Legora Logo

Legora

Endpoint Engineer

Posted 18 Minutes Ago
Be an Early Applicant
In-Office
New York City, NY
216K-254K Annually
Senior level
In-Office
New York City, NY
216K-254K Annually
Senior level
Own and build Legora’s macOS endpoint platform: manage configuration-as-code and MDM as a production service, automate device lifecycle and binary authorization, implement continuous posture evaluation and telemetry-driven compliance, build AI-assisted operational automations, and define the endpoint roadmap working across IT, security, and engineering.
The summary above was generated by AI
About Us

Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.

  • We lean in: ownership over titles, outcomes over intentions.

  • We fight for excellence: high standards, direct, ego-free feedback.

  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.

If you’re driven by impact, pace, and raising the bar. This is the place.

About the team

The IT and AI Enablement function exists to make Legora itself run as well as the product we sell: secure, automated, and compounding over time. We run an Apple-first fleet as a distributed platform: endpoint configuration, security policy, and software delivery move through version control with review, testing, staged rollout, and a way back. The Endpoint Engineer owns that platform: the machinery that turns a new Mac into a secure, working laptop and keeps every device in the fleet provably healthy. You’ll work across IT Systems, Workplace Technology, Information Security, and Engineering, and you’ll set the endpoint roadmap.

What you’ll be doing
  • Manage endpoint configuration as code: author, review, test, and progressively deploy macOS profiles, declarations, security baselines, and remediation scripts, with staging, canary groups, telemetry-based promotion, and rollback built into every change. Own the migration from legacy payloads to declarative management as Apple retires the MDM equivalents.

  • Run MDM as a production service: configuration as code, observability, reliability, upgrades, and incident response, plus the integrations that connect it to identity, security, and IT systems. Lead platform evaluations and migrations end to end when the tooling needs to change.

  • Automate the device lifecycle: zero-touch provisioning through Apple Business Manager and Automated Device Enrollment, declarative software update enforcement on timelines that hold without wrecking the employee experience, software packaging and distribution, and secure deprovisioning.

  • Own binary authorization: the policy model, rule distribution, application approvals, telemetry, and the synchronisation service behind it. Take a view on where macOS 27’s native binary allow/deny fits against a dedicated binary-authorization stack.

  • Build continuous posture evaluation: evaluate device health live (enrolment, OS and patch state, disk encryption, endpoint protection, control status, configuration drift) from real-time status subscriptions rather than polling, remediate automatically where you can, and produce the posture signal Corporate Security gates access on.

  • Turn fleet telemetry into decisions: query device state at scale and drive it into dashboards, compliance reporting, and early warning on drift, feeding endpoint telemetry to Detection & Response for detection and incident work.

  • Build AI-assisted operations: put agents and LLMs on the repetitive operational work so reliability scales with the fleet. Anything manual twice a quarter gets automated.

  • Define the endpoint roadmap: evaluate technologies, make the architecture calls, and take on the macOS and endpoint-platform problems that standard support paths can’t resolve.

Who you are
  • 8+ years building and operating secure endpoint or IT systems in complex environments, including a large macOS fleet on a modern MDM, owning the platform as the final escalation point, with no endpoint engineer above you to hand it to.

  • A builder first: you write production-grade code (Python at least; Swift or Go for endpoint tooling is a bonus) and treat endpoint configuration as software you own, with tests, review, and observability, not a console you administer.

  • AI-first by conviction: you already reach for agents and LLMs (Claude Code and the like) to compress operational toil, and you have a clear view on where they’re trustworthy and where a human owns the call. Show us something you automated that used to eat your week.

  • Deep on macOS internals: launchd, configuration profiles, TCC, system extensions, Endpoint Security, FileVault, Secure Token and bootstrap tokens.

  • Fluent in declarative device management, not just profiles: you know where Apple has moved configuration to declarations and can plan a migration off the payloads being retired. Legacy software update management no longer functions in the 27 release, so declarative enforcement is the only supported path.

