Security & Infrastructure Engineer

Posted 3 Days Ago
Be an Early Applicant
Hiring Remotely in Toronto, ON, CAN
In-Office or Remote
Mid level
Artificial Intelligence • Software • Industrial • Automation
The Role
Own SOC 2 Type 2 and ISO 27001 compliance programs while securing AWS, GCP, SaaS, infrastructure, identity, CI/CD, and software supply chains. Triage and remediate security findings, administer access and endpoints, support IT operations, manage auditors and customer reviews, debug cloud production issues, and build automated security guardrails, documentation, and postmortems.
Summary Generated by Built In

Nexxa is building the best AI systems for heavy industries — enabling machines, systems, and operations to think, decide, and act autonomously across manufacturing, large-scale infrastructure, logistics, and legacy environments.

Our mission is to translate deep technical breakthroughs into operational reality, solving some of the hardest systems-level problems in industry.

About the Role

Selling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not a function beside it.

We hold SOC 2 Type 2 and ISO 27001, and we're moving toward more certifications because governing autonomous industrial systems responsibly is a commercial requirement in our market. You'll own our certification programs and the security and infrastructure underneath them — across our multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments, not customer plant-floor or control-system security.

This role is ideal for candidates who want real, ongoing ownership of a security function, including standing up and running one of the industry's first AI management systems, at a company where trust and compliance directly determine whether customers deploy the platform at all.

What You'll Do
  • Own the compliance calendar across SOC 2 Type 2 and ISO 27001 — evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readiness

  • Triage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closure

  • Remediate what you triage directly in infrastructure as code, IAM policy, and pipeline configuration

  • Administer identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycle

  • Support internal IT operations — endpoint fleet and device compliance, SaaS and license administration, asset inventory, support requests — while keeping the human cost of them flat as the company grows

  • Serve as the working interface to external auditors, our certification body, and customer security and procurement reviews

  • Build controls into infrastructure so they hold automatically, replacing manual verification with guardrails that fail closed

  • Harden CI/CD and the software supply chain — build identity, artifact provenance, dependency and secret hygiene

  • Debug production issues across cloud infrastructure, containers, and networking, and write the postmortem that keeps the fix from being forgotten

  • Produce documentation others rely on: runbooks, control narratives, architecture notes, postmortems

Required Qualifications
  • Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical role — broad competence across security, networking, and operating systems, with real depth in at least one

  • Deep hands-on experience with:

    • Security fundamentals — trust boundaries and blast radius, authentication vs. authorization, least privilege, secrets handling, and judging real-world exploitability of findings

    • Networking — diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, and proxies; comfortable with VPN/private connectivity and packet captures

    • Linux operating systems — processes, filesystems, permissions, systemd, resource limits, log analysis, and how containers relate to the host

    • Cloud infrastructure — hands-on with AWS or GCP beyond the console: IAM, networking, compute, and their failure modes

  • Strong scripting/automation skills (Python, Bash, Go, or similar) — recurring manual work gets scripted away, not tracked by hand

  • Strong writing ability: control narratives, runbooks, postmortems, audit responses, risk assessments

  • Proven judgment under ambiguity — able to rank findings honestly and defend the ranking

  • CS/CE degree or equivalent hands-on experience

Preferred Qualifications
  • Hands-on ISO 27001 experience — operating an ISMS, recertification, surveillance audits, internal audit programmes, Statement of Applicability, risk treatment

  • SOC 2 experience in practice — producing evidence, answering auditor requests, remediating findings against a real deadline

  • Any exposure to AI governance or ISO 42001 — AI risk assessment, model inventory, AI lifecycle controls, the EU AI Act

  • Infrastructure as code at scale (Pulumi primarily, Terraform secondarily — deep Terraform experience transfers fine)

  • Multi-account cloud organization experience: landing zones, org-level policy guardrails, centralized logging, cross-account access patterns

  • Identity provider and endpoint management at scale (Google Workspace or Microsoft 365, SSO/SAML/OIDC, MDM and device compliance tooling)

  • Cloud security tooling experience (CSPM, SAST/SCA, vulnerability management platforms), including their false-positive rates

