Security & Infrastructure Engineer

Posted 20hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security and Infrastructure Engineer securing Nexxa’s AI systems for heavy industries. Owning cloud infrastructure, security operations, and SOC 2/ISO 27001 compliance.

Responsibilities:

  • Own the compliance calendar across SOC 2 Type 2 and ISO 27001, including evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readiness
  • Triage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closure
  • Remediate findings directly in infrastructure as code, IAM policy, and pipeline configuration
  • Administer identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycle
  • Support internal IT operations, including endpoint fleet and device compliance, SaaS and license administration, asset inventory, and support requests
  • Serve as the working interface to external auditors, the certification body, and customer security and procurement reviews
  • Build controls into infrastructure using automatically enforced guardrails that fail closed
  • Harden CI/CD and the software supply chain, including build identity, artifact provenance, dependency hygiene, and secret hygiene
  • Debug production issues across cloud infrastructure, containers, and networking
  • Write postmortems and produce runbooks, control narratives, architecture notes, and other operational documentation

Requirements:

  • Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical role
  • Broad competence across security, networking, and operating systems, with real depth in at least one
  • Deep hands-on experience with security fundamentals, including trust boundaries, blast radius, authentication, authorization, least privilege, secrets handling, and exploitability assessment
  • Networking experience with routing, firewalls/security groups, DNS, TLS termination, proxies, VPN/private connectivity, and packet captures
  • Linux operating systems experience with processes, filesystems, permissions, systemd, resource limits, log analysis, and container-host relationships
  • Hands-on AWS or GCP cloud infrastructure experience beyond the console, including IAM, networking, compute, and failure modes
  • Strong scripting/automation skills in Python, Bash, Go, or similar
  • Strong writing ability for control narratives, runbooks, postmortems, audit responses, and risk assessments
  • Proven judgment under ambiguity
  • CS/CE degree or equivalent hands-on experience
  • Hands-on ISO 27001 experience preferred
  • SOC 2 experience preferred
  • Exposure to AI governance or ISO 42001 preferred
  • Infrastructure as code experience, especially Pulumi or Terraform, preferred
  • Multi-account cloud organization experience preferred
  • Identity provider and endpoint management experience at scale preferred
  • Cloud security tooling experience preferred
  • Container orchestration experience with ECS, EKS, or Kubernetes preferred
  • Observability experience with metrics, logs, and traces preferred
  • Experience across both AWS and GCP, including workload identity federation, preferred
  • Cloud cost awareness preferred
  • Startup or high-growth experience preferred

Benefits:

  • Equity package
  • Competitive compensation
  • Career development and advancement opportunities
  • Remote work arrangement
  • Collaborative culture
  • Innovative environment
  • Continuous improvement opportunities