About this role
About the Role Astra seeks an Infrastructure Systems Engineer to build and own the internal platform powering the company: identity, endpoints, networks, and security. This role focuses on enabling scalable, secure internal systems to accelerate company-wide impact. What You'll Do
- Own identity as a first-class system (SSO, RBAC, lifecycle, device trust)
- Build a fully automated onboarding/offboarding pipeline
- Design and operate endpoint infrastructure across Mac, Windows, and Linux
- Eliminate manual IT work through automation, scripting, and tooling
- Spend the majority of time building systems and automation—not responding to tickets
- Architect secure network infrastructure across office, lab, and remote environments
- Design and implement modern access patterns (WireGuard-based networking, zero-trust, device-aware access)
- Own firewall and perimeter security (Palo Alto, Juniper, or equivalent)
- Enable secure, compliant access to cloud environments (AWS GovCloud, GCP Assured Workloads)
- Drive compliance (CMMC, ITAR) through systems—not paperwork
- Partner directly with engineering to remove friction and increase velocity
- You will have high ownership and autonomy to define how these systems are built and operated What We're Looking For
- 12+ yrs proven experience building and owning infrastructure systems
- Deep experience with identity systems (Azure AD / Entra or equivalent; SAML/OAuth/SCIM)
- Strong experience managing heterogeneous endpoint fleets (Mac, Windows, Linux; MDM such as Intune/Jamf/Kandji)
- Hands-on experience with network security and modern connectivity patterns (VPNs, WireGuard, zero-trust networking)
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience integrating systems via APIs and event-driven workflows
- Experience operating in regulated environments (CMMC, ITAR, FedRAMP-like) Nice to Have
- Experience in GCC High environments (Microsoft Entra ID)
- Familiarity with Amazon Web Services GovCloud or Google Cloud Platform Assured Workloads
- Experience with WireGuard-based networking or modern secure access platforms (e.g., Tailscale, Cloudflare Zero Trust)
- Experience supporting hardware, lab, or manufacturing environments
- Experience designing zero-trust or device-trust architectures Compensation & Benefits
- Salary: $179,140 - $240,000 per year
- Equity as part of the package
- Health, vision, dental, and 401K benefits
- Lunch and snacks on site
- We provide reasonable accommodations for applicants with disabilities during the application or interview process
- ITAR Requirements: This role involves compliance with U.S. Government space technology trade restrictions; employment contingent on status as a documented U.S. Person or ability to receive a trade license, plus background checks and compliance with applicable laws