Infrastructure Systems EngineerAstra's mission is to improve life on Earth from space by creating a healthier and more connected planet. Today, Astra offers one of the lowest cost-per-launch dedicated orbital launch services, and one of the industry's leading flight-proven electric propulsion systems for satellites, the Astra Spacecraft Engine.The OpportunityWe are looking for an Infrastructure Systems Engineer to build and own the internal platform that powers the company: identity, endpoints, networks, and security that will make company-wide impact.AI-Forward Engineering CultureWe are an AI-forward engineering organization. Are you ready to use AI tools to write code, architect systems, and solve complex problems in your daily work?
Our engineers:Use AI as a force multiplier in their daily workDesign systems assuming AI-assisted development and operationsValue engineers who experiment, adapt quickly, and adopt better toolsWhat This Role IsThis role focuses on infrastructure for people and internal systems:Identity (SSO, RBAC, lifecycle)Endpoints (Mac, Windows, Linux)Access (device trust, zero-trust networking)Internal platform and automationIT Security & ComplianceHow You'll Fulfill Your MissionOwn identity as a first-class system (SSO, RBAC, lifecycle, device trust)Build a fully automated onboarding/offboarding pipelineDesign and operate endpoint infrastructure across Mac, Windows, and LinuxEliminate manual IT work through automation, scripting, and toolingArchitect secure network infrastructure across office, lab, and remote environmentsDesign and implement modern access patterns (e.g., WireGuard-based networking, zero-trust, device-aware access)Own firewall and perimeter security (Palo Alto, Juniper, or equivalent)Enable secure, compliant access to cloud environments (AWS GovCloud, GCP Assured Workloads)Drive compliance (CMMC, ITAR) through systems —not paperworkPartner directly with engineering to remove friction and increase velocityYou will have high ownership and autonomy to define how these systems are built and operatedWhat We Value in You12+ yrs proven experience building and owning infrastructure systemsDeep experience with identity systems (Azure AD / Entra or equivalent; SAML/OAuth/SCIM)Strong experience managing heterogeneous endpoint fleets (Mac, Windows, Linux; MDM such as Intune/Jamf/Kandji)Hands-on experience with network security and modern connectivity patterns (VPNs, WireGuard, zero-trust networking)Strong scripting and automation skills (Python, Bash, or similar)Experience integrating systems via APIs and event-driven workflowsExperience operating in regulated environments (CMMC, ITAR, FedRAMP-like)What Sets You ApartYou treat internal infrastructure like a product, not a helpdeskYou automate everything that happens more than onceYou reduce complexity instead of adding itYou think in terms of identity-first and network-minimized architecturesYou can debug across identity, network, endpoint, and cloud boundariesYou have strong opinions about how systems should be built—and can back them upDesired MultipliersExperience in GCC High environments (Microsoft Entra ID)Familiarity with Amazon Web Services GovCloud or Google Cloud Platform Assured WorkloadsExperience with WireGuard-based networking or modern secure access platforms (e.g., Tailscale, Cloudflare Zero Trust)Experience supporting hardware, lab, or manufacturing environmentsExperience designing zero-trust or device-trust architecturesWhat Success Looks LikeNew hires are fully provisioned in minutes, not daysAccess is automated, auditable, and least-privileged by defaultNetwork access is identity-driven and device-aware, not perimeter-basedEndpoint fleet is secure, compliant, and requires minimal manual interventionEngineers can move fast without being blocked by infrastructureCompliance is continuously satisfied through system designSystems are more secure, audits become trivial, and the company scales without frictionThe pay range for this role is: $ 179,140-240,000 per yearWe're competitive in compensation and offer equity as part of the package. We have great benefits that include health, vision, dental, and 401K in comparison to other startups. We provide lunch and there's plenty of snacks and drinks to get you through the day.We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.
Please contact us to request accommodation.© Astra Space Operations, LLC. All rights reserved, Astra is proud to be an equal opportunity workplace. We celebrate diversity and are committed to creating an inclusive environment for all employees.
We do not discriminate on the basis of race, religion, color, gender identity, sexual orientation, age, disability, veteran status, or other applicable legally protected characteristics. We encourage people of different backgrounds, experiences, abilities, and perspectives to apply.San Francisco Applicants: Astra will consider applicants with arrest and conviction records (criminal histories) in a manner consistent with the San Francisco Fair Chance Ordinance.