About this role.
UpGuard is seeking an IT Operations Analyst to own and improve its internal corporate technology platform across identity, endpoints, SaaS administration, device management, and service operations. The role emphasizes automation-first operational engineering using Python, REST APIs, Apps Script, Terraform, n8n, and AI-assisted workflows. Core responsibilities include administering Google Workspace, an identity provider, MDM, and Cloudflare Zero Trust while maintaining secure, low-friction employee access. The analyst will establish and improve incident, change, asset, knowledge-management, monitoring, compliance, and self-service practices. This is a hands-on infrastructure operations position with security embedded in the platform rather than serving as the primary security function.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I first mapped the request volume, decision points, and exceptions, then used APIs and scripted workflows to automate the repeatable path. I added logging, error handling, documentation, and ownership boundaries, then measured reduced turnaround time and ticket volume after rollout.
I would review application inventory, identity groups, device posture signals, access logs, and user-reported failures. I would apply least-privilege, identity- and device-aware policies incrementally, test with representative user groups, and monitor both security events and access success rates before expanding changes.
I would make the HR system or approved identity source authoritative, automate account provisioning and deprovisioning through SCIM where possible, and use role-based access groups. I would include asset assignment, manager approvals for exceptions, audit trails, and periodic access reviews to ensure changes are timely and compliant.
I use zero-touch enrollment, standardized configuration profiles, automated application deployment, FileVault and OS-update enforcement, and continuous compliance reporting. I also define exception processes, validate changes with pilot rings, and maintain clear remediation guidance for employees and support teams.
I would begin with metrics tied to employee experience and operational risk, such as request fulfillment time, incident volume and recurrence, change failure rate, endpoint compliance, provisioning time, and knowledge-base deflection. I would review trends regularly, pair metrics with root-cause analysis, and use findings to prioritize automation and platform improvements.
Who are we?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
Where does this role fit in?
Build, operate and continually improve the technology platform that lets every UpGuardian work securely, efficiently and with minimal friction.
You’ll own the lifecycle of our corporate technology end to end: identity, endpoints, SaaS and the service practices that hold them together. You’ll automate the repetitive parts, instrument the rest, and make security a property of how systems are built rather than a task someone remembers to do.
This is an engineering role, not a ticket queue. If you see the same request three times and your first thought is “why is a human still doing this?” – you’ll fit.
Security is an outcome of excellent operational engineering here, not the primary function of the role.
What will you do?
Platform, identity and fleet
Google Workspace, Okta (or equivalent IdP), and MDM (Kandji, Jamf or similar) across a mostly macOS and ChromeOS fleet
You’ll own SaaS administration and lifecycle, asset management, endpoint standards and compliance, and the joiner–mover–leaver process end to end
Zero Trust and secure access
Operate and continually improve our Cloudflare Zero Trust environment across ZTNA, Secure Web Gateway, DNS filtering, tunnels and identity and device aware access policies
You’ll help move us away from traditional network trust, maintain secure access to internal applications and services, troubleshoot access and connectivity issues, and make sure security controls don’t create unnecessary friction for employees
Automation and internal tooling
Automation is the default approach, not a stretch goal. If a task happens more than twice, it’s a candidate for code
You’ll work with REST APIs, Python, Apps Script, Terraform, n8n and AI assisted workflows to build internal tooling that removes work rather than making it faster to do by hand
Service operations
Incident, problem and change management. Service catalogue, knowledge base, service metrics, capacity planning and operational readiness
You’ll define these practices where they don’t exist yet and improve the ones that do
Reliability and continuous improvement
Zero touch provisioning, endpoint compliance, fleet health, monitoring, reporting, SaaS governance and self service. Making internal platforms boringly reliable is the goal
Security, embedded
Deploy and maintain security controls, harden endpoints, support security incidents, reduce operational risk and keep baselines current
Security is part of how you’ll operate the platform rather than a separate function you’ll own
What will you bring?
You won’t have all of this. Tell us which parts you’d be learning, and we’ll tell you honestly whether that works
Depth across enterprise SaaS and identity – you’ve administered Google Workspace or Microsoft 365, an IdP such as Okta or Entra, and MDM at organisational scale. You’re comfortable with SSO, SAML, SCIM, DNS and certificates
Zero Trust, hands on – you’ve worked with ZTNA, Secure Web Gateway or modern network access controls, ideally Cloudflare Zero Trust or a similar platform such as Zscaler, Netskope, Tailscale or Entra Private Access. You understand identity and device aware access and the principles behind replacing traditional network trust
You don’t need to be a Zero Trust specialist, but you should be comfortable taking ownership of an existing Cloudflare implementation, troubleshooting it and making it better
You genuinely automate – you write code using Python, Apps Script or similar, work confidently with REST APIs, and can point to internal tooling you’ve shipped that removed recurring work permanently
Fleet management maturity – you’ve worked with macOS at scale, zero touch provisioning and endpoint compliance baselines
Service operations experience – you’ve run incident and change practices, defined metrics and built documentation people actually use
Security and infrastructure fundamentals – you’re comfortable with endpoint hardening, identity security, DNS, certificates, secure network access and making sensible risk trade offs
Process improvement instinct – you make the system better, not just the outcome of one request
What will give you an edge?
Terraform or other Infrastructure as Code
Cloudflare
n8n or similar orchestration
AI and LLM-assisted workflows
Deep macOS expertise
Chrome Enterprise
Working in a security-first or audited environment (SOC 2, ISO 27001)
What’s in it for you?
Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being
WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
$1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance
Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
18 weeks paid Parental Leave: Irrespective of parenting role
Personal Leave Allowance: This includes sick & carer’s leave
Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
Top-spec hardware: All team members will be provided with top-spec laptops for their role
Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work
Health Insurance: Access to comprehensive coverage.
UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!
As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
For applications to positions in the United States, please note, at this time, we can only support hiring in the following US states: CA, MD, MA, IL, OR, WA, CO, TX, FL, PA, LA, MO, or DC.
Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.





