Senior Systems Administrator

UpGuard Sydney, Australia Publicerat 10 augusti 2026
full_timeremotesenior
WHO ARE WE? At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk. We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface. We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale. Where does this role fit in? Build, operate, and strategically evolve the technology platform that enables every UpGuardian to work securely, efficiently, and with minimal friction. You'll own the hands-on administration and optimization of our core IT stack: identity systems, endpoint engineering, and SaaS platforms. Your main focus will be automating repetitive operational tasks, establishing system performance and compliance metrics, and maintaining a secure-by-default infrastructure. This is a platform engineering and ownership role above all else, with the added responsibility of serving as the senior escalation point for complex day-to-day issues. We don't want you stuck in a queue, so if you see the same manual task three times and immediately design an automated, self-service fix to permanently remove it, you’ll fit right in. Security is an outcome of excellent operational engineering here, not the primary function of the role. What will you do? Platform, Identity & Fleet Operations - Drive end-to-end shared platform ownership across Google Workspace, Okta, and enterprise MDM (Kandji/Jamf) for our macOS and ChromeOS fleet. You’ll architect robust SSO/SAML integrations, optimize SCIM provisioning, design scalable role hierarchies, and establish proactive OS lifecycle and patching strategies that keep our systems secure by default. - Optimise our global joiner-mover-leaver process. Find the steps that still need a human, automate them, and tighten the handoffs with the People Team. Keep asset records and endpoint compliance reporting accurate, and administer the SaaS estate against the governance model. Zero Trust & Secure Access - Take operational ownership of our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, secure tunnels, and identity and device-aware access policies. Tune policies, and troubleshoot the edge access problems that get escalated past everyone else. - Own the migration of remaining internal applications off legacy network access as a workstream, and flag where a control is creating friction that isn't buying us anything. Automation & Internal Tooling - Build production-grade tooling using REST APIs, Python, Apps Script, and n8n that permanently removes manual work. - Propose what should be automated next, based on what you're seeing in the queue. Service Operations - Take incident command for platform incidents on rota. Coordinate the response, keep people informed, drive to resolution, then write the postmortem and see the actions through to closure. - Raise and execute changes through our change process, including risk assessment and rollback. Investigate recurring incidents to root cause and own the resulting problem records. - Keep the runbooks, knowledge base, and service catalogue entries accurate for the systems you run. Where you find a gap in the practice, propose the fix and pilot it on your own systems. Reliability & Self-Service - Own zero-touch provisioning, endpoint compliance enforcement, and fleet health monitoring. - Build the self-service options and self-healing behaviour that make routine requests stop reaching the team. Embedded Security Engineering - Implement and maintain endpoint hardening and baseline configurations, and keep them current. Act as technical responder on security incidents and support the evidence side of audit and compliance work. - Design security into platform changes as you make them rather than adding it afterwards. Where you find operational risk, surface it with a recommendation attached. Raising the Level Around You - Mentor your colleagues on the platforms and tools you know best. Where you fix something, leave documentation behind so the next person doesn't need you. What will you bring? You won't have all of this. Tell us which parts you'd be learning, and we'll tell you honestly whether that works. - SaaS & Identity Depth: Several years administering Google Workspace or Microsoft 365 alongside an enterprise IdP (Okta, Entra) and MDM at organisational scale. SSO, SAML, SCIM, DNS, and certificates as things you've configured and debugged. - Hands-on Zero Trust Experience: Direct experience configuring and optimising ZTNA, Secure Web Gateways, or modern edge access controls (Cloudflare Zero Trust, Zscaler, Netskope, Tailscale, Entra Private Access). Enough to take operational ownership of a Cloudflare estate and troubleshoot complex edge access issues. - Automation Capability: Production-grade scripts or code (Python, Apps Script, Terraform) integrated against REST APIs. Point us at internal tools or pipelines you've built that permanently eliminated operational work. - Fleet Management at Scale: Managing macOS at scale, building zero-touch deployment workflows, and enforcing endpoint compliance baselines. - Process Optimisation: You've taken a joiner-mover-leaver or similar cross-functional process and measurably reduced the manual steps in it, working with People or HR to do it. - Operational Discipline: Experience running incidents, working within a change process, and authoring technical documentation that teams rely on. - Security Fundamentals: Endpoint hardening, identity security, and network access controls, with the judgment to make proportionate risk recommendat

Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.

Visa jobbet och ansök

Ursprunglig annons: jobs.ashbyhq.com