Hi, my name is
Andrew Arsenault
Senior Systems & Platform Engineer
I own enterprise SaaS platforms end-to-end — identity, Slack, and endpoint fleets — and build the automation that eliminates operational toil at scale.
- 10+
- Years owning enterprise platforms
- 2,500+
- Hours of manual toil automated away
- 5 OS
- Endpoint platforms managed at global scale
About
I'm a results-driven Senior Systems Engineer with 10+ years owning enterprise SaaS platforms, engineering workflow automation, and eliminating operational toil at scale. My deep work is in Slack platform engineering, Google Workspace administration, and identity & access management — Okta, SCIM, SAML, and OAuth.
I build the API integrations, low-code/no-code automations, and custom tooling that remove friction and let teams scale. I design and maintain multiple MCP servers — including the Google Workspace MCP I built personally — and lean on AI tooling like Claude, Vercel, Gemini, and GPT to design, build, and ship systems quickly and at scale. I partner cross-functionally to turn process pain into high-impact engineering solutions.
Experience
Senior Systems Engineer · Coinbase
Mar 2022 — PresentRemote
Primary Slack platform owner and service owner — governance, app security, provisioning, and AI feature rollout across an enterprise-scale workforce.
- Own the Slack platform: lead governance, app security reviews, SCIM behavior, AI feature rollout controls, and elevated-scope approval processes for enterprise-scale reliability and security.
- Eliminated 2,500+ hours of manual work through custom Slack bots, API-driven Jira workflow automations, and self-service tooling that replaced repetitive access and support operations org-wide.
- Serve as subject-matter expert (SME) for Slack, Google Workspace, SendSafely, and DocuSign — owning configuration, security, and escalation support across these platforms for the enterprise.
- Engineered IAM improvements across Okta, LDAP, and Workday→Okta→Slack provisioning; designed dynamic attribute-driven group models that replaced static LDAP groups and eliminated manual access provisioning toil org-wide.
- Helped build out integrations on a Go-based orchestration platform that drives automated LDAP group/role assignment to SaaS applications, enabling attribute-driven access provisioning at scale.
- Personally built the Google Workspace MCP server and build and maintain multiple MCP servers — owning design, OAuth flow validation, and release readiness to expose internal systems to AI agents.
- Leverage AI tooling — Claude, Vercel, Gemini, and GPT — to design, build, and ship systems quickly and at scale, accelerating automation and integration delivery across the org.
- Drove Slack Webhook Proxy deprecation using Datadog telemetry to find legacy consumers and coordinate migration to native API integrations and custom apps.
- Recognized by ESTO leadership for leading simultaneous incident responses and delivering platform solutions for partner teams under tight timelines.
OktaSlack PlatformGoogle WorkspaceGoWorkdayDatadogJiraPythonOAuth/SCIMSenior Windows Client Platform Engineer · Okta
May 2024 — Sep 2024Remote
Managed a global, cross-platform endpoint fleet and stood up greenfield Azure cloud-management infrastructure as code.
- Orchestrated a global endpoint fleet across macOS, Windows, ChromeOS, iOS, and Linux using Intune, JAMF Pro, WorkspaceOne, and Google Workspace MDM — with fleet-health visibility via Looker dashboards.
- Designed a custom Temporal workflow to automate device offboarding: remote lock, lock-key escrow to Oomnitza, and DynamoDB audit logging for compliance.
- Led greenfield Azure setup — Log Analytics, Key Vaults, Automation Accounts, Runbooks, and Intune/Autopilot — establishing a scalable cloud-management foundation.
- Executed MDM server upgrades via infrastructure-as-code and administered Azure groups and RBAC with Terraform, reducing downtime.
- Designed SAML/OIDC app integrations in Okta and built Okta Workflows automations triggered by Jira service requests, eliminating manual provisioning steps.
IntuneJAMF ProTerraformAzureTemporalOkta WorkflowsClient Platform Engineer — Windows · Peloton Interactive
Jun 2021 — Mar 2022Remote
Managed a global endpoint fleet and built zero-touch enrollment and compliance reporting automation.
- Managed a global fleet across macOS, Windows, Linux, ChromeOS, iOS, and Android using Intune, JAMF, Chef, and Ansible.
- Developed complex PowerShell for zero-touch enrollment (ZTE) via Autopilot and built Azure Log Analytics dashboards for OS-version and patch-compliance metrics.
