# Staff Systems Administrator (5996)

**Company**: Shield AI
**Location**: Bangalore
**Work arrangement**: onsite
**Experience**: staff
**Job type**: Full Time Employee
**Category**: IT
**Industry**: Technology

**Apply**: https://jobs.lever.co/shieldai/2527684b-f4fb-4c16-9ca8-c5532d3f70be?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_a276421f-403

## Description

Shield AI is seeking a highly autonomous Staff Systems Administrator to serve as the accountable technical owner for enterprise IT infrastructure and end-user computing within a dedicated, security-sensitive entity environment.

## Responsibilities

### Infrastructure Ownership (On-Prem & Cloud)

- Design, implement, operate, secure, and continuously improve on-premises systems, cloud platforms, identity services, networks, and endpoints.

- Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness.

- Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements.

- Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information.

- Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices.

### Firewalled Entity and Segmented-Environment Support

- Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required.

- Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity.

- Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries.

- Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence.

- Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure.

- Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance.

### Security, Compliance, and Systems

- Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance.

- Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting.

- Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations.

- Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews.

- Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability.

- Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans.

- Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events.

- Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans.

### Identity, Endpoint, and Service Delivery

- Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement.

- Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement.

- Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation.

- Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity.

- Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal.

- Use scripting and automation to improve consistency, reduce manual effort, strengthen controls, and provide meaningful operational and compliance reporting.

- Contribute reusable infrastructure patterns, standards, and documentation that can scale across comparable international entity environments.

## Requirements

- 12+ years of experience in systems administration, infrastructure engineering, enterprise IT operations, or a closely related discipline.

- Demonstrated success independently owning production IT infrastructure and end-user environments in a complex, regulated, segmented, or security-sensitive organization.

- Strong hands-on expertise with Windows, macOS, and Linux; server administration and virtualization; Azure and/or AWS; and Active Directory and Entra ID or equivalent identity platforms.

- Practical experience implementing system and endpoint hardening, configuration baselines, patch management, vulnerability remediation, encryption, endpoint detection and response, and least-privilege controls.

- Experience supporting security or compliance programs and producing evidence for audits, assessments, or customer and regulatory requirements.

- Strong networking knowledge, including TCP/IP, DNS, DHCP, VLANs, routing, VPNs, network segmentation, firewall policy, and secure remote access.

- Experience with endpoint management platforms such as Intune, Jamf, or equivalent, including compliance policy and device lifecycle management.

- Experience implementing and testing monitoring, backup, disaster recovery, and business-continuity capabilities.

- Excellent documentation, prioritization, risk communication, and stakeholder-management skills, with the ability to drive outcomes under limited supervision.

- Ability to support time-sensitive operational needs and participate in planned after-hours maintenance or incident response when required.

## Preferred Qualifications

- Experience supporting a firewalled, ring-fenced, subsidiary, joint-venture, sovereign, or otherwise separately governed entity environment.

- Experience supporting engineering, R&D, aerospace, defense, manufacturing, or other mission-critical technical teams.

- Working knowledge of recognized security and compliance frameworks such as CIS Controls and Benchmarks, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent local and contractual standards.

- Experience with security tooling such as SIEM, vulnerability-management platforms, privileged-access management, data-loss prevention, certificate management, or network-access control.

- Experience supporting isolated, air-gapped, export-controlled, or data-residency-restricted systems.

- Scripting and automation experience using PowerShell, Bash, Python, APIs, infrastructure as code, or configuration-management tooling.

- Familiarity with GitHub, Azure DevOps, CI/CD environments, and secure engineering workflows.

- Relevant certifications such as Microsoft, AWS, VMware, Cisco, CompTIA Security+, CISSP, CISM, GIAC, ITIL, or equivalent.

## Additional Information

- Total package details for U.S. based positions: Salary within range + Bonus + Benefits + Equity.

- Total package details for International positions: International premium, hardship differential, cost of living differential, living quarters allowance, foreign service transfer allowance, equity, international benefits, visa assistance, and relocation assistance.

## Skills

### Required
- Windows
- macOS
- Linux
- Azure
- AWS
- Active Directory
- Entra ID
- Intune
- Jamf
- TCP/IP
- DNS
- DHCP
- VLANs
- routing
- VPNs
- network segmentation
- firewall policy
- secure remote access

### Nice to have
- CIS Controls and Benchmarks
- NIST
- ISO 27001
- SOC 2
- Cyber Essentials
- SIEM
- vulnerability-management platforms
- privileged-access management
- data-loss prevention
- certificate management
- network-access control
- PowerShell
- Bash
- Python
- APIs
- infrastructure as code
- configuration-management tooling
- GitHub
- Azure DevOps
- CI/CD environments

---

Source: [Apply at jobs.lever.co](https://jobs.lever.co/shieldai/2527684b-f4fb-4c16-9ca8-c5532d3f70be?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