  • Disciplined about change: you’ve shipped endpoint changes through Git-based workflows with staging, canary, and rollback, and you’d rather find a regression in a canary group than in the all-hands channel.

  • A product-engineering mindset toward IT: reliability, observability, controlled change, and documentation others can operate from: architecture diagrams, runbooks, and decisions written down.

  • Clear with both audiences: you can take a technical stakeholder through the architecture and a non-technical colleague through what’s changing on their laptop and why.

Nice to have
  • Fleet: deploying, operating, or contributing to Fleet, including its MDM, osquery, GitOps, software-management, and vulnerability-management capabilities.

  • Leading a production MDM migration, particularly with Apple Business Manager and Automated Device Enrollment in play.

  • Operating Santa at scale: rule management, binary authorization policy, event telemetry, and a Rudolph synchronisation service.

  • Managing macOS through Jamf or Kandji (now Iru), and Windows through Intune where the fleet calls for it.

  • Fleet-scale querying with osquery, and turning that data into compliance and drift reporting.

  • Declarative credentials: ACME, SCEP, and identity credentials declared once as reusable assets and referenced across network configurations, rather than embedded per profile.

  • Moving network, VPN/DNS, extensible SSO, content caching, and web content filtering onto declarative configurations.

  • Operating an MDM service against Apple’s stricter TLS and App Transport Security requirements.

  • Progressive delivery for endpoints: automated rollout with staging, canary groups, telemetry-based promotion, and rollback.

  • Device trust and continuous posture evaluation integrated with an identity provider and conditional access.

  • Infrastructure as code (Terraform or similar) and public-cloud fundamentals: serverless, containers, managed databases, monitoring.

  • Deploying, operating, or contributing to open-source macOS endpoint management and security tooling.

  • Experience with Okta, Microsoft Entra ID, 1Password, CrowdStrike, Jamf, Apple Business Manager, Lumos, and our AI-native ITSM (Serval).

What’s In It For You
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.

  • Competitive package: Comprehensive salary, benefits, and tools for success.

  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.

  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.

  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision

    • Multiple medical plan options through Aetna and Kaiser Permanente

    • HSA or Healthcare FSA (based on plan selection)

    • Dental plans via MetLife

    • Vision plans via Vision Care

    Family Support

    • Generous parental leave

    • Free access to Maven Clinic

    • Dependent Care FSA

    • Free One Medical membership for employees and dependents

    Additional Perks

    • Pre-tax commuter benefits

    • Life Insurance + STD/LTD

    • 401(K) with generous company match

    • Unlimited PTO

    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer

At Legora, we believe great teams are built on diversity of thought and experience. We’re proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don’t discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.

Legora San Francisco, California, USA Office

2 Embarcadero Ctr, San Francisco, California, United States, 94111

Similar Jobs at Legora

8 Hours Ago
In-Office
204K-240K Annually
Senior level
204K-240K Annually
Senior level
Artificial Intelligence • Legal Tech • Software
Serve as the technical services voice in enterprise sales, draft and automate technical RFP responses (security, architecture, implementation), align pre-sale promises with delivery, enable partners and sales with capability materials, and build/own an automated human-in-the-loop RFP system.
Top Skills: AIGdprIso 27001Rfp AutomationSoc 2
18 Hours Ago
In-Office
204K-276K Annually
Senior level
204K-276K Annually
Senior level
Artificial Intelligence • Legal Tech • Software
The Senior Product Manager will own the product strategy for enterprise-facing solutions, focusing on integrations, and ensure long-term customer value through collaboration with various teams.
Top Skills: APIsB2B SaasIntegrationsPlatform Products
18 Hours Ago
In-Office
128K-150K Annually
Mid level
128K-150K Annually
Mid level
Artificial Intelligence • Legal Tech • Software
As a GTM Systems Analyst, you'll enhance Salesforce and support revenue systems, focusing on integrations and revenue process enablement across various platforms.
Top Skills: ApexBillingCpqFlowsGongLwcsSalesforceStripe

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account