About the role
About the role We are seeking an experienced Senior Systems Engineer to own our macOS platform and drive endpoint management and device trust standards across Chime’s IT ecosystem. As a Senior Systems Engineer, you will drive multi-system initiatives across our IT domains – endpoint management, identity, and security tooling – with a primary focus on macOS and Jamf Pro. You’ll establish the technical standards other engineers work to, and partner cross-functionally on programs that affect IT Support, Security, and every Chimer with a laptop. This is a role for someone who thrives in ambiguity: you’ll often define the problem before solving it, and align stakeholders around a technical direction rather than waiting for a specification. We believe a secure access platform can be built entirely in the cloud, leveraging tools such as Jamf, AutoPkg, Okta, osQuery, and CrowdStrike. Pairing closely with our Security team, this role makes sure our fleet stays in sync with all policies and posture checks before devices are allowed access to corporate data. This role participates in an after-hours/on-call rotation for critical endpoint and device-management issues. Rotation frequency, response expectations, and escalation procedures will be communicated during the interview process. This position will report to the IT Engineering Manager. The base salary offered for this role and level of experience will begin at $152,000.00 and up to $210,000.00 . Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience. In this role, you can expect to macOS Platform and Endpoint Management Platform Ownership: Own the technical direction, operation, and continuous improvement of our Jamf Pro environment, including configuration profiles, smart groups, policies, MDM commands, and change standards. Software Delivery: Own our AutoPkg-based software pipeline: recipes, overrides, trust verification, and automated import into Jamf, alongside packaging, deployment, patch management, and disk encryption across the global macOS fleet. Automation & Reusable Tooling: Build automations and shared tooling that accelerate work beyond your own – scripts, patterns, and integrations other IT engineers can adopt rather than rebuild. Provisioning: Own zero-touch provisioning and device enrollment (Automated Device Enrollment, Setup Assistant, bootstrap workflows) so new Chimers are productive on day one. Scripting & API Integration: Use scripting and general-purpose languages (Python, Swift, Bash, Go) and vendor APIs to create custom integrations and eliminate manual IT operations. Security, Governance, and Compliance Security Posture: Partner with Security to identify and mitigate risks to the fleet, enforcing a Zero Trust / BeyondCorp model through device trust, adaptive authentication, and least-privilege access. Device Trust: Connect device management to our identity provider (Okta) so device posture is a factor in authentication and application access. Compliance: Implement compliance processes and tooling to report configuration status, and assess and implement benchmark standards (e.g., CIS) against a documented, risk-based rationale. Reporting: Develop metrics and reporting reflecting the inventory, health, and compliance state of all devices. Troubleshooting: Serve as the Tier 3 escalation point for complex endpoint issues. Standards, Collaboration, and Mentorship Technical Standards: Establish and document the endpoint standards the broader IT organization works to, and raise the bar on testing, monitoring, and maintainability through example and influence. Cross-Functional Delivery: Lead initiatives spanning IT Support, Security, and People teams – reconciling competing priorities and keeping stakeholders aligned from planning through rollout. Mentorship: Mentor peers, engineers, and technicians through technical guidance, documentation, enablement, and example. Support Enablement: Work with IT Support to identify pain points and implement systemic fixes that reduce ticket load rather than absorbing it. To thrive in this role, you have Experience: 8+ years of hands-on experience managing macOS at scale with enterprise MDM (e.g., Jamf Pro, Kandji, Mosyle) and/or open-source tooling (e.g., Munki, Puppet, Chef). AutoPkg: Production experience building and operating AutoPkg recipes, overrides, trust controls, and automated promotion into an enterprise MDM environment is required. Apple Platform Depth: In-depth understanding of Apple’s MDM protocol and Configuration Profile specifications, including the shift to Declarative Device Management. macOS Fundamentals: In-depth understanding of installers and packages, LaunchDaemons and LaunchAgents, the preferences subsystem, system extensions, macOS built-in security tooling (Endpoint Security Framework, SIP, XProtect, Gatekeeper, openBSM), and unified logs. Scripting: Proficiency in at least one general-purpose or scripting language (e.g., Python, Swift, Bash, Go) for API interaction and automation. Security Model: Solid understanding of Zero Trust / BeyondCorp