Senior Infrastructure Security Specialist
Job Summary
Our mission is to provide real-time on-orbit connectivity for critical missions enabling a new era of data-driven intelligence and innovation. With 33 satellites launched to date Kepler operates the first commercial optical data relay constellation enabling real-time continuous space communications while supporting advanced on-orbit compute and hosted payload capabilities.
As a Senior Infrastructure Security Specialist you will play a key role in protecting Keplers corporate cloud and operational infrastructure. Reporting to the VP Information Security & CISO you will be responsible for owning operating and continuously improving core infrastructure security capabilities including vulnerability management security monitoring and SIEM endpoint security infrastructure hardening and incident response. You will work closely with IT Engineering Operations and other business teams to identify security risks implement practical security controls and ensure Keplers infrastructure remains secure and resilient as the organization continues to scale.
The role will also support security requirements associated with regulated and Government of Canada environments including environments that may process Protected and Classified information.
This role is based in Toronto and follows a hybrid work model with approximately 40% of time spent on-site.
Infrastructure Security
- Provide security engineering expertise for existing and new infrastructure cloud environments networks systems and related technologies.
- Review infrastructure and solution architectures to identify security risks and recommend practical security controls and risk mitigation measures.
- Assess and improve security controls across networks servers operating systems cloud infrastructure databases firewalls identity systems and other infrastructure technologies.
- Develop maintain and continuously improve secure configuration and system-hardening standards based on recognized security frameworks and industry best practices including CIS Benchmarks and NIST guidance; assess systems against established baselines and work with system owners to remediate identified configuration gaps.
- Work closely with IT and Engineering teams to integrate security requirements into infrastructure design implementation and operational processes.
- Support the design implementation and improvement of infrastructure security controls including firewalls network segmentation secure remote access and other network security technologies.
Vulnerability & Configuration Management
- Own operate and continuously improve Keplers infrastructure vulnerability management capability.
- Manage vulnerability scanning across infrastructure environments including authenticated scanning and validation of scanning coverage.
- Review and analyze vulnerability findings and apply risk-based prioritization to support effective remediation.
- Coordinate remediation activities with IT Engineering Operations and system owners and track vulnerabilities through remediation or approved risk acceptance.
- Assess infrastructure against established secure configuration baselines and identify configuration deviations requiring remediation.
- Develop and report metrics related to vulnerability exposure remediation performance scanning coverage exceptions and overall vulnerability management effectiveness.
- Administer maintain and optimize enterprise vulnerability management technologies such as Tenable or equivalent platforms.
Security Monitoring SIEM & MDR
- Own and continuously improve Keplers SIEM and security monitoring capabilities.
- Manage the onboarding and integration of infrastructure cloud application identity and security technology log sources into the SIEM.
- Develop maintain and tune security monitoring and detection use cases to improve threat detection effectiveness.
- Monitor SIEM health logging coverage and detection effectiveness and identify and address gaps in security visibility.
- Serve as a key technical security contact for Keplers MDR/SOC provider coordinating escalations investigations and continuous service improvements.
- Support investigation and response to security alerts and coordinate escalations with internal stakeholders and external security providers.
- Administer maintain and optimize SIEM technologies such as Securonix or equivalent platforms.
Endpoint Security
- Own and continuously improve Keplers endpoint security and Endpoint Detection and Response (EDR/XDR) capabilities.
- Maintain endpoint security policies configurations agent coverage and security posture across supported environments.
- Investigate endpoint security alerts and support containment remediation and recovery activities.
- Work with IT and system owners to address endpoint security gaps and improve endpoint protection.
- Administer maintain and optimize endpoint security technologies such as SentinelOne or equivalent platforms.
Incident Response
- Serve as a key technical contributor during cybersecurity incidents and investigations particularly those involving infrastructure endpoints identity network and cloud environments.
- Perform security analysis using SIEM endpoint network vulnerability and other available security telemetry.
- Support incident containment remediation recovery and evidence collection activities.
- Work with internal teams and external security providers during security investigations.
- Participate in post-incident reviews and identify opportunities to improve security controls monitoring detection and response capabilities.
Cloud Security & Automation
- Assess security risks and controls within cloud environments including AWS and/or Microsoft Azure.
- Support secure configuration of cloud infrastructure identity and access management logging network security and other cloud security controls.
