Shield AI is seeking a highly autonomous Staff Systems Administrator to serve as the accountable technical owner for enterprise IT infrastructure and end-user computing within a dedicated, security-sensitive entity environment. This senior individual contributor will design, implement, operate, secure, and continuously improve on-premises systems, cloud platforms, identity services, networks, and endpoints while preserving required legal, operational, information-security, and access boundaries.
The role combines deep infrastructure ownership with hands-on service delivery. The successful candidate will translate security and compliance requirements into durable technical controls, maintain audit-ready evidence, drive equipment and endpoint hardening, and deliver resilient support to engineering and business teams with minimal oversight.
What You'll Do:
- Own and operate on-premises and cloud infrastructure, including physical and virtual servers, storage, backup platforms, identity services, core network services, and enterprise applications.
- Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness.
- Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements.
- Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information.
- Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices.
- Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required.
- Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity.
- Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries.
- Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence.
- Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure.
- Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance.
- Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance.
- Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting.
- Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations.
- Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews.
- Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability.
- Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans.
- Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events.
- Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans.
- Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement.
- Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement.
- Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation.
- Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity.
- Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal.
- Use scripting and automation to improve consistency, reduce manual effort, strengthen controls, and provide meaningful operational and compliance reporting.
- Contribute reusable infrastructure patterns, standards, and documentation that can scale across comparable international entity environments.
Firewalled Entity and Segmented-Environment Support
Security, Compliance, and Systems
Identity, Endpoint, and Service Delivery
Required Qualifications:
- 12+ years of experience in systems administration, infrastructure engineering, enterprise IT operations, or a closely related discipline.
- Demonstrated success independently owning production IT infrastructure and end-user environments in a complex, regulated, segmented, or security-sensitive organization.
- Strong hands-on expertise with Windows, macOS, and Linux; server administration and virtualization; Azure and/or AWS; and Active Directory and Entra ID or equivalent identity platforms.
- Practical experience implementing system and endpoint hardening, configuration baselines, patch management, vulnerability remediation, encryption, endpoint detection and response, and least-privilege controls.
- Experience supporting security or compliance programs and producing evidence for audits, assessments, or customer and regulatory requirements.
- Strong networking knowledge, including TCP/IP, DNS, DHCP, VLANs, routing, VPNs, network segmentation, firewall policy, and secure remote access.
- Experience with endpoint management platforms such as Intune, Jamf, or equivalent, including compliance policy and device lifecycle management.
- Experience implementing and testing monitoring, backup, disaster recovery, and business-continuity capabilities.
- Excellent documentation, prioritization, risk communication, and stakeholder-management skills, with the ability to drive outcomes under limited supervision.
- Ability to support time-sensitive operational needs and participate in planned after-hours maintenance or incident response when required.
Preferred Qualifications
- Experience supporting a firewalled, ring-fenced, subsidiary, joint-venture, sovereign, or otherwise separately governed entity environment.
- Experience supporting engineering, R&D, aerospace, defense, manufacturing, or other mission-critical technical teams.
- Working knowledge of recognized security and compliance frameworks such as CIS Controls and Benchmarks, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent local and contractual standards.
- Experience with security tooling such as SIEM, vulnerability-management platforms, privileged-access management, data-loss prevention, certificate management, or network-access control.
- Experience supporting isolated, air-gapped, export-controlled, or data-residency-restricted systems.
- Scripting and automation experience using PowerShell, Bash, Python, APIs, infrastructure as code, or configuration-management tooling.
- Familiarity with GitHub, Azure DevOps, CI/CD environments, and secure engineering workflows.
- Relevant certifications such as Microsoft, AWS, VMware, Cisco, CompTIA Security+, CISSP, CISM, GIAC, ITIL, or equivalent.
