🌏 Berlin / Remote

TLDR;

We’re building a meeting agent that builds company-wide conversational context and eliminates busy work around meetings. We’re a fast-moving team looking for an Enterprise Deployment Engineer to make Jamie install, update and run silently and reliably inside locked-down corporate environments — and to make the IT admin’s experience of Jamie as good as the end user’s.

About Jamie

Every company runs on conversations, and most of that context disappears the moment a meeting ends. Jamie captures it, structures it, and makes it usable across the entire organisation. We work closely with our customers to build a magical product with real-world impact.

We believe in shipping fast, learning constantly, and building a product users love.

The Role

Jamie runs as a desktop app on managed corporate machines. That means our software has to survive MDM packaging, application allowlisting, endpoint security agents, proxies, and IT teams who — quite reasonably — don’t want an app updating itself in the middle of a meeting.

Today, that surface has no owner. Installer and MDM issues land on whichever engineer is closest, week after week. Application control tooling alone exposes dozens of settings that can block an install, which makes per-company troubleshooting a losing game. Security software occasionally blocks or corrupts our updates. Admins have no reliable way to see which version their fleet is running. Every one of these is a real thing a customer has told us.

Your job is to turn all of that from recurring firefighting into an engineered system. We’re looking for someone who builds general solutions rather than patching one deployment at a time, and who is as comfortable reading installer telemetry as they are on a call with a customer’s security team.

What You Will Be Working On

Windows Distribution & Updates: Own per-user and per-machine MSI packaging, our system-level update service, elevation and IPC with the privileged helper, reconciliation of failed updates, and exit-code telemetry that tells us what actually happened on the endpoint.

macOS Distribution & Updates: Own MDM distribution and app repackaging, and build the update daemon we don’t have yet. This is real greenfield systems work, not maintenance.

Update Policy That Respects IT: No self-updating mid-meeting, admin-controllable update windows, and genuine version visibility for administrators.

Trust, Signing & Reputation: Own code signing and certificate lifecycle, installer reputation and SmartScreen propagation, antivirus false-positive triage, and publisher metadata stability so privilege-management tooling doesn’t break on every release.

Don’t Trigger the EDRs: Build proactive relationships with endpoint security vendors — allowlisting, behavioural signatures, a documented process and binary inventory. Nobody owns this today, and it directly determines whether we can sell into security-conscious organisations.

Networking in Restricted Environments: Publish and maintain stable firewall, proxy and allowlist requirements. Continuously validate relay fallbacks and corporate VPN paths, and make sure that when a network policy breaks something, the app says so clearly instead of failing silently.

Build the Enterprise Test Estate: Stand up a real managed-environment lab — MDM, directory services, application control, privilege management, an EDR agent — so deployment regressions are caught by us and not by a customer.

Own the Enterprise Release Path: Run the progression from internal to staged to general to enterprise, with the enterprise ring deliberately behind and properly validated.

Admin Experience: Write and maintain the deployment guides and per-environment runbooks, give admins fleet version and health visibility, and handle the technical side of rollout calls — often working through a customer’s external IT provider.