IT运维分析师
IT Operations Analyst
### **我们是谁?**
在 UpGuard,我们用人工智能驱动的精准性取代了手动安全瓶颈。刚刚完成 7500 万美元 C 轮融资后,我们正在扩展基础设施,以每天处理 1000 亿个风险信号。这不仅仅是增长;而是对全球管理网络风险方式的彻底重新定义。
我们打造了网络安全态势管理(CRPM)平台,安全团队真正喜欢的平台。通过整合安全评分、威胁情报和代理型 AI,我们使组织能够领先于不断变化的攻击面。
我们不只是打造另一个工具;我们正在定义一个新类别。我们提供自主开发世界级技术的能力,以及在全球范围内实现这一目标的资源。
**这个职位在这个体系中扮演什么角色?**
- 构建、运营并持续改进让每个 UpGuardian 安全、高效且低摩擦工作的技术平台。
- 你将负责企业技术的整个生命周期:身份、终端设备、SaaS 以及支撑它们的服务实践。你将自动化重复部分,对其他部分进行监控,并让安全成为系统构建方式的属性,而不是某人记得去完成的任务。
- 这是一个工程岗位,而不是工单队列。如果你看到同样的请求三次,你的第一反应是“为什么还有人做这个?”——你会很适合。
- 在这里,安全是优秀运维工程的结果,而不是该职位的主要职能。
**你将做什么?**
**平台、身份和设备群**
- 在主要使用 macOS 和 ChromeOS 的设备群中,使用 Google Workspace、Okta(或等效 IdP)和 MDM(Kandji、Jamf 或类似产品)
- 你将负责 SaaS 管理和生命周期、资产管理和终端标准与合规性,以及入职–调动–离职流程的全流程
**零信任和安全访问**
- 在 ZTNA、安全 Web 网关、DNS 过滤、隧道和基于身份与设备的访问策略方面,运营并持续改进我们的 Cloudflare 零信任环境
- 你将帮助我们摆脱传统的网络信任模式,维护对内部应用和服务的安全访问,排查访问和连接问题,并确保安全控制不会给员工带来不必要的麻烦
**自动化和内部工具**
- 自动化是默认方法,而不是一个远大目标。如果一个任务发生超过两次,它就值得用代码来实现
- 你将使用 REST API、Python、Apps Script、Terraform、n8n 和 AI 辅助工作流来构建内部工具
查看英文原文
### **Who are we?**
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
**Where does this role fit in?**
- Build, operate and continually improve the technology platform that lets every UpGuardian work securely, efficiently and with minimal friction.
- You’ll own the lifecycle of our corporate technology end to end: identity, endpoints, SaaS and the service practices that hold them together. You’ll automate the repetitive parts, instrument the rest, and make security a property of how systems are built rather than a task someone remembers to do.
- This is an engineering role, not a ticket queue. If you see the same request three times and your first thought is “why is a human still doing this?” - you’ll fit.
- Security is an outcome of excellent operational engineering here, not the primary function of the role.
**What will you do?**
**Platform, identity and fleet**
- Google Workspace, Okta (or equivalent IdP), and MDM (Kandji, Jamf or similar) across a mostly macOS and ChromeOS fleet
- You’ll own SaaS administration and lifecycle, asset management, endpoint standards and compliance, and the joiner–mover–leaver process end to end
**Zero Trust and secure access**
- Operate and continually improve our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, tunnels and identity and device aware access policies
- You’ll help move us away from traditional network trust, maintain secure access to internal applications and services, troubleshoot access and connectivity issues, and make sure security controls don’t create unnecessary friction for employees
**Automation and internal tooling**
- Automation is the default approach, not a stretch goal. If a task happens more than twice, it’s a candidate for code
- You’ll work with REST APIs, Python, Apps Script, Terraform, n8n and AI assisted workflows to build internal tooling that removes work rather than making it faster to do by hand
**Service operations**
- Incident, problem and change management. Service catalogue, knowledge base, service metrics, capacity planning and operational readiness
- You’ll define these practices where they don’t exist yet and improve the ones that do
**Reliability and continuous improvement**
- Zero touch provisioning, endpoint compliance, fleet health, monitoring, reporting, SaaS governance and self service. Making internal platforms boringly reliable is the goal
**Security, embedded**
- Deploy and maintain security controls, harden endpoints, support security incidents, reduce operational risk and keep baselines current
- Security is part of how you’ll operate the platform rather than a separate function you’ll own
**What will you bring?**
You won’t have all of this. Tell us which parts you’d be learning, and we’ll tell you honestly whether that works
- **Depth across enterprise SaaS and identity**- you’ve administered Google Workspace or Microsoft 365, an IdP such as Okta or Entra, and MDM at organisational scale. You’re comfortable with SSO, SAML, SCIM, DNS and certificates
- **Zero Trust, hands on** - you’ve worked with ZTNA, Secure Web Gateway or modern network access controls, ideally Cloudflare Zero Trust or a similar platform such as Zscaler, Netskope, Tailscale or Entra Private Access. You understand identity and device aware access and the principles behind replacing traditional network trust
- You don’t need to be a Zero Trust specialist, but you should be comfortable taking ownership of an existing Cloudflare implementation, troubleshooting it and making it better
- **You genuinely automate** - you write code using Python, Apps Script or similar, work confidently with REST APIs, and can point to internal tooling you’ve shipped that removed recurring work permanently
- **Fleet management maturity**- you’ve worked with macOS at scale, zero touch provisioning and endpoint compliance baselines
- **Service operations experience** - you’ve run incident and change practices, defined metrics and built documentation people actually use
- **Security and infrastructure fundamentals**- you’re comfortable with endpoint hardening, identity security, DNS, certificates, secure network access and making sensible risk trade offs
- **Process improvement instinct**- you make the system better, not just the outcome of one request
**What will give you an edge?**
- Terraform or other Infrastructure as Code
- Cloudflare
- n8n or similar orchestration
- AI and LLM-assisted workflows
- Deep macOS expertise
- Chrome Enterprise
- Working in a security-first or audited environment (SOC 2, ISO 27001)
**What's in it for you?**
- **Monthly Lifestyle subsidy:** Use this for financial, physical, and mental well-being
- **WFH set-up allowance:** To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
- **$1500 USD annual Learning & Development allowance:** To support your career development, all team members will be able to expense development opportunities against this allowance
- **Annual leave:** PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
- **18 weeks paid Parental Leave:** Irrespective of parenting role
- **Personal Leave Allowance:** This includes sick & carer’s leave
- **Fully remote working environment:** While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
- **Top-spec hardware:** All team members will be provided with top-spec laptops for their role
- **Generative AI subsidy:** UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work
- **Health Insurance:** Access to comprehensive coverage.
UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!
As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
**Please Note:** Not all roles can be performed from the United States. Please check your specific job listing to confirm its advertised location. If the role you are applying for is listed as based in the US, we are currently only able to support hiring in the following locations: CA, CO, FL, IL, LA, MA, MD, MO, OR, PA, TX, WA, and DC.
Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.