Skills Required
- 12+ years of experience in systems administration, infrastructure engineering, enterprise IT operations, or a closely related discipline
- Experience independently owning production IT infrastructure and end-user environments in a complex, regulated, segmented, or security-sensitive organization
- Hands-on expertise with Windows, macOS, Linux, server administration, virtualization, Azure and/or AWS, and Active Directory and Entra ID or equivalent identity platforms
- Experience implementing system and endpoint hardening, configuration baselines, patch management, vulnerability remediation, encryption, endpoint detection and response, and least-privilege controls
- Experience supporting security or compliance programs and producing audit, assessment, customer, or regulatory evidence
- Strong networking knowledge including TCP/IP, DNS, DHCP, VLANs, routing, VPNs, network segmentation, firewall policy, and secure remote access
- Experience with endpoint management platforms such as Intune, Jamf, or equivalent, including compliance policy and device lifecycle management
- Experience implementing and testing monitoring, backup, disaster recovery, and business continuity capabilities
- Excellent documentation, prioritization, risk communication, and stakeholder-management skills, with the ability to work under limited supervision
- Ability to support time-sensitive operational needs and participate in planned after-hours maintenance or incident response
- Experience supporting a firewalled, ring-fenced, subsidiary, joint-venture, sovereign, or separately governed entity environment
- Experience supporting engineering, R&D, aerospace, defense, manufacturing, or other mission-critical technical teams
- Working knowledge of CIS Controls, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent frameworks
- Experience with SIEM, vulnerability-management, privileged-access management, data-loss prevention, certificate-management, or network-access-control tools
- Experience supporting isolated, air-gapped, export-controlled, or data-residency-restricted systems
- Scripting and automation experience using PowerShell, Bash, Python, APIs, infrastructure as code, or configuration-management tooling
- Familiarity with GitHub, Azure DevOps, CI/CD environments, and secure engineering workflows
- Relevant Microsoft, AWS, VMware, Cisco, CompTIA Security+, CISSP, CISM, GIAC, or ITIL certification
Shield AI Compensation & Benefits Highlights
-
Healthcare Strength — Healthcare coverage is described as excellent, with dental/vision and mental‑health support, and ancillary protections like life and disability appearing in benefit summaries. The breadth and perceived affordability of coverage are highlighted as a standout component of the package.
-
Parental & Family Support — Paid parental leave is featured alongside enhanced maternity benefits, fertility and childcare support, and onsite resources such as a Mother’s Room. These elements are positioned as competitive and above the minimal baseline for the company’s stage.
-
Equity Value & Accessibility — Equity is granted to all full‑time hires, with RSUs, double‑trigger tax timing, and tools to model scenarios (e.g., through Carta Tax). Communications also reference a transition from options to RSUs, reinforcing access and maturity of ownership programs.
Shield AI Insights
What We Do
At Shield AI, you won't wait years to see your work reach the field. You'll build hardware and software that operates in the real world right now, in the hands of the people who depend on it. Hivemind, our AI pilot, has been flying since 2018. It has flown more than 30 platforms, including an F-16, and it now sits under a U.S. Air Force production contract for Collaborative Combat Aircraft. When you write code or shape a system here, you contribute to technology with a proven flight record and a clear production future. V-BAT flies intelligence, surveillance, and reconnaissance missions with an operational record that stretches from Ukraine to the Indo-Pacific. It delivers eyes where they matter most, in the most demanding conditions on earth. The teams behind it watch their work get tested where the stakes are real. X-BAT takes its first flight this year. It's an AI-piloted fighter that needs no runway, built to operate where traditional aircraft can't. Join now and you help shape a program at its earliest, most formative stage. That's the kind of ground-floor work that defines a career. Do the most impactful work of your life, on problems that matter. Autonomy at this level asks a lot of you. You'll take on problems in perception, planning, and control that few teams anywhere are equipped to solve. You'll work across disciplines, from aerospace and robotics to machine learning and systems engineering, alongside people who hold themselves to an exacting standard and expect the same from you. Our mission is clear: protect service members and civilians with intelligent systems. That purpose runs through every decision, every design review, and every deployment. It's why the work here carries a weight you can feel. Ready to join our mission? Explore our open roles and find where you fit.
Why Work With Us
Founded in 2015 by a former Navy SEAL, Shield AI builds AI pilots and uncrewed aircraft. Veterans aren't an afterthought here, they're at every level. It's why the work carries weight: AI pilots and uncrewed aircraft flying real missions, from Ukraine to the Indo-Pacific, protecting service members and civilians.
Gallery
Shield AI Teams
Shield AI Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
.jpg)