concepts and how endpoint posture feeds identity-based access decisions. Cross-Domain Judgment: Track record of decisions spanning multiple systems, balancing scalability, compliance, cost, and long-term maintainability. Working in Ambiguity: Comfort defining a problem before solving it, and aligning stakeholders around a technical direction. Communication: Excellent written and verbal communication for technical and non-technical audiences, including the structured documentation that scales understanding across a distributed team. Nice-to-have Jamf Certified Admin (300/400) or equivalent demonstrated mastery of those knowledge domains. Familiarity with Windows endpoint management (Intune/Endpoint Manager, PowerShell, MSI packaging, WMI, registry) – Windows is a smaller part of our fleet. Experience with Infrastructure as Code (e.g., Terraform) for managing SaaS and MDM configuration. Experience with osQuery, CrowdStrike, or comparable endpoint telemetry and EDR tooling. Experience integrating endpoint management with Okta for device trust and conditional access. #LI-Onsite #LI-WS1 A little about us At Chime, we believe that everyone can achieve financial progress. We created Chime—a financial technology company, not a bank*—on the premise that core banking services should be helpful, easy, and free. Through our user-friendly tools and intuitive platforms, we empower our members to take control of their finances and work towards their goals. Whether it's starting a savings account, purchasing a first car or home, launching a business, or pursuing higher education, we're proud to have helped millions unlock their financial potential. We're a team of problem solvers, dreamers, and builders with one shared obsession: our members. From day one, Chimers have worked tirelessly to out-hustle and out-execute competitors to bring our mission to life. Their grit and determination inspire us to work harder every day to deliver the very best experience possible. We each bring an owner's mindset to our work, refusing to be outdone and holding ourselves accountable to meet and exceed the highest bars for our teams, our company, and our members. We believe in being bold, dreaming big, and taking risks, while also working together, embracing our diverse perspectives, and giving each other honest feedback. Our culture remains deeply entrepreneurial, encouraging every Chimer to see themselves as stewards of our mission to help everyday Americans unlock their financial progress. We know that to achieve our mission, we must earn and keep people's trust—so we hold ourselves to the highest standards of integrity in everything we do. These aren't just words on a wall—our values are embedded in every aspect of our business, serving as a north star that guides us as we work to help millions achieve their financial potential. Because if we don't—who will? *Chime is a financial technology company, not a bank. Banking services provided by The Bancorp Bank, N.A. or Stride Bank, N.A., Members FDIC. What we offer for our full-time, regular employees 🏢 Our in-office work policy is designed to keep you connected - with four days a week in the office and Fridays from home for those near one of our offices, plus team and company-wide events depending on location. Whether you’re coming in regularly or are part of our fully remote program, you’ll stay engaged with your work and teammates. 💻 Benefits that support your work and life, including backup child, elder, and pet care and subsidized commuter benefits for eligible employees. ✨ Comprehensive health, financial, and wellbeing benefits designed to support you at every stage of life. 🏝 Generous vacation policy and company-wide paid days off 🫂 1% of your time off to support local community organizations of your choice 👟 Annual wellness stipend to use towards eligible wellness related expenses 👶 Up to 22 weeks of paid parental leave for birthing parents and 12 weeks of paid parental leave for non-birthing parents 👪 Access to family planning reimbursement 💚 A challenging and fulfilling opportunity to join one of the most experienced teams in FinTech and help millions unlock financial progress We know that great work can’t be done without a diverse team and inclusive environment. That’s why we specifically look for individuals of varying strengths, skills, backgrounds, and ideas to join our team. We believe this gives us a competitive advantage to better serve our members and helps us all grow as Chimers and individuals. Chime is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the San Francisco Fair Chance Ordinance, Cook County Ordinance, NYC Fair Chance Act, and the LA City Fair Chance Ordinance, and consistent with Canadian provincial and federal laws. If you have a disability or special need that requires accommodation during any stage of the application process, please contact: accommodations@chime.com . To learn more about how Chime collects and uses your personal information during the application process, please see the Chime Applicant Privacy Notice .