Senior Infrastructure Security Specialist protecting Kepler’s corporate, cloud, and operational infrastructure. Securing satellite-connectivity operations and Government of Canada environments through vulnerability management, SIEM, endpoint security, and incident response.
Responsibilities
Protect Kepler's corporate, cloud, and operational infrastructure.
Own, operate, and continuously improve vulnerability management, security monitoring and SIEM, endpoint security, infrastructure hardening, and incident response capabilities.
Provide security engineering expertise for infrastructure, cloud environments, networks, systems, and related technologies.
Review architectures, identify security risks, and recommend practical controls and mitigation measures.
Assess and improve controls across networks, servers, operating systems, cloud infrastructure, databases, firewalls, identity systems, and other infrastructure technologies.
Develop and maintain secure configuration and system-hardening standards based on CIS Benchmarks and NIST guidance.
Integrate security requirements into infrastructure design, implementation, and operational processes.
Own SIEM and monitoring capabilities, onboard log sources, develop and tune detection use cases, monitor visibility, and coordinate with MDR/SOC providers.
Own endpoint security and EDR/XDR capabilities; investigate alerts and support containment, remediation, and recovery.
Contribute to cybersecurity incident investigations, containment, remediation, recovery, evidence collection, and post-incident reviews.
Assess and secure AWS and/or Microsoft Azure environments, including IAM, logging, network security, and automation opportunities.
Support Government of Canada and regulated-environment security requirements, assessments, audits, inspections, certification activities, remediation, and control documentation.
Report to the VP, Information Security & CISO and collaborate with IT, Engineering, Operations, Security, Facilities, program teams, and external providers.
Requirements
7+ years of progressive experience in cybersecurity, with demonstrated hands-on experience in infrastructure security, security engineering, security operations, or a related technical security role.
Strong hands-on knowledge of infrastructure security across Windows, Linux, networking, cloud, and enterprise IT environments.
Demonstrated experience operating or supporting enterprise vulnerability management platforms, including vulnerability scanning, analysis, prioritization, and remediation.
Experience with SIEM and security monitoring technologies, including log analysis, security investigations, detection use cases, and monitoring.
Experience with endpoint security and EDR/XDR technologies, including alert investigation, containment, and security policy management.
Strong understanding of network security concepts including firewalls, network segmentation, intrusion detection/prevention, secure protocols, and network monitoring.
Experience supporting cybersecurity incident investigations and remediation.
Experience securing cloud environments such as AWS and/or Microsoft Azure.
Knowledge of infrastructure and operating-system hardening and secure configuration practices.
Knowledge of NIST Cybersecurity Framework (CSF), NIST SP 800-171, NIST SP 800-53, and CIS Controls/Benchmarks.
Understanding of identity and access management, privileged access, authentication, authorization, and least-privilege principles.
Ability to analyze technical security risks and communicate findings and recommendations to technical and non-technical stakeholders.
Strong problem-solving skills with demonstrated ownership and accountability.
Strong organizational skills and ability to manage multiple priorities in a fast-paced environment.
Ability to work independently while collaborating effectively across Security, IT, Engineering, Operations, and other teams.
Ability to obtain and maintain a Government of Canada security clearance appropriate to the role.
Benefits
Competitive compensation with a robust equity plan to share in our success.
Comprehensive coverage for health, dental, and vision insurance—including dependents.
Unlimited vacation
Supportive parental leave policy
Company-wide holiday shutdown
Semi-annual company-wide parties
Frequent in-office team events
Relocation packages available for approved roles.
$1,500 annual professional development fund
Fully stocked Toronto office kitchen with snacks, drinks, games and top-notch kitchen appliances.
Town Halls, Celebration Calls, and Company-wide events
Senior Program Manager driving enterprise cybersecurity programs for NBCUniversal, a global media and entertainment company. Coordinating technical delivery, operational change, adoption, risk, and executive reporting.
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.
Senior Security Specialist securing RBC’s cloud banking environments across AWS, Azure, and Google Cloud. Executing red/purple team exercises and refining offensive security tooling.
Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.
Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI - powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.