  • Container orchestration on ECS, EKS, or Kubernetes

  • Observability: metrics, logs, traces, and the judgment to instrument what will matter later

  • Experience across both AWS and GCP, including workload identity federation

  • Cloud cost awareness — you notice when spend and value diverge

  • Startup or high-growth experience building process rather than following one

What Success Looks Like
  • You can own ambiguous, high-stakes security and compliance problems end-to-end

  • Controls you build hold automatically as the company scales — you design for guardrails that fail closed, not recurring manual verification

  • You bring strong technical judgment on tradeoffs between security rigor, velocity, and cost

  • You raise the bar for security rigor and operational discipline across the team

  • You help define what's next for the security program, not just execute what's known

Why Join Nexxa.ai?
  • Innovative Environment: Play a critical role in transforming heavy industries through groundbreaking AI and automation technologies

  • Collaborative Culture: Be part of a team that values innovation, discipline, and continuous improvement

  • Professional Growth: Benefit from significant opportunities for career development and advancement

  • Competitive Compensation: Enjoy a comprehensive salary and equity package reflective of your expertise and contributions

If you're passionate about building the security and compliance backbone for advanced AI solutions in the real world, we'd love to connect.

Skills Required

  • Professional experience in security engineering, infrastructure or platform engineering, or a closely related technical role
  • Broad competence across security, networking, and operating systems, with substantial depth in at least one area
  • Hands-on knowledge of security fundamentals, including trust boundaries, blast radius, authentication, authorization, least privilege, secrets handling, and exploitability assessment
  • Hands-on networking experience with routing, firewalls or security groups, DNS, TLS termination, proxies, VPNs or private connectivity, and packet captures
  • Hands-on Linux experience with processes, filesystems, permissions, systemd, resource limits, log analysis, and container-host relationships
  • Hands-on AWS or GCP cloud infrastructure experience beyond console usage, including IAM, networking, compute, and failure modes
  • Strong scripting or automation skills in Python, Bash, Go, or a similar language
  • Strong technical writing skills for control narratives, runbooks, postmortems, audit responses, and risk assessments
  • Proven judgment under ambiguity and ability to prioritize and defend security findings
  • Computer science or computer engineering degree, or equivalent hands-on experience
  • Hands-on ISO 27001 experience, including ISMS operations, audits, Statement of Applicability, and risk treatment
  • Practical SOC 2 experience producing evidence, responding to auditors, and remediating findings
  • Exposure to AI governance or ISO 42001, including AI risk assessment, model inventory, lifecycle controls, or the EU AI Act
  • Infrastructure as code experience, particularly Pulumi or Terraform
  • Multi-account cloud organization experience with landing zones, policy guardrails, centralized logging, and cross-account access
  • Identity provider and endpoint management experience at scale, including Google Workspace or Microsoft 365, SSO, SAML, OIDC, MDM, and device compliance
  • Experience with cloud security tooling such as CSPM, SAST, SCA, and vulnerability management platforms
  • Container orchestration experience with ECS, EKS, or Kubernetes
  • Observability experience with metrics, logs, and traces
  • Experience across both AWS and GCP, including workload identity federation
  • Cloud cost awareness
  • Startup or high-growth company experience building operational processes
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Green Bay, WI
30 Employees
Year Founded: 2024

What We Do

Nexxa builds specialized AI for industrial engineering in heavy project industries. Project industries like railroads, energy, construction, mining and others rely on highly educated industrial engineers to function. Today, industrial engineers have to do their work in a fragmented, sometimes outdated technology stack. Nexxa delivers AI agents that understand the technical work and augment the engineer in their most critical, but repetitive work. Our vision is to build an AI system that works with the engineer from scratch and accelerates engineering productivity without any pre-training.

Similar Jobs

NVIDIA Logo NVIDIA

Senior Security Engineer

Artificial Intelligence • Computer Vision • Hardware • Robotics • Metaverse
Remote
Canada
21960 Employees
170K-275K Annually
Remote
Canada
146 Employees
218K-273K Annually

Samsara Logo Samsara

Customer Success Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Canada
4000 Employees
78K-101K Annually
Remote or Hybrid
11 Locations
2449 Employees
71K-127K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account