- Remediated Windows OS issues with PowerShell Proactive Remediations; managed Windows 10 / EM+S / M365 licensing and Azure AD.
IntuneAutopilotPowerShellJAMFAnsibleAzure ADEndpoint Management Consultant · SystemCenterDudes
Jan 2021 — Mar 2022Contract
Consulted on cloud device management and client migrations to Intune.
- Designed and implemented cloud device management; assisted clients migrating from WorkspaceOne and JAMF to Intune across Windows, macOS, iOS, and Android.
- Configured compliance policies, app protection, conditional access, and security baselines; ran client training on security best practices.
IntuneConditional AccessmacOSWindowsDigital Technology Lead · Nova Scotia Community College
Dec 2016 — Jun 2021Nova Scotia
Led province-wide software packaging, deployment, and IT service management.
- Led the SCCM/MECM packaging team: built and deployed 100+ application packages and complex task sequences for BIOS updates, encryption, and Windows feature upgrades province-wide.
- Implemented Intune MDM and Autopilot for loaner devices; designed a college-wide Windows 10 base image via Windows Deployment Services.
- Launched the TeamDynamix IT service desk and knowledge base (500+ services, hundreds of KB articles) and led Change Management across the college.
- Performed vulnerability scanning (Nessus), rogue-device detection (NMAP), and traffic analysis (Wireshark); configured an ELK stack to monitor Windows event logs on CentOS.
SCCM/MECMPowerShellIntuneELKNessus
Earlier
- Digital Technology Analyst · Nova Scotia Community CollegeApr 2015 – Dec 2016
- IT Security Administrator · Sobeys CorporateFeb 2014 – Apr 2015
- Technical Consultant · Staples CanadaMar 2013 – Mar 2014
Featured Engineering Projects
Slack Automation Suite
2,500+ hours reclaimed
Custom Slack bots and API-driven Jira workflow automations that eliminated 2,500+ hours of manual work, automating complex user-access assignment and enabling self-service tooling for support teams.
Dynamic IAM Provisioning
Workday → Okta → Slack
Re-architected identity provisioning around dynamic, attribute-driven group models that replaced brittle static LDAP groups — eliminating manual access provisioning toil across the organization.
SaaS Access Orchestration
LDAP → SaaS, automated
Helped build integrations on a Go-based orchestration platform that automates LDAP group and role assignment to SaaS applications, enabling attribute-driven access provisioning at scale.
Google Workspace MCP Server
Internal systems, AI-native
Personally designed and built the Google Workspace MCP server — plus several other MCP servers I build and maintain — exposing internal systems to AI agents with validated OAuth flows and release-ready security.
Temporal Device Offboarding
Compliant, hands-off deprovisioning
A custom Temporal workflow that automates device offboarding end-to-end: remote lock, lock-key escrow to Oomnitza, and DynamoDB audit logging for compliance.
Greenfield Azure Platform
Cloud management from zero
Stood up a greenfield Azure environment as code — Log Analytics, Key Vaults, Automation Accounts, Runbooks, and Intune/Autopilot — establishing a scalable endpoint cloud-management foundation.
Skills & Background
Identity & Access
- Okta (SSO, SCIM, Workflows)
- SAML / OIDC / OAuth
- Azure / Entra ID / AAD
- LDAP
- Workday provisioning
Endpoint & Fleet
- Microsoft Intune / Autopilot
- JAMF Pro (Certified Admin)
- WorkspaceOne
- Google Workspace MDM
- SCCM / MECM
- Autopkg / Munki
Automation & IaC
- PowerShell
- Python
- Terraform
- Temporal
- Slack bots & Platform
- API integrations
Cloud, CI & Observability
- Azure (Log Analytics, Key Vault, Runbooks)
- Datadog
- ELK
- Buildkite
- GitHub Actions
SaaS Platforms (SME)
- Slack
- Google Workspace
- SendSafely
- DocuSign
- Okta
Practice & Process
- ITIL / Change Management
- MCP (build & maintain)
- AI tooling — Claude, Vercel, Gemini, GPT
- Incident response
- Jira / Confluence
- Windows / macOS / Linux / ChromeOS
Education & Certs
- Information Systems SpecialistCompuCollege · 2004
- JAMF Certified Administrator
- JAMF Certified Technician
- ITIL Foundations V3
05 — What's next
Let's build something solid.
I'm open to staff-level roles, advisory work, and interesting systems problems. The fastest way to reach me is email — I read everything.