Back to jobs
New

IT Client Engineer

San Jose, CA

Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It's time to build!

We are looking for a Client Engineer to own Figure's endpoint fleet everywhere it operates: our San Jose campus, our factories, our contract manufacturing partners, and connectivity-challenged field sites. Figure's most valuable asset is the design and software behind our humanoid, and this role is the technical owner of the controls that keep that IP on the devices, in the environments, and in the hands we intend. You will work closely with our Information Security team to define how devices are issued, hardened, monitored, and recovered; what data is allowed to land on them; and how quickly we can detect and cut off exposure when something goes wrong, whether the device sits on the corporate network or offline on a factory floor.

You are also the technical lead for client-side infrastructure company-wide. You will run endpoint management across macOS, Windows 11 Pro, and Ubuntu LTS, own SSO integration and identity lifecycle automation on Okta, and replace manual IT work with code. The ideal candidate is an engineer first and a systems administrator second: someone who responds to a repeated ticket by writing the script that eliminates it, documents the result, and is comfortable owning a security-sensitive program with real business consequences.

Responsibilities

Endpoint Engineering

  • Own zero-touch enrollment end to end: Apple Business Manager for macOS, Windows Autopilot for Windows, and PXE provisioning for Ubuntu workstations
  • Translate CIS Benchmarks into deployable configuration profiles across all platforms: deterministically applied settings accompanied with osquery validations to validate posture
  • Operate FleetDM as the cross-platform management agent across macOS, Windows, and Ubuntu LTS
  • Maintain standard, reproducible workstation builds with measured and enforced patch compliance
  • Build hardened device configurations for factories, contract manufacturers, and low-connectivity sites: loaner and clean-device programs, encryption enforcement and escrow, conditional access, and remote wipe and recovery
  • Deploy and maintain CrowdStrike Falcon coverage across the fleet in partnership with Security, closing gaps on unmanaged or drifted devices
  • Translate data handling and IP protection requirements from Security, Legal, and Engineering leadership into enforceable technical controls

Identity and SSO Engineering

  • Own SSO integration of applications into Okta (SAML and OIDC), including internal tools with no vendor documentation
  • Design application authentication and RBAC from first principles, in coordination with Security
  • Automate the identity lifecycle end to end: provisioning, entitlement, and deprovisioning driven by Okta Workflows and integrated with Google Workspace, Slack, and Jira

SaaS Operations and Automation

  • Build tooling in Python, Bash, or PowerShell to eliminate manual work across onboarding, offboarding, provisioning, reporting, and audit
  • Run license and access audits, surface inactive accounts and orphaned entitlements, and drive cost recovery with Procurement
  • Formalize change management for endpoint and SaaS changes and participate in the Change Advisory Board
  • Document standards, runbooks, and automation so the broader IT team can operate and extend what you build
  • Act as escalation point for complex client-side issues and mentor Operations Specialists

Qualifications

  • Hands-on experience managing macOS, Windows, and Linux (Ubuntu LTS) endpoint fleets in production
  • Practical experience with zero-touch enrollment and modern endpoint tooling: FleetDM or comparable osquery-based management, Apple Business Manager, Windows Autopilot or Microsoft Intune
  • Experience turning security benchmarks (CIS or similar) into enforced, validated configuration policy
  • Strong scripting skills in Python, Bash, and/or PowerShell, with a track record of replacing manual processes with code
  • Working knowledge of authentication fundamentals: SAML, OIDC, SCIM, and the tradeoffs between them
  • Experience administering identity and SaaS platforms at scale: Okta, Google Workspace, Slack, Jira, including SCIM and API-driven provisioning
  • Sound judgment on security and risk tradeoffs, and the ability to explain technical controls to non-technical stakeholders
  • Detail-oriented and process-driven, particularly in documenting standards and policy
  • Great communication, collaboration, and interpersonal skills

Bonus Qualifications

  • Experience supporting devices or users at manufacturing sites, contract manufacturers, or other high-IP-risk environments
  • Familiarity with export control, data residency, or IP protection frameworks in hardware and software R&D
  • Experience with employee-built AI applications: assess authentication and permissions risk, and redirect requests to a Security consult
  • Experience deploying or operating EDR agents at fleet scale (CrowdStrike Falcon or similar)
  • Experience building integrations against SaaS APIs and identity providers
  • Experience supporting engineering workloads on Linux, including workstation and build-host management
  • Experience standing up IT capability at new sites, or supporting international growth remotely from a central location

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf