高级系统工程师
Senior Systems Engineer
### **我们是谁?**
在 UpGuard,我们用人工智能驱动的精准性取代了手动安全瓶颈。刚刚完成 7500 万美元 C 轮融资后,我们正在扩展基础设施,以每天处理 1000 亿个风险信号。这不仅仅是增长;而是对全球管理网络风险方式的彻底重新定义。
我们打造了网络安全态势管理(CRPM)平台,这是安全团队真正喜欢的平台。通过整合安全评级、威胁情报和代理型 AI,我们使组织能够领先于不断演变的攻击面。
我们不只是打造另一个工具;我们正在定义一个新类别。我们提供自主开发世界级技术的能力以及在全球范围内实现这一目标的资源。
**这个职位将如何融入我们的团队?**
构建、运营并战略性地推进使每位 UpGuardian 能够安全、高效且无摩擦工作的技术平台。
你将负责核心 IT 堆栈的现场管理和优化:身份系统、终端工程和 SaaS 平台。你的主要任务是自动化重复的操作任务,建立系统性能和合规指标,并维护默认安全的基础设施。
这个职位首先是平台工程和所有权角色,同时还需要承担复杂日常问题的高级解决职责。我们不希望你被卡在队列中,如果你发现同样的手动任务出现三次,并立即设计出自动化的自助解决方案来永久消除它,那么你将非常契合。
**在这里,安全是卓越的运维工程的结果,而不是该职位的主要职能。**
**你会做什么?**
**平台、身份与设备运维**
- 在 Google Workspace、Okta 和企业 MDM(Kandji/Jamf)之间推动针对 macOS 和 ChromeOS 设备组的端到端共享平台责任。你将设计强大的 SSO/SAML 集成,优化 SCIM 配置,设计可扩展的角色层级,并制定主动的 OS 生命周期和补丁策略,确保我们的系统默认安全。
- 优化我们的全球入职-调动-离职流程。找出仍需要人工干预的步骤,进行自动化,并与人力资源团队加强交接。保持资产记录和终端合规报告的准确性,并根据治理模型管理 SaaS 系统。
**零信任与安全访问**
- 操作我们跨 ZTNA、安全 Web 网关和 DNS 的 Cloudflare 零信任环境。
查看英文原文
### **Who are we?**
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
**Where does this role fit in?**
Build, operate, and strategically evolve the technology platform that enables every UpGuardian to work securely, efficiently, and with minimal friction.
You'll own the hands-on administration and optimization of our core IT stack: identity systems, endpoint engineering, and SaaS platforms. Your main focus will be automating repetitive operational tasks, establishing system performance and compliance metrics, and maintaining a secure-by-default infrastructure.
This is a platform engineering and ownership role above all else, with the added responsibility of serving as the senior escalation point for complex day-to-day issues. We don't want you stuck in a queue, so if you see the same manual task three times and immediately design an automated, self-service fix to permanently remove it, you’ll fit right in.
_Security is an outcome of excellent operational engineering here, not the primary function of the role._
**What will you do?**
**Platform, Identity & Fleet Operations**
- Drive end-to-end **shared** platform ownership across Google Workspace, Okta, and enterprise MDM (Kandji/Jamf) for our macOS and ChromeOS fleet. You’ll architect robust SSO/SAML integrations, optimize SCIM provisioning, design scalable role hierarchies, and establish proactive OS lifecycle and patching strategies that keep our systems secure by default.
- Optimise our global joiner-mover-leaver process. Find the steps that still need a human, automate them, and tighten the handoffs with the People Team. Keep asset records and endpoint compliance reporting accurate, and administer the SaaS estate against the governance model.
**Zero Trust & Secure Access**
- Take operational ownership of our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, secure tunnels, and identity and device-aware access policies. Tune policies, and troubleshoot the edge access problems that get escalated past everyone else.
- Own the migration of remaining internal applications off legacy network access as a workstream, and flag where a control is creating friction that isn't buying us anything.
