Earth Is Our Runway
Shield AI Logo

Shield AI

Staff Systems Administrator (5996)

Posted 21 Days Ago
Be an Early Applicant
In-Office
Bangalore, Bengaluru Urban, Karnataka
Expert/Leader
In-Office
Bangalore, Bengaluru Urban, Karnataka
Expert/Leader
Owns enterprise IT infrastructure and end-user computing across on-premises, cloud, identity, networks, endpoints, and segmented environments. Responsibilities include Azure/AWS administration, systems hardening, patching, vulnerability remediation, endpoint management, access controls, backups, disaster recovery, audit evidence, incident response, documentation, automation, asset lifecycle management, and advanced technical support. The role partners with security, legal, compliance, and IT teams to maintain secure, resilient, and compliant operations.
The summary above was generated by AI
Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedIn, X, Instagram, and YouTube. 

Shield AI is seeking a highly autonomous Staff Systems Administrator to serve as the accountable technical owner for enterprise IT infrastructure and end-user computing within a dedicated, security-sensitive entity environment. This senior individual contributor will design, implement, operate, secure, and continuously improve on-premises systems, cloud platforms, identity services, networks, and endpoints while preserving required legal, operational, information-security, and access boundaries.

The role combines deep infrastructure ownership with hands-on service delivery. The successful candidate will translate security and compliance requirements into durable technical controls, maintain audit-ready evidence, drive equipment and endpoint hardening, and deliver resilient support to engineering and business teams with minimal oversight.

What You'll Do:

    Infrastructure Ownership (On-Prem & Cloud)
  • Own and operate on-premises and cloud infrastructure, including physical and virtual servers, storage, backup platforms, identity services, core network services, and enterprise applications.
  • Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness.
  • Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements.
  • Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information.
  • Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices.
  • Firewalled Entity and Segmented-Environment Support

  • Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required.
  • Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity.
  • Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries.
  • Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence.
  • Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure.
  • Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance.
  • Security, Compliance, and Systems

  • Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance.
  • Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting.
  • Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations.
  • Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews.
  • Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability.
  • Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans.
  • Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events.
  • Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans.
  • Identity, Endpoint, and Service Delivery

  • Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement.
  •  Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement.
  • Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation.
  • Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity.
  • Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal.
  • Use scripting and automation to improve consistency, reduce manual effort, strengthen controls, and provide meaningful operational and compliance reporting.
  • Contribute reusable infrastructure patterns, standards, and documentation that can scale across comparable international entity environments.

Required Qualifications:

  • 8+ years of experience in systems administration, infrastructure engineering, enterprise IT operations, or a closely related discipline.
  • Demonstrated success independently owning production IT infrastructure and end-user environments in a complex, regulated, segmented, or security-sensitive organization.
  • Strong hands-on expertise with Windows, macOS, and Linux; server administration and virtualization; Azure and/or AWS; and Active Directory and Entra ID or equivalent identity platforms.
  • Practical experience implementing system and endpoint hardening, configuration baselines, patch management, vulnerability remediation, encryption, endpoint detection and response, and least-privilege controls.
  • Experience supporting security or compliance programs and producing evidence for audits, assessments, or customer and regulatory requirements.
  • Strong networking knowledge, including TCP/IP, DNS, DHCP, VLANs, routing, VPNs, network segmentation, firewall policy, and secure remote access.
  • Experience with endpoint management platforms such as Intune, Jamf, or equivalent, including compliance policy and device lifecycle management.
  • Experience implementing and testing monitoring, backup, disaster recovery, and business-continuity capabilities.
  • Excellent documentation, prioritization, risk communication, and stakeholder-management skills, with the ability to drive outcomes under limited supervision.
  • Ability to support time-sensitive operational needs and participate in planned after-hours maintenance or incident response when required.

Preferred Qualifications

  • Experience supporting a firewalled, ring-fenced, subsidiary, joint-venture, sovereign, or otherwise separately governed entity environment.
  • Experience supporting engineering, R&D, aerospace, defense, manufacturing, or other mission-critical technical teams.
  • Working knowledge of recognized security and compliance frameworks such as CIS Controls and Benchmarks, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent local and contractual standards.
  • Experience with security tooling such as SIEM, vulnerability-management platforms, privileged-access management, data-loss prevention, certificate management, or network-access control.
  • Experience supporting isolated, air-gapped, export-controlled, or data-residency-restricted systems.
  • Scripting and automation experience using PowerShell, Bash, Python, APIs, infrastructure as code, or configuration-management tooling.
  • Familiarity with GitHub, Azure DevOps, CI/CD environments, and secure engineering workflows.
  • Relevant certifications such as Microsoft, AWS, VMware, Cisco, CompTIA Security+, CISSP, CISM, GIAC, ITIL, or equivalent.

Total package details for U.S. based positions:
- Regular employee positions: Salary within range listed above + Bonus + Benefits + Equity
- Temporary employee positions: Hourly within range listed above + temporary benefits package (applicable after 60 days
of employment)
- Interns/Military Fellows/Part-time not eligible for bonus, benefits or equity
 
Total package details for International positions which are roles based outside of the United States (where applicable):
- International premium, hardship differential, cost of living differential, living quarters allowance, foreign service transfer
allowance, equity, international benefits, visa assistance, and relocation assistance.
 
Salary compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, licenses and certifications, and specific work location. All offers are contingent on a cleared background and possible reference check.
 
Shield AI is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or Veteran status. If you have a disability or special need that requires accommodation, please let us know.

Shield AI Waltham, Massachusetts, USA Office

500 Totten Pond Road, Waltham, MA, United States, 02451

Similar Jobs at Shield AI

An Hour Ago
In-Office
Senior level
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
Leads architecture, integration, testing, debugging, and optimization of high-performance C++ and Python systems across distributed, real-time, simulation, infrastructure, and hardware/software environments. Owns messaging and API layers, CI/CD pipelines, build tooling, and end-to-end verification. Provides technical direction, mentors engineers, and drives improvements to shared systems and development processes.
Top Skills: AfsimC++CmakeConanDockerGitlab CiGrpcLinuxNgtsOmsPythonRest ApisUciUnixWindowsZeromq
21 Days Ago
In-Office
Senior level
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Administers and optimizes enterprise Windows, Linux, and macOS infrastructure across cloud, identity, endpoints, servers, networking, and collaboration platforms. Leads infrastructure projects, upgrades, migrations, automation, troubleshooting, asset lifecycle management, incident response, disaster recovery, and business continuity activities. Maintains secure, reliable, scalable systems, documents operations, participates in on-call support, and mentors junior administrators.
Top Skills: Active DirectoryAzure Ad/Entra IdBashDhcpDnsExchange OnlineFirewallsGroup PolicyHyper-VItilJAMFJira Service ManagementLinuxmacOSMicrosoft 365AzureMicrosoft Endpoint ManagerMicrosoft IntuneMicrosoft TeamsPowershellSharepointSnipe-ItTcp/IpVMwareVpnWindows
One Month Ago
In-Office
Senior level
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Lead design and implementation of autonomy and edge-AI software for air, land, and sea platforms. Develop tactical autonomy algorithms, integrate software with hardware, deploy and field-test capabilities, analyze mission data, mentor teammates, collaborate cross-functionally, and support customers and defense programs.
Top Skills: C++Edge AiHivemind Enterprise Autonomy SdkMachine LearningPythonReinforcement Learning

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account