Sr Infrastructure Systems Engineer
Listed on 2026-06-05
-
IT/Tech
Systems Engineer, Cybersecurity
We are looking for an Infrastructure Systems Engineer to build and own the internal platform that powers the company: identity, endpoints, networks, and security that will make company-wide impact.
Our engineering organization is AI‑forward. Our engineers use AI as a force multiplier in their daily work, design systems assuming AI‑assisted development and operations, and value experimentation and rapid adaptation.
The OpportunityWe are seeking an engineer who can deliver end‑to‑end infrastructure solutions that serve people and internal systems.
What This Role Is- Identity (SSO, RBAC, lifecycle)
- Endpoints (Mac, Windows, Linux)
- Access (device trust, zero‑trust networking)
- Internal platform and automation
- IT Security & Compliance
- Own identity as a first‑class system (SSO, RBAC, lifecycle, device trust)
- Build a fully automated onboarding/offboarding pipeline
- Design and operate endpoint infrastructure across Mac, Windows, and Linux
- Eliminate manual IT work through automation, scripting, and tooling
- Spend the majority of time building systems and automation—not responding to tickets
- Architect secure network infrastructure across office, lab, and remote environments
- Design and implement modern access patterns (e.g., Wire Guard‑based networking, zero‑trust, device‑aware access)
- Own firewall and perimeter security (Palo Alto, Juniper, or equivalent)
- Enable secure, compliant access to cloud environments (AWS Gov Cloud, GCP Assured Workloads)
- Drive compliance (CMMC, ITAR) through systems —not paperwork
- Partner directly with engineering to remove friction and increase velocity
- High ownership and autonomy to define how these systems are built and operated
- 12+ years proven experience building and owning infrastructure systems
- Deep experience with identity systems (Azure AD / Entra or equivalent; SAML/OAuth/SCIM)
- Strong experience managing heterogeneous endpoint fleets (Mac, Windows, Linux; MDM such as Intune/Jamf/Kandji)
- Hands‑on experience with network security and modern connectivity patterns (VPNs, Wire Guard, zero‑trust networking)
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience integrating systems via APIs and event‑driven workflows
- Experience operating in regulated environments (CMMC, ITAR, FedRAMP‑like)
- You treat internal infrastructure like a product, not a helpdesk
- You automate everything that happens more than once
- You reduce complexity instead of adding it
- You think in terms of identity‑first and network‑minimized architectures
- You can debug across identity, network, endpoint, and cloud boundaries
- You have strong opinions about how systems should be built—and can back them up
- Experience in GCC High environments (Microsoft Entra )
- Familiarity with Amazon Web Services Gov Cloud or Google Cloud Platform Assured Workloads
- Experience with Wire Guard‑based networking or modern secure access platforms (e.g., Tailscale, Cloudflare Zero Trust)
- Experience supporting hardware, lab, or manufacturing environments
- Experience designing zero‑trust or device‑trust architectures
- New hires are fully provisioned in minutes, not days
- Access is automated, auditable, and least‑privileged by default
- Network access is identity‑driven and device‑aware, not perimeter‑based
- Endpoint fleet is secure, compliant, and requires minimal manual intervention
- Engineers can move fast without being blocked by infrastructure
- Compliance is continuously satisfied through system design
- Systems are more secure, audits become trivial, and the company scales without friction
The pay range for this role is: $,000 per year.
Salary and BenefitsWe offer competitive compensation, equity, health, vision, dental, and 401(k) benefits. We provide lunch and snacks and drinks.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
ITAR Requirements: This position requires compliance with U.S. Government space technology trade…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).