Skip to content

Hi, my name is

Andrew Arsenault

Senior Systems & Platform Engineer

I own enterprise SaaS platforms end-to-end — identity, Slack, and endpoint fleets — and build the automation that eliminates operational toil at scale.

10+
Years owning enterprise platforms
2,500+
Hours of manual toil automated away
5 OS
Endpoint platforms managed at global scale
01Profile

About

I'm a results-driven Senior Systems Engineer with 10+ years owning enterprise SaaS platforms, engineering workflow automation, and eliminating operational toil at scale. My deep work is in Slack platform engineering, Google Workspace administration, and identity & access management — Okta, SCIM, SAML, and OAuth.

I build the API integrations, low-code/no-code automations, and custom tooling that remove friction and let teams scale. I design and maintain multiple MCP servers — including the Google Workspace MCP I built personally — and lean on AI tooling like Claude, Vercel, Gemini, and GPT to design, build, and ship systems quickly and at scale. I partner cross-functionally to turn process pain into high-impact engineering solutions.

02Track record

Experience

  1. Senior Systems Engineer · Coinbase

    Mar 2022 — Present

    Remote

    Primary Slack platform owner and service owner — governance, app security, provisioning, and AI feature rollout across an enterprise-scale workforce.

    • Own the Slack platform: lead governance, app security reviews, SCIM behavior, AI feature rollout controls, and elevated-scope approval processes for enterprise-scale reliability and security.
    • Eliminated 2,500+ hours of manual work through custom Slack bots, API-driven Jira workflow automations, and self-service tooling that replaced repetitive access and support operations org-wide.
    • Serve as subject-matter expert (SME) for Slack, Google Workspace, SendSafely, and DocuSign — owning configuration, security, and escalation support across these platforms for the enterprise.
    • Engineered IAM improvements across Okta, LDAP, and Workday→Okta→Slack provisioning; designed dynamic attribute-driven group models that replaced static LDAP groups and eliminated manual access provisioning toil org-wide.
    • Helped build out integrations on a Go-based orchestration platform that drives automated LDAP group/role assignment to SaaS applications, enabling attribute-driven access provisioning at scale.
    • Personally built the Google Workspace MCP server and build and maintain multiple MCP servers — owning design, OAuth flow validation, and release readiness to expose internal systems to AI agents.
    • Leverage AI tooling — Claude, Vercel, Gemini, and GPT — to design, build, and ship systems quickly and at scale, accelerating automation and integration delivery across the org.
    • Drove Slack Webhook Proxy deprecation using Datadog telemetry to find legacy consumers and coordinate migration to native API integrations and custom apps.
    • Recognized by ESTO leadership for leading simultaneous incident responses and delivering platform solutions for partner teams under tight timelines.
    OktaSlack PlatformGoogle WorkspaceGoWorkdayDatadogJiraPythonOAuth/SCIM
  2. Senior Windows Client Platform Engineer · Okta

    May 2024 — Sep 2024

    Remote

    Managed a global, cross-platform endpoint fleet and stood up greenfield Azure cloud-management infrastructure as code.

    • Orchestrated a global endpoint fleet across macOS, Windows, ChromeOS, iOS, and Linux using Intune, JAMF Pro, WorkspaceOne, and Google Workspace MDM — with fleet-health visibility via Looker dashboards.
    • Designed a custom Temporal workflow to automate device offboarding: remote lock, lock-key escrow to Oomnitza, and DynamoDB audit logging for compliance.
    • Led greenfield Azure setup — Log Analytics, Key Vaults, Automation Accounts, Runbooks, and Intune/Autopilot — establishing a scalable cloud-management foundation.
    • Executed MDM server upgrades via infrastructure-as-code and administered Azure groups and RBAC with Terraform, reducing downtime.
    • Designed SAML/OIDC app integrations in Okta and built Okta Workflows automations triggered by Jira service requests, eliminating manual provisioning steps.
    IntuneJAMF ProTerraformAzureTemporalOkta Workflows
  3. Client Platform Engineer — Windows · Peloton Interactive

    Jun 2021 — Mar 2022

    Remote

    Managed a global endpoint fleet and built zero-touch enrollment and compliance reporting automation.

    • Managed a global fleet across macOS, Windows, Linux, ChromeOS, iOS, and Android using Intune, JAMF, Chef, and Ansible.
    • Developed complex PowerShell for zero-touch enrollment (ZTE) via Autopilot and built Azure Log Analytics dashboards for OS-version and patch-compliance metrics.
    • Remediated Windows OS issues with PowerShell Proactive Remediations; managed Windows 10 / EM+S / M365 licensing and Azure AD.
    IntuneAutopilotPowerShellJAMFAnsibleAzure AD
  4. Endpoint Management Consultant · SystemCenterDudes

    Jan 2021 — Mar 2022

    Contract

    Consulted on cloud device management and client migrations to Intune.

