Senior Client Platform Engineer

Okta Okta · Enterprise · San Francisco, CA · BT Workplace Technology-140

Okta is seeking a Senior Client Platform Engineer to manage and secure their macOS, iOS, Windows, and Linux endpoints. This role involves implementing automation-first strategies, using tools like Jamf Pro, Munki, Santa, and FleetDM, and ensuring endpoints meet security and compliance standards. The engineer will also act as 'Customer Zero', testing new Okta product features and providing feedback to internal product teams, contributing to the company's identity and device management offerings.

What you'd actually do

  1. Own the global macOS and iOS fleet using Jamf Pro, overseeing enrollment, configuration profiles, and application deployment.
  2. Contribute to the management and security of Windows (via Intune/Autopilot) and Linux endpoints as the program evolves, ensuring a consistent security posture across all OS types.
  3. Administer open-source tools (Munki, Santa) and lead evaluations of emerging platforms like FleetDM to enhance cross-platform fleet visibility.
  4. Ensure endpoints meet NIST, CIS, and STIG standards. Partner with Security teams to respond to vulnerabilities across the entire fleet.
  5. Apply an IaC mindset to device management using code-based workflows (e.g., Terraform, Ansible, or Jamf API). Build and maintain CI/CD pipelines to ensure repeatable, scalable, and automated deployments regardless of the OS.

Skills

Required

  • 5+ years in endpoint engineering with a focus on Apple platforms at enterprise scale.
  • Strong understanding of Windows and Linux operating systems.
  • Deep expertise in Jamf Pro.
  • Proficiency in Bash, Python, Go, or Swift.
  • Experience with Git, GitHub Actions, Terraform, or similar CI/CD frameworks.
  • Understanding of ADE/DEP, MDM protocols, and platform-specific hardening (e.g., BitLocker, FileVault, LUKS).
  • Familiarity with SAML and OIDC and how they integrate with endpoint authentication.
  • Ability to submit documentation establishing U.S. Person status.

Nice to have

  • Familiarity with Microsoft Intune or other cross-platform MDM/UEM solutions.
  • PowerShell experience.
  • Hands-on experience with FleetDM or osquery for multi-OS visibility.
  • Experience with Autopkg pipelines or AWS Lambda for endpoint automation.
  • Background in Federal compliance (FedRAMP).
  • Relevant certifications (Apple, Okta, Microsoft, AWS, Jamf).

What the JD emphasized

  • Customer Zero
  • macOS and iOS fleet
  • Windows and Linux management workflows
  • Apple ecosystem
  • Apple expertise
  • Apple platforms at enterprise scale
  • Windows and Linux operating systems
  • Jamf Pro
  • federal environments
  • protected federal data
  • U.S. Person status