Back to all jobs
Senior Systems Engineer
UpGuard
RemoteAustralia1 day agovia Jobicy
Applications for these vacancies are submitted on the employer’s own site. We prepare the documents, then hand you the link.
Job description
Who are we?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
Where does this role fit in?
Build, operate, and strategically evolve the technology platform that enables every UpGuardian to work securely, efficiently, and with minimal friction.
You'll own the hands-on administration and optimization of our core IT stack: identity systems, endpoint engineering, and SaaS platforms. Your main focus will be automating repetitive operational tasks, establishing system performance and compliance metrics, and maintaining a secure-by-default infrastructure.
This is a platform engineering and ownership role above all else, with the added responsibility of serving as the senior escalation point for complex day-to-day issues. We don't want you stuck in a queue, so if you see the same manual task three times and immediately design an automated, self-service fix to permanently remove it, you’ll fit right in.
Security is an outcome of excellent operational engineering here, not the primary function of the role.
What will you do?
Platform, Identity & Fleet Operations
Drive end-to-end shared platform ownership across Google Workspace, Okta, and enterprise MDM (Kandji/Jamf) for our macOS and ChromeOS fleet. You’ll architect robust SSO/SAML integrations, optimize SCIM provisioning, design scalable role hierarchies, and establish proactive OS lifecycle and patching strategies that keep our systems secure by default.
Optimise our global joiner-mover-leaver process. Find the steps that still need a human, automate them, and tighten the handoffs with the People Team. Keep asset records and endpoint compliance reporting accurate, and administer the SaaS estate against the governance model.
Zero Trust & Secure Access
Take operational ownership of our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, secure tunnels, and identity and device-aware access policies. Tune policies, and troubleshoot the edge access problems that get escalated past everyone else.
Own the migration of remaining internal applications off legacy network access as a workstream, and flag where a control is creating friction that isn't buying us anything.
Automation & Internal Tooling
Build production-grade tooling using REST APIs, Python, Apps Script, and n8n that permanently removes manual work.
Propose what should be automated next, based on what you're seeing in the queue.
Service Operations
Take incident command for platform incidents on rota. Coordinate the response, keep people informed, drive to resolution, then write the postmortem and see the actions through to closure.
Raise and execute changes through our change process, including risk assessment and rollback. Investigate recurring incidents to root cause and own the resulting problem records.
Keep the runbooks, knowledge base, and service catalogue entries accurate for the systems you run. Where you find a gap in the practice, propose the fix and pilot it on your own systems.
Reliability & Self-Service
Own zero-touch provisioning, endpoint compliance enforcement, and fleet health monitoring.
Build the self-service options and self-healing behaviour that make routine requests stop reaching the team.
Embedded Security Engineering
Implement and maintain endpoint hardening and baseline configurations, and keep them current. Act as technical responder on
DevOps & InfrastructureSenior