About this role
Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedIn, X, Instagram, and YouTube.
What you'll do:
Team leadership and ICT management
- Lead, develop and grow a small team of ICT professionals; own hiring, performance management, workload allocation, on-call rostering and capability development.
- Set the regional ICT strategy, roadmap and annual operating plan; own the regional ICT budget, forecasting and capital planning.
- Manage local vendors, managed service providers, carriers and licensing agreements, including commercial negotiation and service-level accountability.
- Establish and enforce regional standards for documentation, change management, incident response and service delivery, aligned to ITIL or an equivalent framework.
Network and infrastructure
- Own the end-to-end regional network: campus and access-layer switching, wireless, routing, SD-WAN and WAN services, firewalls, VPN, DNS, DHCP, and monitoring.
- Design and maintain segmented network enclaves that separate corporate, program and test environments in line with data-handling and need-to-know requirements.
- Own site-to-site connectivity with the US parent company and partner organisations, including the controls that govern what traverses those links.
- Deliver connectivity and compute for deployed, remote and flight-test locations, including transportable and low-bandwidth environments.
- Manage server, storage, virtualisation and colocation infrastructure supporting regional engineering and program workloads.
Cloud and platform operations
- Own regional cloud architecture and operations across AWS and/or Azure, including landing-zone design, tenancy and subscription structure, identity federation and network integration.
- Ensure workloads and data reside in appropriate sovereign regions, and that data residency, jurisdiction and access constraints are enforced by design rather than by policy alone.
- Drive infrastructure-as-code, automation and configuration management; use scripting and agentic AI tooling to reduce manual operational load.
- Own cloud cost governance, capacity planning, backup, resilience and disaster recovery for the region.
Export control, data classification and sovereignty
- Act as the regional ICT authority for export-control compliance, working with Trade Compliance and Legal to implement ITAR, EAR and Australian Defence Trade Controls Act obligations in the technical environment.
- Design and operate access controls that reliably segregate data by nationality, program, clearance and need-to-know — including AUS-only, US-only and AUS/US-EYES-ONLY handling.
- Translate Technical Assistance Agreements, licences and program security instructions into enforceable IT controls, and evidence that enforcement to auditors and customers.
- Manage the interface with the US parent company on global tooling, tenancy and security policy; negotiate regional variations where sovereignty or export control requires them, and articulate the rationale clearly to both sides.
- Support onboarding of foreign nationals, visitors and seconded personnel with correct system access, monitoring and offboarding.
Security and compliance
- Maintain regional alignment to the ASD Essential Eight and the Information Security Manual, and support Defence Industry Security Program (DISP) membership obligations.
- Own identity and access management, privileged access, endpoint security, logging, and patch and vulnerability management for the region.
- Partner with global security and the regional security officer on incident response, insider-risk controls, audits, assessments and certification activity.
- Support the accreditation and ongoing assurance of program-specific and classified environments.
- Service delivery and program support
- Deliver reliable day-to-day IT services across Windows, macOS and Linux endpoints, identity, collaboration tooling and asset management.
- Provide high-touch support to regional executives, visiting leaders, customers and board members.
- Provide ICT input into new site establishment, facility fit-out, program bids and customer engagements, including cost and schedule estimates.
- Manage the regional IT asset lifecycle from procurement and deployment through inventory, licensing, refresh and secure decommissioning or destruction.
Required qualifications:
- Australian citizenship, and an NV1 security clearance held or the demonstrated ability to obtain and maintain one.
- 10+ years in enterprise ICT across infrastructure, network and systems administration, with progressive increases in scope and accountability.
- 3+ years directly leading technical teams, including hiring, performance management and development of engineers.
- Demonstrated ownership of enterprise networking: routing and switching, SD-WAN or WAN services, firewalls, VLANs and segmentation, wireless, VPN, DNS, DHCP and network monitoring.
- Hands-on cloud engineering and operations experience in AWS and/or Azure, including identity federation, network integration, IaC and cost management.
- Strong administration across Windows, macOS and Linux, with Active Directory, Microsoft Entra ID, group policy, IAM, Intune and Jamf.
- Practical experience working inside a multinational structure — ideally as the in-country lead reconciling a foreign parent company’s global standards with local regulatory obligations.
- Working knowledge of export control and data-classification regimes, and the ability to translate them into technical controls: ITAR, EAR, the Defence Trade Controls Act 2012, and Australian Government classification and handling requirements.
- Experience operating in classified, need-to-know or otherwise access-restricted environments.
- Scripting and automation capability (PowerShell, Bash or Python) and a strong bias toward automating operational work.
- Excellent written and verbal communication, with the credibility to brief executives, customers and certifiers, and the clarity to explain constraints to non-technical stakeholders.
- Willingness to travel domestically and regionally, participate in an on-call rotation and support scheduled after-hours maintenance.
Salary compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, licenses and certifications, and specific work location. All offers are contingent on a cleared background and possible reference check.
Shield AI is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or Veteran status. If you have a disability or special need that requires accommodation, please let us know.