
Security & Infrastructure Engineer
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Canada.
• Take ownership of the compliance calendar for SOC 2 Type 2 and ISO 27001, which includes gathering evidence, conducting access and vendor reviews, monitoring controls, performing internal audits, overseeing management reviews, refreshing policies, and ensuring audit readiness.
• Assess security findings related to cloud posture, code scanning, dependencies, and secrets, and drive the remediation process to completion.
• Address findings directly within infrastructure as code, IAM policy, and pipeline configurations.
• Manage identity and access across cloud and SaaS platforms, encompassing SSO/federation, least-privilege roles, and the lifecycle of joiners, movers, and leavers.
• Assist internal IT operations, which include managing the endpoint fleet and device compliance, administering SaaS and licenses, maintaining asset inventory, and handling support requests.
• Act as the primary liaison with external auditors, certification bodies, and customer security and procurement evaluations.
• Implement controls within the infrastructure utilizing automatically enforced guardrails that default to a closed state.
• Strengthen CI/CD processes and the software supply chain, focusing on build identity, artifact provenance, dependency management, and secret handling.
• Troubleshoot production issues across cloud infrastructure, containers, and networking.
• Create postmortems and develop runbooks, control narratives, architecture notes, and other essential operational documentation.
• Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical field.
• Extensive knowledge across security, networking, and operating systems, with significant expertise in at least one area.
• In-depth hands-on experience with security fundamentals, such as trust boundaries, blast radius, authentication, authorization, least privilege, secrets management, and exploitability assessment.
• Networking proficiency, including routing, firewalls/security groups, DNS, TLS termination, proxies, VPN/private connectivity, and packet capture techniques.
• Hands-on experience with Linux operating systems regarding processes, filesystems, permissions, systemd, resource limits, log analysis, and container-host relationships.
• Practical experience with AWS or GCP cloud infrastructure beyond the console, including IAM, networking, compute, and understanding failure modes.
• Strong scripting and automation capabilities in Python, Bash, Go, or similar languages.
• Excellent writing skills for creating control narratives, runbooks, postmortems, audit responses, and risk assessments.
• Demonstrated judgment in ambiguous situations.
• A degree in Computer Science or Computer Engineering, or equivalent hands-on experience.
• Experience with ISO 27001 is preferred.
• Experience with SOC 2 is preferred.
• Familiarity with AI governance or ISO 42001 is preferred.
• Experience with infrastructure as code, particularly using Pulumi or Terraform, is preferred.
• Preferred experience in managing multi-account cloud organizations.
• Experience with identity provider and endpoint management at scale is preferred.
• Familiarity with cloud security tooling is preferred.
• Experience in container orchestration using ECS, EKS, or Kubernetes is preferred.
• Observability experience with metrics, logs, and traces is preferred.
• Experience across both AWS and GCP, including workload identity federation, is preferred.
• Awareness of cloud costs is preferred.
• Experience in a startup or high-growth environment is preferred.
• Equity package
• Competitive compensation
• Opportunities for career development and advancement
• Remote work arrangements
• A collaborative culture
• An innovative environment
• Continuous improvement opportunities
Sezzle
HavocAI
QuickNode ⚡
Sezzle
Get handpicked remote jobs straight to your inbox weekly.