🌏 Berlin / Remote
We’re building a meeting agent that builds company-wide conversational context and eliminates busy work around meetings. We’re a fast-moving team looking for an Enterprise Deployment Engineer to make Jamie install, update and run silently and reliably inside locked-down corporate environments — and to make the IT admin’s experience of Jamie as good as the end user’s.
Every company runs on conversations, and most of that context disappears the moment a meeting ends. Jamie captures it, structures it, and makes it usable across the entire organisation. We work closely with our customers to build a magical product with real-world impact.
We believe in shipping fast, learning constantly, and building a product users love.
Jamie runs as a desktop app on managed corporate machines. That means our software has to survive MDM packaging, application allowlisting, endpoint security agents, proxies, and IT teams who — quite reasonably — don’t want an app updating itself in the middle of a meeting.
Your job is to turn all of that into an engineered system. We’re looking for someone who builds general solutions rather than patching one deployment at a time, and who is as comfortable reading installer telemetry as they are on a call with a customer’s security team.
Windows Distribution & Updates: Own per-user and per-machine MSI packaging, our system-level update service, elevation and IPC with the privileged helper, reconciliation of failed updates, and exit-code telemetry that tells us what actually happened on the endpoint.
macOS Distribution & Updates: Own MDM distribution and app repackaging, and build the update daemon we don’t have yet. This is real greenfield systems work, not maintenance.
Update Policy That Respects IT: No self-updating mid-meeting, admin-controllable update windows, and genuine version visibility for administrators.
Trust, Signing & Reputation: Own code signing and certificate lifecycle, installer reputation and SmartScreen propagation, antivirus false-positive triage, and publisher metadata stability so privilege-management tooling doesn’t break on every release.
Don’t Trigger the EDRs: Build proactive relationships with endpoint security vendors — allowlisting, behavioural signatures, a documented process and binary inventory. Nobody owns this today, and it directly determines whether we can sell into security-conscious organisations.
Networking in Restricted Environments: Publish and maintain stable firewall, proxy and allowlist requirements. Continuously validate relay fallbacks and corporate VPN paths, and make sure that when a network policy breaks something, the app says so clearly instead of failing silently.
Build the Enterprise Test Estate: Stand up a real managed-environment lab — MDM, directory services, application control, privilege management, an EDR agent — so deployment regressions are caught by us and not by a customer.
Own the Enterprise Release Path: Run the progression from internal to staged to general to enterprise, with the enterprise ring deliberately behind and properly validated.
Admin Experience: Write and maintain the deployment guides and per-environment runbooks, give admins fleet version and health visibility, and handle the technical side of rollout calls — often working through a customer’s external IT provider.