Remote
Senior Systems Engineer
About this role
Who are we? At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk. We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale. Where does this role fit in? Build, operate, and strategically evolve the technology platform that enables every UpGuardian to work securely, efficiently, and with minimal friction. You'll own the hands-on administration and optimization of our core IT stack: identity systems, endpoint engineering, and SaaS platforms.
Your main focus will be automating repetitive operational tasks, establishing system performance and compliance metrics, and maintaining a secure-by-default infrastructure. This is a platform engineering and ownership role above all else, with the added responsibility of serving as the senior escalation point for complex day-to-day issues. We don't want you stuck in a queue, so if you see the same manual task three times and immediately design an automated, self-service fix to permanently remove it, you’ll fit right in.
Security is an outcome of excellent operational engineering here, not the primary function of the role. What will you do? Platform, Identity & Fleet Operations Drive end-to-end shared platform ownership across Google Workspace, Okta, and enterprise MDM (Kandji/Jamf) for our macOS and ChromeOS fleet. You’ll architect robust SSO/SAML integrations, optimize SCIM provisioning, design scalable role hierarchies, and establish proactive OS lifecycle and patching strategies that keep our systems secure by default.
Optimise our global joiner-mover-leaver process. Find the steps that still need a human, automate them, and tighten the handoffs with the People Team. Keep asset records and endpoint compliance reporting accurate, and administer the SaaS estate against the governance model. Zero Trust & Secure Access Take operational ownership of our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, secure tunnels, and identity and device-aware access policies.