Senior Systems Administrator
- Remote
- All operations jobs
- Sydney
- FullTime
- IT
About the role
Who are we?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
Where does this role fit in?
Build, operate, and strategically evolve the technology platform that enables every UpGuardian to work securely, efficiently, and with minimal friction.
You will hold end-to-end technical ownership over the lifecycle of our corporate technology ecosystem: identity architecture, endpoint engineering, SaaS strategy, and the service practices that hold them together. You’ll architect automation for repetitive workflows, instrument performance and compliance across our systems, and ensure security is built into the foundation of our platforms by design.
This is a senior engineering and platform ownership role, not a ticket queue. If you see the same manual request three times and immediately design an automated, self-service solution to eliminate it permanently….you’ll fit right in.
Security is an outcome of excellent operational engineering here, not the primary function of the role.
What will you do?
Platform, Identity & Fleet Architecture
Enterprise administration and long-term strategy for Google Workspace, Okta (or equivalent IdP), and MDM solutions (Kandji, Jamf) across a predominantly macOS and ChromeOS fleet.
Drive SaaS lifecycle management, asset governance, endpoint compliance standards, and lead the architecture of our global joiner–mover–leaver (JML) processes end to end.
Zero Trust & Secure Access Leadership
Architect, operate, and continually mature our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, secure tunnels, and identity/device-aware access policies.
Lead our transition away from traditional network trust models, ensuring seamless and secure access to internal systems while actively eliminating operational friction for employees.
Automation & Internal Tooling Engineering
Establish automation as the default engineering standard. If a workflow recurs, it is a primary candidate for programmatic resolution.
Leverage REST APIs, Python, Apps Script, Terraform, n8n, and AI-assisted workflows to design, build, and deploy high-impact internal tooling that permanently removes manual overhead.
Service Operations & Systems Governance
Establish and mature Incident, Problem, and Change Management practices. Drive the evolution of our service catalogue, knowledge systems, operational metrics, capacity planning, and readiness frameworks.
Define and implement operational practices where gaps exist, and continually elevate existing frameworks for scale.
Reliability, Continuous Improvement & Self-Service
Lead zero-touch provisioning initiatives, endpoint compliance enforcement, fleet health monitoring, reporting, and SaaS governance.
Drive systems engineering toward "boring reliability" through robust self-service options and self-healing systems.
Embedded Security Engineering
Architect, deploy, and maintain robust security controls, harden endpoints, partner on incident response, mitigate operational risk, and keep baseline configurations current.
Embed security directly into platform operations as an intrinsic property of how systems are built.
What will you bring?
Senior-Level SaaS & Identity Depth: Proven track record administering Google Workspace or Microsoft 365, enterprise IdPs (Okta/Entra), and MDM frameworks at organizational scale. Expertise in SSO, SAML, SCIM, DNS, and PKI/certificates.
Hands-on Zero Trust Experience: Direct experience configuring and optimizing ZTNA, Secure Web Gateways, or modern edge access controls (Cloudflare Zero Trust, Zscaler, Netskope, Tailscale, or Entra Private Access). Ability to take full operational ownership of a Cloudflare implementation, troubleshoot complex edge access issues, and optimize policies.
Demonstrated Automation Capabilities: Demonstrated ability to write production-grade scripts/code (Python, Apps Script, Terraform) and integrate REST APIs. You can point to internal tools or automated pipelines you’ve engineered that permanently eliminated operational work.
Enterprise Fleet Management Maturity: Extensive experience managing macOS at scale, building zero-touch deployment workflows, and enforcing endpoint compliance baselines.
Operational Leadership & Systems Thinking: Proven experience designing or maturing incident/change frameworks, establishing operational SLAs/metrics, and authoring technical documentation that teams rely on.
Infrastructure & Security Fundamentals: Solid foundation in endpoint hardening, identity security, network access controls, and the business acumen to make pragmatic risk trade-offs.
Systems Improvement Instinct: A track record of elevating system architecture and operational frameworks rather than just resolving individual tickets.
What will give you an edge?
Terraform or other Infrastructure as Code
Cloudflare
n8n or similar orchestration
AI and LLM-assisted workflows
Deep macOS expertise
Chrome Enterprise
Working in a security-first or audited environment (SOC 2, ISO 27001)
What's in it for you?
Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being
WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
$1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance
Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
18 weeks paid Parental Leave: Irrespective of parenting role
Personal Leave Allowance: This includes sick & carer’s leave
Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
Top-spec hardware: All team members will be provided with top-spec laptops for their role
Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work
UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!
As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
For applications to positions in the United States, please note, at this time, we can only support hiring in the following US states: CA, MD, MA, IL, OR, WA, CO, TX, FL, PA, LA, MO, or DC.
Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.