Sr Staff Infrastructure Systems Engineer Verified today
The Opportunity
Build and own the internal platform that powers the company: identity, endpoints, networks, and security that will make company-wide impact.
What This Role Is
This role focuses on infrastructure for people and internal systems:
- Identity (SSO, RBAC, lifecycle)
- Endpoints (Mac, Windows, Linux)
- Access (device trust, zero-trust networking)
- Internal platform and automation
- IT Security and Compliance
How You'll Fulfill Your Mission
- Own identity as a first-class system (SSO, RBAC, lifecycle, device trust)
- Build a fully automated onboarding and offboarding pipeline
- Design and operate endpoint infrastructure across Mac, Windows, and Linux
- Eliminate manual IT work through automation, scripting, and tooling. You will spend the majority of your time building systems and automation, not responding to tickets
- Architect secure network infrastructure across office, lab, and remote environments
- Design and implement modern access patterns (WireGuard-based networking, zero-trust, device-aware access)
- Own firewall and perimeter security (Palo Alto, Juniper, or equivalent)
- Enable secure, compliant access to cloud environments (AWS GovCloud, GCP Assured Workloads)
- Drive compliance (CMMC, ITAR) through systems, not paperwork
- Partner directly with engineering to remove friction and increase velocity
- You will have high ownership and autonomy to define how these systems are built and operated
What We Value in You
- 12+ years proven experience building and owning infrastructure systems
- Deep experience with identity systems (Azure AD, Entra, or equivalent; SAML, OAuth, SCIM)
- Strong experience managing heterogeneous endpoint fleets (Mac, Windows, Linux; MDM such as Intune, Jamf, Kandji)
- Hands-on experience with network security and modern connectivity patterns (VPNs, WireGuard, zero-trust networking)
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience integrating systems via APIs and event-driven workflows
- Experience operating in regulated environments (CMMC, ITAR, FedRAMP-like)
What Sets You Apart
- You treat internal infrastructure like a product, not a helpdesk
- You automate everything that happens more than once
- You reduce complexity instead of adding it
- You think in terms of identity-first and network-minimized architectures
- You can debug across identity, network, endpoint, and cloud boundaries
- You have strong opinions about how systems should be built and can back them up
