The Senior IT Systems Engineer builds, improves, and sustains classified infrastructure supporting engineering work. The role covers compute, virtualization, storage, networking, identity, endpoints, and security tooling in standalone and air-gapped environments.
This is a hands-on senior individual contributor position. Responsibilities include racking and imaging hardware, building and hardening systems, automating repeatable work, troubleshooting difficult issues, and helping establish technical standards across sites. The engineer must be comfortable working independently, shifting across infrastructure disciplines when needed, and owning work from design through testing, documentation, and support.
The role sits between IT operations and accreditation. Systems must be secure, reliable, and ready for review by ISSMs and government assessors. Correct implementation the first time, backed by complete documentation and technical evidence, is an expected part of every build.
What you'll do:
- Deploy, configure, and sustain Windows Server and Red Hat Enterprise Linux systems, virtualization clusters, enterprise storage, and core infrastructure services in standalone and air-gapped enclaves.
- Build and support VMware, Nutanix AHV/Prism, or similar virtualization environments. Nutanix experience is preferred.
- Support high-density compute for AI/ML, simulation, and engineering workloads, including GPU node provisioning, performance troubleshooting, capacity planning, and coordination with facilities on rack space, power, and cooling.
- Administer and support Active Directory, DNS, DHCP, Group Policy, PKI, certificate services, privileged access, and role-based access for isolated forests with no connection to corporate IT.
- Build and maintain golden images and hardened baselines for servers, workstations, virtual desktops, and supporting infrastructure.
- Manage patching, updates, software packages, and security content in disconnected environments through approved transfer and validation processes.
- Administer backup, recovery, and continuity capabilities. Perform scheduled restore testing and document results and corrective actions.
- Design, configure, and troubleshoot managed switching, VLANs, firewall rules, network segmentation, and approved network connections between facilities. Coordinate with network and security teams to maintain secure, supportable network standards.
- Automate provisioning, configuration, patching, reporting, and compliance tasks using PowerShell, Ansible, Python, Terraform, or similar tools.
- Create repeatable build processes, system baselines, checklists, and runbooks so systems can be deployed consistently rather than built by hand each time.
- Improve existing processes by reducing manual steps, preventing common errors, and documenting effective methods for building and supporting systems.
- Apply and validate DISA STIGs and SRGs using SCAP, STIG Viewer, ACAS/Nessus, scripted remediation, and other approved tools.
- Maintain configuration-management records, as-built documentation, change records, and scan evidence so system configurations can be understood and defended later.
- Review technical changes before production implementation, with attention to security, availability, rollback planning, and operational impact.
- Work with ISSMs, ISSOs, security teams, and program stakeholders to implement NIST SP 800-53, JSIG, RMF, and program-specific technical controls.
- Provide technical documentation and evidence for authorization packages, continuous monitoring, assessments, and audits.
- Implement and maintain audit logging and forwarding, including Elastic or similar centralized logging and SIEM tools.
- Support vulnerability management through ACAS/Nessus scanning, findings triage, remediation planning, patching, and validation during approved maintenance windows.
- Help resolve technical POA&M items and document remediation steps, validation results, and remaining risks.
- Support approved media handling, file transfer, cross-domain processes, and contamination or spillage response alongside the security team.
- Act as a senior escalation point for classified IT issues that block engineering work or require deeper troubleshooting across multiple systems.
- Identify and correct root causes rather than relying on repeated fixes or workarounds.
- Support user-account, privileged-access, and workstation-access requests consistent with least privilege and separation-of-duties requirements.
- Support new facility and enclave stand-ups from rack layout and cabling through infrastructure deployment, user onboarding, and operational handoff.
- Mentor junior system administrators and site IT staff, review implementation work before production release, and help improve team standards.
- Work independently, manage competing priorities, communicate risks early, and bring practical solutions to the team.
Build and operate classified infrastructure
Automate and standardize
Support accreditation and security operations
Support users and sites
Required qualifications:
- Strong hands-on experience with Windows Server, Active Directory, Group Policy, DNS, DHCP, PKI, and enterprise endpoint management.
- Experience administering Red Hat Enterprise Linux or similar enterprise Linux systems.
- Experience with VMware, Nutanix, Hyper-V, or similar enterprise virtualization platforms. Nutanix AHV/Prism experience is preferred.
- Experience with enterprise storage, backup/recovery, and capacity planning.
- Experience with managed switching, VLANs, firewall administration, network segmentation, and troubleshooting network connectivity.
- Experience with PowerShell and infrastructure automation. Experience with Ansible, Python, Terraform, or similar tools is a plus.