- Review infrastructure changes and projects and provide practical security recommendations aligned with business and operational requirements.
- Identify opportunities to automate security operations monitoring vulnerability management and other infrastructure security processes using scripting APIs and security tooling.
Government & Regulated Environments
- Support security requirements associated with Government of Canada contracts and other regulated or sensitive environments.
- Assist with implementing technical controls required for systems processing or supporting Protected and Classified information.
- Work with Security IT Engineering Facilities and program teams to implement security requirements related to access control system hardening vulnerability management logging monitoring and secure infrastructure.
- Support security assessments audits inspections certification activities and remediation efforts associated with customer regulatory contractual and Government of Canada cybersecurity requirements.
- Maintain appropriate documentation and evidence demonstrating implementation and operation of applicable infrastructure security controls.
- 7 years of progressive experience in cybersecurity with demonstrated hands-on experience in infrastructure security security engineering security operations or a related technical security role.
- Strong hands-on knowledge of infrastructure security across Windows Linux networking cloud and enterprise IT environments.
- Demonstrated experience operating or supporting enterprise vulnerability management platforms including vulnerability scanning analysis prioritization and remediation.
- Experience with SIEM and security monitoring technologies including log analysis security investigations detection use cases and monitoring.
- Experience with endpoint security and EDR/XDR technologies including alert investigation containment and security policy management.
- Strong understanding of network security concepts including firewalls network segmentation intrusion detection/prevention secure protocols and network monitoring.
- Experience supporting cybersecurity incident investigations and remediation.
- Experience securing cloud environments such as AWS and/or Microsoft Azure.
- Knowledge of infrastructure and operating-system hardening and secure configuration practices.
- Knowledge of security frameworks and standards such as NIST Cybersecurity Framework (CSF) NIST SP 800-171 NIST SP 800-53 and CIS Controls/Benchmarks.
- Understanding of identity and access management privileged access authentication authorization and least-privilege principles.
- Ability to analyze technical security risks and clearly communicate findings and recommendations to technical and non-technical stakeholders.
- Strong problem-solving skills with demonstrated ownership and accountability.
- Strong organizational skills and the ability to manage multiple priorities in a fast-paced environment.
- Ability to work independently while collaborating effectively across Security IT Engineering Operations and other teams.
- Ability to obtain and maintain a Government of Canada security clearance appropriate to the role.
- Hands-on experience with Tenable Securonix SentinelOne or comparable vulnerability management SIEM and endpoint security platforms.
- Experience working with an external MDR/MSSP/SOC provider.
- Experience supporting Government of Canada contracts or environments handling Protected or Classified information.
- Familiarity with Government of Canada security requirements and guidance including ITSG-33 ITSP.10.171 the Canadian Program for Cyber Security Certification (CPCSC) and the Contract Security Program (CSP).
- Understanding of Government of Canada personnel information IT and facility security requirements.
- Experience supporting security audits assessments compliance activities or customer security reviews.
- Experience with security automation or scripting using technologies such as Python PowerShell Bash or APIs.
- Experience with infrastructure-as-code cloud security tooling or automated configuration management.
- Relevant security or technology certifications such as CISSP GIAC CCSP Security CISM CISA or equivalent technical certifications.
- Bachelors degree in computer science Information Security Engineering Information Technology or a related discipline or an equivalent combination of education and relevant professional experience.
The successful candidate will take ownership of Keplers core infrastructure security capabilities and work collaboratively with teams across the organization to reduce security risk without unnecessarily slowing the business.
You will help ensure vulnerabilities are identified prioritized and remediated effectively; security monitoring provides appropriate visibility and detection coverage; endpoints and infrastructure remain appropriately protected; security incidents can be rapidly investigated and contained; and infrastructure supporting sensitive and Government of Canada programs meets applicable security requirements.
Actual total compensation will be determined at the Companys discretion and is based on a variety of job-related factors which may include but are not limited to relevant knowledge skills experience performance and education and/or training. The Company encourages all qualified applicants to apply even if the posted salary range does not align with their expectations as it does not reflect our total compensation package.
Job Type: This is for a current vacancy
Required Experience:
Senior IC
About Company
Employment Equity & Accommodation Statement Kepler Communications is an equal opportunity employer committed to building a diverse and inclusive workplace. We welcome applications from all qualified individuals, including women, Indigenous peoples, persons with disabilities, members o ... View more