
Staff Systems Administrator (5996)
- AI
- Azure
- AWS
- Disaster Recovery
- Windows
- MacOS
- Linux
- EDR
- Conditional Access
- Incident Response
- Intune
- Jamf
- Active Directory
- TCP/IP
- DNS
- DHCP
- VLANs
- CIS Controls
- NIST
- ISO 27001
- SOC2
- SIEM
- Vulnerability Management
- PowerShell
- Bash
- Python
- IaC
- Configuration Management
- GitHub
- Azure DevOps
- CI/CD
- VMware
- Cisco
- CompTIA Security+
- CISSP
- CISM
- ITIL
- Equity
Shield AI is seeking a highly autonomous Staff Systems Administrator to serve as the accountable technical owner for enterprise IT infrastructure and end-user computing within a dedicated, security-sensitive entity environment. This senior individual contributor will design, implement, operate, secure, and continuously improve on-premises systems, cloud platforms, identity services, networks, and endpoints while preserving required legal, operational, information-security, and access boundaries.
The role combines deep infrastructure ownership with hands-on service delivery. The successful candidate will translate security and compliance requirements into durable technical controls, maintain audit-ready evidence, drive equipment and endpoint hardening, and deliver resilient support to engineering and business teams with minimal oversight.
What You'll Do:
- Infrastructure Ownership (On-Prem & Cloud)
- Own and operate on-premises and cloud infrastructure, including physical and virtual servers, storage, backup platforms, identity services, core network services, and enterprise applications.
- Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness.
- Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements.
- Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information.
- Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices.
- Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required.
- Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity.
- Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries.
- Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence.
- Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure.
- Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance.
- Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance.
- Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting.
- Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations.
- Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews.
- Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability.
- Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans.
- Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events.
- Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans.
- Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement.
- Â Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement.
- Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation.
- Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity.
- Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal.
- Use scripting and automation to improve consistency, reduce manual effort, strengthen controls, and provide meaningful operational and compliance reporting.
- Contribute reusable infrastructure patterns, standards, and documentation that can scale across comparable international entity environments.
Firewalled Entity and Segmented-Environment Support
Security, Compliance, and Systems
Identity, Endpoint, and Service Delivery
Required Qualifications:
- 12+ years of experience in systems administration, infrastructure engineering, enterprise IT operations, or a closely related discipline.
- Demonstrated success independently owning production IT infrastructure and end-user environments in a complex, regulated, segmented, or security-sensitive organization.
- Strong hands-on expertise with Windows, macOS, and Linux; server administration and virtualization; Azure and/or AWS; and Active Directory and Entra ID or equivalent identity platforms.
- Practical experience implementing system and endpoint hardening, configuration baselines, patch management, vulnerability remediation, encryption, endpoint detection and response, and least-privilege controls.
- Experience supporting security or compliance programs and producing evidence for audits, assessments, or customer and regulatory requirements.
- Strong networking knowledge, including TCP/IP, DNS, DHCP, VLANs, routing, VPNs, network segmentation, firewall policy, and secure remote access.
- Experience with endpoint management platforms such as Intune, Jamf, or equivalent, including compliance policy and device lifecycle management.
- Experience implementing and testing monitoring, backup, disaster recovery, and business-continuity capabilities.
- Excellent documentation, prioritization, risk communication, and stakeholder-management skills, with the ability to drive outcomes under limited supervision.
- Ability to support time-sensitive operational needs and participate in planned after-hours maintenance or incident response when required.
Preferred Qualifications
- Experience supporting a firewalled, ring-fenced, subsidiary, joint-venture, sovereign, or otherwise separately governed entity environment.
- Experience supporting engineering, R&D, aerospace, defense, manufacturing, or other mission-critical technical teams.
- Working knowledge of recognized security and compliance frameworks such as CIS Controls and Benchmarks, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent local and contractual standards.
- Experience with security tooling such as SIEM, vulnerability-management platforms, privileged-access management, data-loss prevention, certificate management, or network-access control.
- Experience supporting isolated, air-gapped, export-controlled, or data-residency-restricted systems.
- Scripting and automation experience using PowerShell, Bash, Python, APIs, infrastructure as code, or configuration-management tooling.
- Familiarity with GitHub, Azure DevOps, CI/CD environments, and secure engineering workflows.
- Relevant certifications such as Microsoft, AWS, VMware, Cisco, CompTIA Security+, CISSP, CISM, GIAC, ITIL, or equivalent.
Staff Systems Administrator (5996) · Shield AI