Staff Systems Administrator (R5995)

Shield AI · London

  • Senior
  • Internship
  • Posted 2026-09-24
  • Confirmed live on 25 September 2026

Apply at Shield AI

Job description

Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedIn, X, Instagram, and YouTube. 

What you'll do:
Infrastructure Ownership (On-Prem & Cloud)

• Own and operate on-premises and cloud infrastructure, including physical and virtual servers, storage, backup platforms, identity services, core network services, and enterprise applications.

• Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness.

• Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements.

• Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information.

• Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices.

Firewalled Entity and Segmented-Environment Support

• Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required.

• Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity.

• Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries.

• Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence.

• Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure.

• Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance.

Security, Compliance, and Systems

• Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance.

• Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting.

• Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations.

• Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews.

• Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability.

• Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans.

• Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events.

• Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans.

Identity, Endpoint, and Service Delivery

• Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement.

• Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement.

• Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation.

• Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity.

• Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal.

• Use scripting and automation to

Prepare for the interview

Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.

More at Shield AI

All open software jobs