About the role
WHO ARE WE?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
Where does this role fit in?
Build, operate, and strategically evolve the technology platform that enables every UpGuardian to work securely, efficiently, and with minimal friction.
You'll own the hands-on administration and optimization of our core IT stack: identity systems, endpoint engineering, and SaaS platforms. Your main focus will be automating repetitive operational tasks, establishing system performance and compliance metrics, and maintaining a secure-by-default infrastructure.
This is a platform engineering and ownership role above all else, with the added responsibility of serving as the senior escalation point for complex day-to-day issues. We don't want you stuck in a queue, so if you see the same manual task three times and immediately design an automated, self-service fix to permanently remove it, you’ll fit right in.
Security is an outcome of excellent operational engineering here, not the primary function of the role.
What will you do?
Platform, Identity & Fleet Operations
- Drive end-to-end shared platform ownership across Google Workspace, Okta, and enterprise MDM (Kandji/Jamf) for our macOS and ChromeOS fleet. You’ll architect robust SSO/SAML integrations, optimize SCIM provisioning, design scalable role hierarchies, and establish proactive OS lifecycle and patching strategies that keep our systems secure by default.
- Optimise our global joiner-mover-leaver process. Find the steps that still need a human, automate them, and tighten the handoffs with the People Team. Keep asset records and endpoint compliance reporting accurate, and administer the SaaS estate against the governance model.
Zero Trust & Secure Access
- Take operational ownership of our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, secure tunnels, and identity and device-aware access policies. Tune policies, and troubleshoot the edge access problems that get escalated past everyone else.
- Own the migration of remaining internal applications off legacy network access as a workstream, and flag where a control is creating friction that isn't buying us anything.
Automation & Internal Tooling
- Build production-grade tooling using REST APIs, Python, Apps Script, and n8n that permanently removes manual work.
- Propose what should be automated next, based on what you're seeing in the queue.
Service Operations
- Take incident command for platform incidents on rota. Coordinate the response, keep people informed, drive to resolution, then write the postmortem and see the actions through to closure.
- Raise and execute changes through our change process, including risk assessment and rollback. Investigate recurring incidents to root cause and own the resulting problem records.
- Keep the runbooks, knowledge base, and service catalogue entries accurate for the systems you run. Where you find a gap in the practice, propose the fix and pilot it on your own systems.
Reliability & Self-Service
- Own zero-touch provisioning, endpoint compliance enforcement, and fleet health monitoring.
- Build the self-service options and self-healing behaviour that make routine requests stop reaching the team.
Embedded Security Engineering
- Implement and maintain endpoint hardening and baseline configurations, and keep them current. Act as technical responder on security incidents and support the evidence side of audit and compliance work.
- Design security into platform changes as you make them rather than adding it afterwards. Where you find operational risk, surface it with a recommendation attached.
Raising the Level Around You
- Mentor your colleagues on the platforms and tools you know best. Where you fix something, leave documentation behind so the next person doesn't need you.
What will you bring?
You won't have all of this. Tell us which parts you'd be learning, and we'll tell you honestly whether that works.
- SaaS & Identity Depth: Several years administering Google Workspace or Microsoft 365 alongside an enterprise IdP (Okta, Entra) and MDM at organisational scale. SSO, SAML, SCIM, DNS, and certificates as things you've configured and debugged.
- Hands-on Zero Trust Experience: Direct experience configuring and optimising ZTNA, Secure Web Gateways, or modern edge access controls (Cloudflare Zero Trust, Zscaler, Netskope, Tailscale, Entra Private Access). Enough to take operational ownership of a Cloudflare estate and troubleshoot complex edge access issues.
- Automation Capability: Production-grade scripts or code (Python, Apps Script, Terraform) integrated against REST APIs. Point us at internal tools or pipelines you've built that permanently eliminated operational work.
- Fleet Management at Scale: Managing macOS at scale, building zero-touch deployment workflows, and enforcing endpoint compliance baselines.
- Process Optimisation: You've taken a joiner-mover-leaver or similar cross-functional process and measurably reduced the manual steps in it, working with People or HR to do it.
- Operational Discipline: Experience running incidents, working within a change process, and authoring technical documentation that teams rely on.
- Security Fundamentals: Endpoint hardening, identity security, and network access controls, with the judgment to make proportionate risk recommendations and know which calls aren't yours.
- Systems Improvement Instinct: A track record of eliminating classes of problem rather than resolving individual tickets.
- Independent Judgment: Enough to keep things running for a couple of weeks without your manager, and enough to know which decisions should wait for them.
What's in it for you?
- Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being
- WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
- $1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance
- Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
- 18 weeks paid Parental Leave: Irrespective of parenting role
- Personal Leave Allowance: This includes sick & carer’s leave
- Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
- Top-spec hardware: All team members will be provided with top-spec laptops for their role
- Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work
UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!
As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
Please Note: Not all roles can be performed from the United States. Please check your specific job listing to confirm its advertised location. If the role you are applying for is listed as based in the US, we are currently only able to support hiring in the following locations: CA, CO, FL, IL, LA, MA, MD, MO, OR, PA, TX, WA, and DC.
Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.