← Все вакансии/Senior/jobgether
SeniorRemoteCanada

Security & Infrastructure Engineer

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security & Infrastructure Engineer based in Canada.

This is a high-impact opportunity to own the security, compliance, and infrastructure foundations behind AI systems deployed in heavy industry. You’ll lead ongoing SOC 2 Type 2 and ISO 27001 programs while strengthening cloud and internal engineering environments. The role combines hands-on security engineering with infrastructure, identity, networking, and IT operations. You’ll work across AWS, GCP, CI/CD, cloud security, and infrastructure-as-code to build controls that operate automatically at scale. You’ll also partner with auditors and customer security teams, making security a direct contributor to business growth. The environment is fast-moving and technically demanding, offering substantial ownership and the opportunity to shape an evolving security function.

Responsibilities
  • Own the security and compliance calendar across SOC 2 Type 2 and ISO 27001, including evidence collection, access and vendor reviews, control monitoring, internal audits, management reviews, policy updates, and audit readiness.
  • Triage security findings across cloud posture, code scanning, dependencies, and secrets, prioritizing remediation based on practical risk and driving issues through to closure.
  • Implement security remediation directly through infrastructure-as-code, IAM policies, CI/CD configuration, and other technical controls.
  • Administer identity and access across cloud and SaaS environments, including SSO and federation, least-privilege access, and joiner/mover/leaver processes.
  • Support internal IT operations covering endpoint management, device compliance, SaaS and license administration, asset inventory, and employee support while maintaining operational efficiency as the organization grows.
  • Act as the primary working interface for external auditors, certification bodies, and customer security and procurement reviews.
  • Build security controls and guardrails directly into infrastructure, reducing reliance on manual verification and ensuring systems fail securely by default.
  • Harden CI/CD pipelines and the software supply chain through stronger build identity, artifact provenance, dependency management, and secret hygiene.
  • Diagnose production issues involving cloud infrastructure, containers, and networking, and document root causes and preventative actions through detailed postmortems.
  • Create and maintain technical documentation, including runbooks, control narratives, architecture notes, risk assessments, audit responses, and postmortems.
  • Collaborate with engineering and other teams to improve security maturity, operational discipline, observability, reliability, and long-term scalability.
Requirements
  • Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical discipline, with broad knowledge across security, networking, and operating systems and demonstrated depth in at least one area.
  • Strong understanding of security fundamentals, including trust boundaries, blast radius, authentication and authorization, least privilege, secrets management, and practical assessment of security findings.
  • Hands-on networking expertise, including routing, firewalls and security groups, DNS, TLS termination, proxies, VPN/private connectivity, and packet capture analysis.
  • Strong Linux systems knowledge covering processes, filesystems, permissions, systemd, resource limits, log analysis, and container-to-host relationships.
  • Practical cloud infrastructure experience with AWS or GCP beyond console-based administration, including IAM, networking, compute, and troubleshooting cloud failure modes.
  • Strong scripting and automation capabilities using Python, Bash, Go, or similar technologies, with a mindset of automating recurring manual processes.
  • Excellent technical writing skills, with the ability to produce clear control narratives, runbooks, postmortems, audit responses, and risk assessments.
  • Strong judgment and prioritization skills, particularly when evaluating ambiguous or high-impact security issues and defending risk-based decisions.
  • Bachelor’s degree in Computer Science, Computer Engineering, or equivalent hands-on professional experience.
  • Experience with ISO 27001, including ISMS operations, recertification or surveillance audits, internal audit programs, Statements of Applicability, and risk treatment, is highly valued.
  • Practical SOC 2 experience, including evidence preparation, auditor communication, and remediation of findings against defined deadlines, is preferred.
  • Exposure to AI governance, ISO 42001, AI risk assessment, model inventories, AI lifecycle controls, or the EU AI Act is an advantage.
  • Experience with infrastructure-as-code, particularly Pulumi or Terraform, and familiarity with multi-account cloud organizations, landing zones, policy guardrails, centralized logging, and cross-account access.
  • Familiarity with identity providers and endpoint management platforms such as Google Workspace or Microsoft 365, including SSO, SAML, OIDC, MDM, and device compliance.
  • Experience with cloud security tooling such as CSPM, SAST/SCA, and vulnerability management platforms, including the ability to distinguish meaningful findings from false positives.
  • Knowledge of ECS, EKS, Kubernetes, observability practices, workload identity federation, or both AWS and GCP environments is an asset.
  • Startup or high-growth experience, particularly building scalable security and operational processes from the ground up, is strongly valued.
Conditions
  • Competitive salary and equity package reflecting experience and contribution.
  • Opportunity to take significant ownership of a growing security and infrastructure function.
  • Work on advanced AI and automation technologies serving complex
Стек и навыки

С чем работаем