Endpoint Lifecycle Operations Engineer
Listed on 2026-03-09
-
IT/Tech
IT Support, Cybersecurity
Job Description Summary
As a Staff Endpoint Lifecycle Operations Engineer on the Digital Workplace team, you will play a key role in the ongoing design, build, and implementation of GE Aerospace’s Mac end‑user devices.
We are seeking a Mac Services Engineer with strong hands‑on expertise in macOS validation and engineering, configuration management, application packaging and deployment, and patching. In this role, you will build, validate, deploy, and maintain macOS‑based laptops and desktops at enterprise scale, ensuring stable, secure, and well‑supported end‑user devices.
You will maintain vital relationships with both internal and external stakeholders to ensure services are deployed compliantly, with a focus on quality and operational excellence. Success in this role requires a deep understanding of service opportunities and constraints within regulated environments, and close partnership with GE Aerospace’s Cyber and Security teams to drive robust policies for macOS. You will also play a key role in defining and maintaining the endpoint service catalog for Mac and ensuring its accurate representation across GE Aerospace’s ITSM toolsets.
You will join a focused team continually evolving this service portfolio, delivering increased value to our global user base of 60,000+ employees and positively impacting every employee across the company.
Job Description Essential ResponsibilitiesMac Build, Enrollment, and Firmware Configuration
- Configure and manage Mac firmware/security settings (File Vault, Secure Boot, Activation Lock, Startup Security Utility) across supported Apple hardware
- Create, maintain, and optimize standard macOS baselines and configuration profiles (golden baseline via MDM, declarative management where applicable)
- Ensure hardware and macOS version compatibility across supported Mac models and Apple silicon/Intel platforms
OS Validation and Engineering
- Plan and execute validation for new macOS releases, point updates, Rapid Security Responses, and security patches
- Perform compatibility testing for kernel/system extensions, login items, security tools, network agents, and core enterprise apps
- Document known issues, provide mitigations/workarounds, and record validation results and release decisions
Application Packaging and Deployment
- Package, notarize, and validate Mac applications for enterprise deployment (PKG/DMG), including pre/postinstall scripts and configuration profiles
- Maintain and update app packages, dependencies, entitlement considerations, and uninstall/remediation scripts
- Collaborate with stakeholders to define packaging standards, code‑signing requirements, and phased deployment schedules
Patching and Vulnerability Remediation
- Plan and implement macOS and application patching cycles using MDM policies, software update deferrals, and smart targeting
- Monitor patch compliance, investigate failures (update deferrals, disk space, power/state issues), and remediate at scale
- Partner with security teams to address CVEs, hardening baselines, and meet compliance targets and SLAs
Incident Resolution and Support
- Serve as an escalation point for complex macOS endpoint incidents (network stack, kernel panics, File Vault, SSO, identity, certificates)
- Perform root cause analysis using system logs, profiles, and telemetry; implement durable fixes and prevention
- Provide technical guidance and runbooks to service desk and field support teams
Documentation and Continuous Improvement
- Create and maintain technical documentation, standard operating procedures, and knowledge base articles specific to macOS
- Identify automation opportunities (policy‑as‑code, packaging pipelines, remediation scripts) to streamline build, deployment, and patching
- Drive continuous improvement of Mac standards, tools, and service quality; benchmark against industry best practices
Design and Implementation
- Participate in the design, build, and rollout of macOS end‑user devices aligned to organizational goals and compliance standards
Stakeholder Collaboration
- Maintain strong relationships with internal teams (e.g., Cyber and Security, Network, Identity) and external vendors to ensure effective, high‑quality deployments
Compliance and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).