Enter a job title or keyword

Systems Engineer – Endpoint & Cloud Integration


Job Location:

Austin, TX - USA

Monthly Salary: Not provided by the employer
Posted: 21 August 2026 (2 days ago)
Application Deadline: 18 November 2026
Vacancies: 1 Vacancy

Job Summary

WHO WE ARE

Apex Fintech Solutions (Apex) powers innovation and the future of digital wealth management by building tech-forward solutions that help simplify automate and facilitate access to financial markets for all. Our robust suite of fintech software enables us to support clients such as Stash Betterment SoFi Webull and eToro amongst many others; collectively Apex powers access to the stock market for over 22 million end customers.

At Apex we are changing how the securities industry operates by reinventing the status quo which was manual slow and accessible only by the ultra-wealthy. Were digitizing and democratizing systems so that everyone has an opportunity to invest.

When youre at Apex you drive this change. Youre part of a global team with a clear vision: to be the trusted technology that powers the digital economy. Our offices in Austin Dallas Chicago New York Portland Belfast and Manila are home to over 1000 employees.

Together were shaping the future of financial innovation. Embrace change. Solve big. Win together. And be G.R.E.A.T. grit results empathy accountability and teamwork with Apex.

Were proud to be recognized for the innovative work we do the purpose-driven nature of our work and the collaborative culture weve created. Here are just a few of the many awards weve recently received:

Best Places to Work

- Presented by BuiltIn

WealthTech of the Year

2025- Presented by US FinTech Awards

The Worlds Top 250 Fintech Companies

2024- Presented by CNBC

ABOUT THIS ROLE

About the Role

Were hiring a Systems/Integration Engineer to own the plumbing that connects our endpoints identity platform and cloud infrastructure. This person will design and build integrations across AWS WorkSpaces Microsoft Intune Kandji Apple Business Manager Entra ID and Conditional Access replacing legacy Group Policy dependencies with modern cloud-native policy-as-code management. Everything shipped must be automated and reproducible.

What Youll Do

  • Own and maintain integrations between AWS WorkSpaces and on-prem/cloud identity (Entra ID AD Connect/Cloud Sync).
  • Own end-to-end Intune administration: compliance policies configuration profiles app deployment Autopilot/Windows enrollment Scope Tags and RBAC design across business units.
  • Manage Apple device lifecycle via Kandji Apple Business Manager (ABM): DEP enrollment supervised device policies app deployment and zero-touch provisioning.
  • Design and enforce Conditional Access policies in Entra ID (device compliance location risk-based sign-in session controls) in coordination with security/identity teams.
  • Work with Team on migration of legacy Group Policy Objects (GPOs) to Intune/Entra-based configuration and compliance policies including translating GPO logic 1:1 where needed and documenting gaps.
  • Build and maintain RBAC models across Intune Entra ID and AWS (least-privilege scoped admin roles custom roles Scope Tag-based delegation).
  • Write and maintain AWS Lambda functions to automate device lifecycle events cross-platform sync (e.g. Kandji Intune Entra WorkSpaces) reporting and remediation workflows.
  • Build all infrastructure using Infrastructure as Code (Terraform Ansible and/or CloudFormation) no manual console changes for anything reproducible managed through version control with peer review.
  • Develop automation/scripting for endpoint and identity workflows (PowerShell Python Microsoft Graph API).
  • Implement and maintain MDM solutions for BYOD devices for Windows/Mac/Linux/Android devices.

Required Skills & Experience

  • Bachelors degree in Computer Science or related technical discipline (or equivalent work experience) required

  • 2 years in systems/endpoint engineering including hands-on administration of both a modern MDM (Intune plus Kandji or Jamf Pro) and AWS infrastructure.
  • Deep hands-on Microsoft Intune expertise: compliance policies configuration profiles app protection/app config policies Autopilot Scope Tags RBAC (built-in and custom roles).
  • Kandji or Jamf Pro administration (Blueprints/policies Library Items/config profiles Liftoff or equivalent zero-touch enrollment).
  • Apple Business Manager (ABM): DEP VPP device assignment MDM server integration.
  • Hands-on Group Policy (GPO) experience and proven experience migrating GPO logic to cloud-native MDM/compliance policy equivalents.
  • Entra ID (Azure AD) administration: users/groups dynamic groups app registrations enterprise apps hybrid identity.
  • Conditional Access policy design and troubleshooting (sign-in logs what-if tool break-glass account practices).
  • RBAC design across Microsoft and AWS environments custom roles least privilege scoped administration.
  • AWS WorkSpaces provisioning directory integration (AWS Directory Service / AD Connector) and related networking.
  • Infrastructure as Code: Terraform Ansible and/or AWS CloudFormation used for all provisioned infrastructure.
  • Git-based version control and CI/CD pipeline familiarity (GitHub Actions Azure DevOps or similar).
  • Scripting proficiency: PowerShell Python Shell Microsoft Graph API.
  • Solid understanding of Windows and macOS device architecture authentication protocols (Kerberos SAML OAuth/OIDC) and certificate-based auth (SCEP/PKCS).
  • Strong documentation habits and ability to communicate technical tradeoffs to both engineering and non-technical stakeholders.
  • Linux and macOS administration expertise command-line fluency shell scripting and system-level troubleshooting beyond GUI-based management.

Nice to Have

  • Microsoft certifications (MS-102 Endpoint Administrator SC-300 Identity and Access Administrator AZ-500).
  • Apple certifications (Apple Certified Support Professional / Apple Deployment and Management).
  • AWS certifications (Solutions Architect SysOps Administrator).
  • Experience with Okta or other third-party IdPs alongside Entra ID.
  • Experience with security frameworks/benchmarks (CIS NIST) as applied to endpoint compliance baselines.
  • ServiceNow or similar ITSM tooling for change management and automation triggers.

Success Metrics for This Role

  • Legacy GPOs fully migrated to Intune/Entra with documented parity or intentional deviation.
  • All new infrastructure provisioned via IaC with zero manual ClickOps for repeatable resources.
  • Clear RBAC/Scope Tag model reducing over-privileged admin access.
  • Reliable automated sync between device management platforms and identity/cloud resources (fewer manual reconciliation tickets).

Please note this job description is not designed to cover or contain a comprehensive listing of activities duties or responsibilities required of the employee for this job. Duties responsibilities and activities may change at any time with or without notice.

Our Rewards

We offer a robust package of employee perks and benefits including healthcare benefits (medical dental and vision EAP) competitive PTO 401k match parental leave and HSA contribution match. We also provide our employees with a paid subscription to the Calm app and offer generous external learning and tuition reimbursement benefits. At AFS we offer a hybrid work schedule for most roles that allows employees to have the flexibility of working from home and one of our primary offices.

EEO Statement

Apex Fintech Solutions is an equal opportunity employer that does not discriminate on the basis of race color religion sex (including pregnancy sexual orientation and gender identity) national origin age disability veteran status marital status or any other protected characteristic. Our hiring practices ensure that all qualified applicants receive fair consideration without regard to these characteristics.

Disability Statement

Apex Fintech Solutions is committed to creating an inclusive and accessible workplace for all candidates including those with disabilities. We are dedicated to ensuring equal employment opportunities and providing reasonable accommodations to qualified individuals with disabilities. If you require reasonable accommodations to participate in the application or interview process please submit your request via the Candidate Accommodation Requests Form. We will work with you to provide the necessary accommodations to ensure your full participation in our hiring process.


Required Experience:

IC


About Company

Company Logo

PEAK6 doesn't do anything the traditional way. Mainly because we're not your typical investment firm. We follow opportunities, not the status quo.

View Profile View Profile