**Automation & Internal Tooling**
- Build production-grade tooling using REST APIs, Python, Apps Script, and n8n that permanently removes manual work.
- Propose what should be automated next, based on what you're seeing in the queue.
**Service Operations**
- Take incident command for platform incidents on rota. Coordinate the response, keep people informed, drive to resolution, then write the postmortem and see the actions through to closure.
- Raise and execute changes through our change process, including risk assessment and rollback. Investigate recurring incidents to root cause and own the resulting problem records.
- Keep the runbooks, knowledge base, and service catalogue entries accurate for the systems you run. Where you find a gap in the practice, propose the fix and pilot it on your own systems.
**Reliability & Self-Service**
- Own zero-touch provisioning, endpoint compliance enforcement, and fleet health monitoring.
- Build the self-service options and self-healing behaviour that make routine requests stop reaching the team.
**Embedded Security Engineering**
- Implement and maintain endpoint hardening and baseline configurations, and keep them current. Act as technical responder on security incidents and support the evidence side of audit and compliance work.
- Design security into platform changes as you make them rather than adding it afterwards. Where you find operational risk, surface it with a recommendation attached.
**Raising the Level Around You**
- Mentor your colleagues on the platforms and tools you know best. Where you fix something, leave documentation behind so the next person doesn't need you.
**What will you bring?**
You won't have all of this. Tell us which parts you'd be learning, and we'll tell you honestly whether that works.
- **SaaS & Identity Depth:** Several years administering Google Workspace or Microsoft 365 alongside an enterprise IdP (Okta, Entra) and MDM at organisational scale. SSO, SAML, SCIM, DNS, and certificates as things you've configured and debugged.
- **Hands-on Zero Trust Experience:** Direct experience configuring and optimising ZTNA, Secure Web Gateways, or modern edge access controls (Cloudflare Zero Trust, Zscaler, Netskope, Tailscale, Entra Private Access). Enough to take operational ownership of a Cloudflare estate and troubleshoot complex edge access issues.
- **Automation Capability:** Production-grade scripts or code (Python, Apps Script, Terraform) integrated against REST APIs. Point us at internal tools or pipelines you've built that permanently eliminated operational work.
- **Fleet Management at Scale:** Managing macOS at scale, building zero-touch deployment workflows, and enforcing endpoint compliance baselines.
- **Process Optimisation:** You've taken a joiner-mover-leaver or similar cross-functional process and measurably reduced the manual steps in it, working with People or HR to do it.
- **Operational Discipline:** Experience running incidents, working within a change process, and authoring technical documentation that teams rely on.
- **Security Fundamentals:** Endpoint hardening, identity security, and network access controls, with the judgment to make proportionate risk recommendations and know which calls aren't yours.
- **Systems Improvement Instinct:** A track record of eliminating classes of problem rather than resolving individual tickets.
- **Independent Judgment:** Enough to keep things running for a couple of weeks without your manager, and enough to know which decisions should wait for them.
**What's in it for you?**
- **Monthly Lifestyle subsidy:** Use this for financial, physical, and mental well-being
- **WFH set-up allowance:** To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
- **$1500 USD annual Learning & Development allowance:** To support your career development, all team members will be able to expense development opportunities against this allowance
- **Annual leave:** PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
- **18 weeks paid Parental Leave:** Irrespective of parenting role
- **Personal Leave Allowance:** This includes sick & carer’s leave
- **Fully remote working environment:** While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
- **Top-spec hardware:** All team members will be provided with top-spec laptops for their role
- **Generative AI subsidy:** UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work
UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!
As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
**Please Note:** Not all roles can be performed from the United States. Please check your specific job listing to confirm its advertised location. If the role you are applying for is listed as based in the US, we are currently only able to support hiring in the following locations: CA, CO, FL, IL, LA, MA, MD, MO, OR, PA, TX, WA, and DC.
Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.