Operations Specialists

Qualifications

Hands-on experience managing macOS, Windows, and Linux (Ubuntu LTS) endpoint fleets in production

Practical experience with zero-touch enrollment and modern endpoint tooling: FleetDM or comparable osquery-based management, Apple Business Manager, Windows Autopilot or Microsoft Intune

Experience turning security benchmarks (CIS or similar) into enforced, validated configuration policy

Strong scripting skills in Python, Bash, and/or PowerShell, with a track record of replacing manual processes with code

Working knowledge of authentication fundamentals: SAML, OIDC, SCIM, and the tradeoffs between them

Experience administering identity and SaaS platforms at scale: Okta, Google Workspace, Slack, Jira, including SCIM and API-driven provisioning

Sound judgment on security and risk tradeoffs, and the ability to explain technical controls to non-technical stakeholders

Detail-oriented and process-driven, particularly in documenting standards and policy

Great communication, collaboration, and interpersonal skills

Bonus Qualifications

Experience supporting devices or users at manufacturing sites, contract manufacturers, or other high-IP-risk environments

Familiarity with export control, data residency, or IP protection frameworks in hardware and software R&D

Experience with employee-built AI applications: assess authentication and permissions risk, and redirect requests to a Security consult

Experience deploying or operating EDR agents at fleet scale (CrowdStrike Falcon or similar)

Experience building integrations against SaaS APIs and identity providers

Experience supporting engineering workloads on Linux, including workstation and build-host management

Experience standing up IT capability at new sites, or supporting international growth remotely from a central location

Source: Figure AI careers (Greenhouse)

Similar roles