    • Designed and implemented cloud device management; assisted clients migrating from WorkspaceOne and JAMF to Intune across Windows, macOS, iOS, and Android.
    • Configured compliance policies, app protection, conditional access, and security baselines; ran client training on security best practices.
    IntuneConditional AccessmacOSWindows
  5. Digital Technology Lead · Nova Scotia Community College

    Dec 2016 — Jun 2021

    Nova Scotia

    Led province-wide software packaging, deployment, and IT service management.

    • Led the SCCM/MECM packaging team: built and deployed 100+ application packages and complex task sequences for BIOS updates, encryption, and Windows feature upgrades province-wide.
    • Implemented Intune MDM and Autopilot for loaner devices; designed a college-wide Windows 10 base image via Windows Deployment Services.
    • Launched the TeamDynamix IT service desk and knowledge base (500+ services, hundreds of KB articles) and led Change Management across the college.
    • Performed vulnerability scanning (Nessus), rogue-device detection (NMAP), and traffic analysis (Wireshark); configured an ELK stack to monitor Windows event logs on CentOS.
    SCCM/MECMPowerShellIntuneELKNessus

Earlier

  • Digital Technology Analyst · Nova Scotia Community CollegeApr 2015 – Dec 2016
  • IT Security Administrator · Sobeys CorporateFeb 2014 – Apr 2015
  • Technical Consultant · Staples CanadaMar 2013 – Mar 2014
03Selected work

Featured Engineering Projects

Slack Automation Suite

2,500+ hours reclaimed

Custom Slack bots and API-driven Jira workflow automations that eliminated 2,500+ hours of manual work, automating complex user-access assignment and enabling self-service tooling for support teams.

Slack PlatformJira APIPythonAutomation

Dynamic IAM Provisioning

Workday → Okta → Slack

Re-architected identity provisioning around dynamic, attribute-driven group models that replaced brittle static LDAP groups — eliminating manual access provisioning toil across the organization.

OktaSCIMWorkdayLDAP

SaaS Access Orchestration

LDAP → SaaS, automated

Helped build integrations on a Go-based orchestration platform that automates LDAP group and role assignment to SaaS applications, enabling attribute-driven access provisioning at scale.

GoLDAPOrchestrationSaaS Provisioning

Google Workspace MCP Server

Internal systems, AI-native

Personally designed and built the Google Workspace MCP server — plus several other MCP servers I build and maintain — exposing internal systems to AI agents with validated OAuth flows and release-ready security.

MCPGoogle WorkspaceOAuthGenerative AI

Temporal Device Offboarding

Compliant, hands-off deprovisioning

A custom Temporal workflow that automates device offboarding end-to-end: remote lock, lock-key escrow to Oomnitza, and DynamoDB audit logging for compliance.

TemporalDynamoDBWorkflow AutomationCompliance

Greenfield Azure Platform

Cloud management from zero

Stood up a greenfield Azure environment as code — Log Analytics, Key Vaults, Automation Accounts, Runbooks, and Intune/Autopilot — establishing a scalable endpoint cloud-management foundation.

AzureTerraformIntuneIaC
04Toolbox

Skills & Background

Identity & Access

  • Okta (SSO, SCIM, Workflows)
  • SAML / OIDC / OAuth
  • Azure / Entra ID / AAD
  • LDAP
  • Workday provisioning

Endpoint & Fleet

  • Microsoft Intune / Autopilot
  • JAMF Pro (Certified Admin)
  • WorkspaceOne
  • Google Workspace MDM
  • SCCM / MECM
  • Autopkg / Munki

Automation & IaC

  • PowerShell
  • Python
  • Terraform
  • Temporal
  • Slack bots & Platform
  • API integrations

Cloud, CI & Observability

  • Azure (Log Analytics, Key Vault, Runbooks)
  • Datadog
  • ELK
  • Buildkite
  • GitHub Actions

SaaS Platforms (SME)

  • Slack
  • Google Workspace
  • SendSafely
  • DocuSign
  • Okta

Practice & Process

  • ITIL / Change Management
  • MCP (build & maintain)
  • AI tooling — Claude, Vercel, Gemini, GPT
  • Incident response
  • Jira / Confluence
  • Windows / macOS / Linux / ChromeOS

Education & Certs

  • Information Systems SpecialistCompuCollege · 2004
  • JAMF Certified Administrator
  • JAMF Certified Technician
  • ITIL Foundations V3

05 — What's next

Let's build something solid.

I'm open to staff-level roles, advisory work, and interesting systems problems. The fastest way to reach me is email — I read everything.