Jobs and Careers
AG

Senior System Administrator (m/f/d)

Agile Robots SE
Germanyfull_timeVerifiedPosted 3 Sept 2025

About the role

<h3>About the role</h3> <span>Agile Robots SE is seeking a Senior System Administrator to operate and evolve our global on-premise compute, operating systems, storage, backups, and identity services. You will engineer and run the foundational server platform—hardened, patch-compliant, recoverable, and ready for our applications and data platforms—across multiple regions and data centers.</span> <h3>Your Responsibilities</h3> <ol><li><strong>Compute &amp; OS Lifecycle</strong><br/>• Operate and optimize hypervisors and clusters (VMware/KVM/Proxmox), including HA, DRS/placement, and firmware/BIOS lifecycle<br/>• Provision and maintain Linux and Windows servers with clear baselines, SLAs, and change control<br/>• Enforce patching windows and automate OS updates with maintenance/rollback plans</li><li><strong>Provisioning, Imaging &amp; Configuration Management</strong><br/>• Deliver repeatable provisioning: PXE/iPXE workflows, golden images with Packer, and unattended installs<br/>• Implement configuration management at scale (Ansible/Salt; WSUS/Chocolatey; Red Hat Satellite) with drift detection and remediation<br/>• Maintain hardened images aligned to CIS/STIG; document MOP/SOP and rollback for all changes</li><li><strong>Storage, Backup &amp; Disaster Recovery</strong><br/>• Operate block/file/object storage (SAN/NAS/Ceph/ZFS): performance tuning, quotas, snapshots/replication<br/>• Ensure backup coverage and restorability with Veeam (policies, immutability where applicable, app-aware backups)<br/>• Conduct scheduled restore tests; document and meet RPO/RTO; participate in DR exercises</li><li><strong>Directory, Identity &amp; Access (optional specialization)</strong><br/>• Administer AD/LDAP/FreeIPA and federation/SSO (Keycloak/MFA), service accounts, and RBAC guardrails<br/>• Automate join/leave/move flows (SCIM/connectors), GPO/Policy hygiene, and privileged access controls<br/>• Integrate identity with platforms (e.g., Linux/Windows domain join, sudo/rights delegation)</li><li><strong>Server Security Hygiene &amp; Logging</strong><br/>• Apply CIS baselines and remediate OS/middleware vulnerabilities within agreed SLAs<br/>• Manage certificate/PKI lifecycle (issuance, rotation, ACME automation, expiry alerting)<br/>• Operate log shipping (rsyslog/agents) to ELK/OpenSearch; ensure audit coverage for privileged actions</li><li><strong>Reliability, Observability &amp; Lifecycle Management</strong><br/>• Build availability patterns (dual-homing, LACP/MLAG where applicable, fast recovery) for critical services<br/>• Implement monitoring/alerting (e.g., Zabbix), telemetry/SNMP, and capacity trending<br/>• Keep the CMDB accurate (CIs, owners, relationships), track EOL/EOS, and produce capacity/cost reports<br/>• Use Git-based workflows to version playbooks/configs and deliver safe, repeatable changes</li></ol> <h3>Essential Skills</h3> <ul><li><span>7+ years administering enterprise Linux/Windows in multi-site environments, including change and incident workflows</span></li><li><span>Hands-on with at least two hypervisor stacks (e.g., VMware + Proxmox/KVM) and cluster operations (HA, live migration, storage moves)</span></li><li><span>Strong in provisioning and config at scale: PXE/iPXE, Packer, Ansible/Salt; WSUS/Chocolatey or Satellite<br/>Storage fundamentals (iSCSI/FC/NFS/SMB) with practical Ceph or ZFS experience (pool design, snapshots, replication)</span></li><li><span>Veeam at scale: policies, proxies/repos, application-aware backups, restore testing, and RPO/RTO discipline</span></li><li><span>Directory/IAM administration: AD (GPO, DNS, Sites &amp; Services) plus FreeIPA/Keycloak and SSO/MFA patterns</span></li><li><span>Security hygiene and logging: CIS alignment, vuln remediation, certificate lifecycle, rsyslog → ELK/OpenSearch</span></li><li><span>Scripting/automation (Bash/PowerShell; Python a plus) and Git-based change workflows</span></li></ul> <h3>Beneficial Skills</h3> <ul><li>ZFS send/receive; Ceph RBD/RGW tuning; storage performance troubleshooting</li><li>Immutable/air-gapped backups; off-site replication; DR orchestration</li><li>Exposure to Kubernetes underlay needs (storage classes/CSI, backup hooks like Velero/restic)</li><li>TISAX/ISO 27001 evidence handling (policies ↔ designs ↔ logs ↔ change records)</li><li>Experience with CMDB tooling (e.g., NetBox/ServiceNow/JIRA CMDB) and asset discovery</li><li>Familiarity with syslog retention strategies, Zabbix tuning, and ITSM/change tooling</li></ul> <h3>What we offer</h3> <ul><li>A dynamic high-tech company combined with financial soundness and world-class investors</li><li>Join an interdisciplinary, international team with 58+ different nationalities in a collaborative work environment</li><li>Lots of development opportunities in the context of our continued growth</li><li>Challenging tasks and impactful projects alongside experts that enable professional and personal growth</li><li>Corporate Benefits Program that covers health, mobility, a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Agile Robots SE

View company profile →