- Experience applying DISA STIGs, using SCAP/STIG Viewer, supporting ACAS/Nessus findings, and working in RMF, NIST SP 800-53, JSIG, or similarly regulated environments.
- Experience operating in disconnected, air-gapped, classified, or highly controlled environments.
- Ability to document work clearly, follow change control, validate results, and build systems that are easy for others to support.
- Ability to work independently in a fast-moving environment, shift between infrastructure disciplines when needed, and make sound technical decisions without requiring detailed direction.
Preferred qualifications:
- Nutanix AHV, Prism Central, Files, Flow, or cluster lifecycle management.
- GPU server, AI/ML, simulation, VDI, or high-performance compute infrastructure.
- Elastic, Splunk, or other centralized logging and SIEM platforms.
- Disconnected WSUS, offline patching, software-repository management, or approved media-transfer workflows.
- Data-center buildouts, rack-and-stack, structured cabling, power/cooling coordination, and new-facility stand-ups.
- Relevant technical or security certifications, such as Security+, CISSP, RHCSA/RHCE, VMware VCP, Nutanix NCA/NCP, Microsoft certifications, or CCNA/CCNP.
Skills Required
- Hands-on experience with Windows Server, Active Directory, Group Policy, DNS, DHCP, PKI, and enterprise endpoint management
- Experience administering Red Hat Enterprise Linux or similar enterprise Linux systems
- Experience with VMware, Nutanix, Hyper-V, or similar enterprise virtualization platforms
- Experience with enterprise storage, backup and recovery, and capacity planning
- Experience with managed switching, VLANs, firewall administration, network segmentation, and connectivity troubleshooting
- Experience with PowerShell and infrastructure automation
- Experience with Ansible, Python, Terraform, or similar tools
- Experience applying DISA STIGs, using SCAP and STIG Viewer, and supporting ACAS/Nessus findings
- Experience working with RMF, NIST SP 800-53, JSIG, or similarly regulated environments
- Experience operating in disconnected, air-gapped, classified, or highly controlled environments
- Ability to document work clearly, follow change control, validate results, and build supportable systems
- Ability to work independently, shift across infrastructure disciplines, and make sound technical decisions
- Nutanix AHV, Prism Central, Files, Flow, or cluster lifecycle management experience
- GPU server, AI/ML, simulation, VDI, or high-performance computing infrastructure experience
- Elastic, Splunk, or other centralized logging and SIEM platform experience
- Disconnected WSUS, offline patching, software repository management, or approved media-transfer workflow experience
- Data-center buildout, rack-and-stack, structured cabling, power/cooling coordination, or new-facility stand-up experience
- Relevant certifications such as Security+, CISSP, RHCSA/RHCE, VMware VCP, Nutanix NCA/NCP, Microsoft certifications, or CCNA/CCNP
What We Do
At Shield AI, you won't wait years to see your work reach the field. You'll build hardware and software that operates in the real world right now, in the hands of the people who depend on it. Hivemind, our AI pilot, has been flying since 2018. It has flown more than 30 platforms, including an F-16, and it now sits under a U.S. Air Force production contract for Collaborative Combat Aircraft. When you write code or shape a system here, you contribute to technology with a proven flight record and a clear production future. V-BAT flies intelligence, surveillance, and reconnaissance missions with an operational record that stretches from Ukraine to the Indo-Pacific. It delivers eyes where they matter most, in the most demanding conditions on earth. The teams behind it watch their work get tested where the stakes are real. X-BAT takes its first flight this year. It's an AI-piloted fighter that needs no runway, built to operate where traditional aircraft can't. Join now and you help shape a program at its earliest, most formative stage. That's the kind of ground-floor work that defines a career. Do the most impactful work of your life, on problems that matter. Autonomy at this level asks a lot of you. You'll take on problems in perception, planning, and control that few teams anywhere are equipped to solve. You'll work across disciplines, from aerospace and robotics to machine learning and systems engineering, alongside people who hold themselves to an exacting standard and expect the same from you. Our mission is clear: protect service members and civilians with intelligent systems. That purpose runs through every decision, every design review, and every deployment. It's why the work here carries a weight you can feel. Ready to join our mission? Explore our open roles and find where you fit.
Why Work With Us
Founded in 2015 by a former Navy SEAL, Shield AI builds AI pilots and uncrewed aircraft. Veterans aren't an afterthought here, they're at every level. It's why the work carries weight: AI pilots and uncrewed aircraft flying real missions, from Ukraine to the Indo-Pacific, protecting service members and civilians.
Gallery
Shield AI Teams
Shield AI Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
.jpg)


