Staff Systems Administrator (R5995)
Shield AI · London
- Senior
- Internship
- Posted 2026-09-24
- Confirmed live on 25 September 2026
Job description
Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedIn, X, Instagram, and YouTube.
What you'll do:
Infrastructure Ownership (On-Prem & Cloud)
• Own and operate on-premises and cloud infrastructure, including physical and virtual servers, storage, backup platforms, identity services, core network services, and enterprise applications.
• Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness.
• Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements.
• Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information.
• Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices.
Firewalled Entity and Segmented-Environment Support
• Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required.
• Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity.
• Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries.
• Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence.
• Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure.
• Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance.
Security, Compliance, and Systems
• Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance.
• Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting.
• Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations.
• Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews.
• Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability.
• Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans.
• Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events.
• Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans.
Identity, Endpoint, and Service Delivery
• Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement.
• Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement.
• Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation.
• Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity.
• Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal.
• Use scripting and automation to
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Shield AI
- Engineer I, Quality (R5976) · Seattle, Washington
- Director, International Growth Campaign Leader (R5851) · Washington, D.C.
- Engineer I, PCB (R6065) · Seattle, Washington
- Capture Portfolio Analyst, X-BAT Family of Systems (FoS) (R6011) · San Diego, California
- Capture Strategy & Operations Sr. Lead, X-BAT Family of Systems (FoS) (R6083) · San Diego, California
- Director of Field Marketing - Asia Pacific / Middle East · Singapore
- Capture Strategy & Operations Sr. Lead, X-BAT Family of Systems (FoS) (R6012) · San Diego, California
- Engineer II, Modelling and Simulation (R5712) · Melbourne