Thinking Machines Lab is an AI research lab founded by Mira Murati that develops frontier AI models and researcher tools such as Tinker.
<div class="content-intro"><p data-pm-slice="1 1 []">Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals. </p> <p>We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.</p></div><h3><strong>About the Team</strong></h3> <p>The IT team builds secure infrastructure and efficient processes that enable our employees to move quickly. We operate an all-Mac environment and manage our endpoint fleet as a distributed platform, applying production-engineering practices to device management and security.</p> <p>Our endpoint configurations, security policies, scripts, and software deployments are increasingly managed through version-controlled workflows with testing, review, staged rollouts, and rollback capabilities. This role will work closely with IT, Security, Identity, and Infrastructure to deliver a secure and reliable employee computing experience.</p> <h3><strong>What You’ll Do</strong></h3> <ul> <li><strong>Endpoint Configuration as Code:</strong> Author, review, test, and progressively deploy macOS configuration profiles, security policies, queries, and remediation scripts. Build code review, staging, canary, validation, and rollback processes into endpoint changes.</li> <li><strong>MDM Platform Engineering:</strong> Operate our MDM platform as a production service, including configuration as code, observability, upgrades, reliability, incident response, and integrations with other IT and Security systems.</li> <li><strong>MDM Migration:</strong> Lead the evaluation, design, testing, and execution of our planned migration from Iru to Fleet. Establish functional requirements, identify configuration and security-control gaps, develop a phased migration plan, and move the fleet with minimal disruption to employees.</li> <li><strong>Santa and Rudolph:</strong> Own the architecture and operation of Santa and its Rudolph synchronization service. Manage binary-authorization policies, rule distribution, application approvals, telemetry, observability, infrastructure, and incident response.</li> <li><strong>Zero Trust and Device Trust:</strong> Partner closely with Security and Identity to make device trust a core component of our Zero Trust architecture. Integrate endpoint posture signals into authentication, authorization, and conditional-access decisions.</li> <li><strong>Continuous Posture Evaluation:</strong> Build systems that continuously evaluate device health and security posture, including MDM enrollment, OS version, patch status, disk encryption, endpoint protection, security-control status, and configuration compliance. Automatically identify and remediate drift or restrict access when a device no longer meets requirements.</li> <li><strong>Patch Management:</strong> Build and maintain automated macOS patching workflows that support rapid enforcement timelines while providing a thoughtful employee experience.</li> <li><strong>Zero-Touch Provisioning:</strong> Design and improve Apple Business Manager and Automated Device Enrollment workflows that turn a new Mac into a secure, fully configured, and productive machine with minimal manual intervention.</li> <li><strong>Software Distribution:</strong> Own application packaging, deployment, updating, and removal across the Mac fleet.</li> <li><strong>Fleet Telemetry and Compliance:</strong> Query live device state at scale and turn endpoint telemetry into actionable policies, dashboards, compliance reporting, and early warnings for configuration drift.</li> <li><strong>Automation:</strong> Build tools and AI-assisted workflows that reduce repetitive operational work and make endpoint management more reliable and scalable.</li> <li><strong>Endpoint Security:</strong> Partner with Security on macOS hardening, binary authorization, vulnerability management, compliance controls, detection and response, and device-based access policies.</li> <li><strong>Advanced Troubleshooting:</strong> Serve as the escalation point for complex macOS and endpoint-platform issues that cannot be resolved through standard IT support processes.</li> <li><strong>Technical Leadership:</strong> Help define the endpoint roadmap, evaluate technologies, make architecture decisions, and lead complex initiatives from conception through production.</li> </ul> <h3><strong>Basic Qualifications</strong></h3> <ul> <li>8+ years of experience building and operating secure IT or endpoint systems in complex environments.</li> <li>Experience managing a large fleet of macOS devices through a modern MDM platform.</li> <li>Experience managing endpoint configuration through scripted deployments, Git-based workflows, or a full GitOps model.</li> <li>Deep knowledge of macOS internals, enterprise deployment, security controls, and troubleshooting.</li> <li>Experience designing and operating zero-touch Mac provisioning, patching, and software-distribution workflows.</li> <li>Experience using device health and security signals to evaluate endpoint compliance.</li> <li>Experience successfully delivering complex technical projects from conception through production.</li> <li>Strong ability to solve ambiguous problems involving multiple teams and stakeholders.</li> <li>Ability to communicate technical concepts clearly to technical and nontechnical audiences.</li> <li>A product-engineering mindset toward IT systems, including testing, observability, reliability, and controlled change management.</li> <li>A consistent practice of creating clear technical documentation, architecture diagrams, runbooks, and operational procedures.</li> <li>Ability to work from either our New York or San Francisco office.</li