Senior Infrastructure Security Specialist
Other Engineering
Toronto, ON, Canada
CAD 114k-164k / year + Equity
Our mission is to provide real-time on-orbit connectivity for critical missions, enabling a new era of data-driven intelligence and innovation. With 33 satellites launched to date, Kepler operates the first commercial optical data relay constellation, enabling real-time, continuous space communications while supporting advanced on-orbit compute and hosted payload capabilities.
As Senior Infrastructure Security Specialist, you will protect Kepler’s corporate, cloud, and operational infrastructure. Reporting to the VP, Information Security & CISO, you will own and improve infrastructure security capabilities, including vulnerability management, security monitoring, endpoint protection, system hardening, and incident response.
You will partner with IT, Engineering, Operations, and other teams to reduce security risk while supporting Kepler’s growth. The role also supports regulated and Government of Canada environments that may process Protected or Classified information.
This Toronto-based role follows a hybrid model, with approximately 40% of time spent on-site.
Key Responsibilities:
- Provide security expertise for infrastructure, cloud environments, networks, systems, databases, and identity technologies
- Review architectures and infrastructure changes to identify risks and recommend practical controls
- Develop secure configuration and hardening standards based on CIS Benchmarks, NIST guidance, and industry best practices
- Support network security controls, including firewalls, segmentation, secure remote access, and intrusion detection and prevention
- Partner with IT and Engineering to incorporate security into infrastructure design and operations
- Own Kepler’s infrastructure vulnerability management program
- Manage authenticated scanning, validate coverage, assess findings, and prioritize remediation based on risk
- Coordinate remediation with system owners and track vulnerabilities through resolution or approved risk acceptance
- Measure vulnerability exposure, remediation performance, scanning coverage, and exceptions
- Administer platforms such as Tenable or equivalent technologies
- Own and improve Kepler’s SIEM, security monitoring, and EDR/XDR capabilities
- Integrate log sources and develop detection use cases across infrastructure, cloud, applications, identity, and security tools
- Monitor logging coverage, platform health, and detection effectiveness
- Investigate security alerts and support containment, remediation, and recovery
- Coordinate investigations and service improvements with Kepler’s MDR/SOC provider
- Administer platforms such as Securonix, SentinelOne, or comparable technologies
- Support incident investigations involving infrastructure, endpoints, networks, identity, and cloud environments
- Analyze security telemetry, collect evidence, and coordinate containment and recovery
- Assess and improve security controls within AWS and/or Microsoft Azure
- Identify opportunities to automate monitoring, vulnerability management, and security operations using scripts, APIs, and security tools
- Implement technical controls for Government of Canada and other regulated environments
- Support audits, security assessments, inspections, certifications, and remediation activities
- Maintain documentation and evidence demonstrating that required security controls are operating effectively
Infrastructure Security
Vulnerability Management
Security Monitoring and Endpoint Protection
Incident Response, Cloud and Automation
Government and Regulated Environments
Required Skills & Qualifications:
- Seven or more years of cybersecurity experience in infrastructure security, security engineering, or security operations
- Strong knowledge of Windows, Linux, networking, cloud platforms, and enterprise IT security
- Strong hands-on experience administering and operating vulnerability management, SIEM/security monitoring, and EDR/XDR technologies
- Experience investigating and responding to cybersecurity incidents
- Knowledge of network security, infrastructure hardening, identity and access management, privileged access, and least-privilege principles
- Experience securing AWS and/or Microsoft Azure environments
- Familiarity with NIST CSF, NIST SP 800-171, NIST SP 800-53, and CIS Controls and Benchmarks
- Ability to communicate technical risks and recommendations to technical and non-technical stakeholders
- Strong ownership, problem-solving, organization, and cross-functional collaboration skills
- Ability to obtain and maintain an appropriate Government of Canada security clearance
Bonus Points:
- Experience with Tenable, Securonix, SentinelOne, or comparable platforms
- Experience working with an MDR, MSSP, or SOC provider
- Experience supporting Government of Canada contracts or environments handling Protected or Classified information
- Familiarity with ITSG-33, ITSP.10.171, the Canadian Program for Cyber Security Certification, and the Contract Security Program
- Experience with security audits, compliance activities, Python, PowerShell, Bash, APIs, or infrastructure as code
- Relevant certification such as CISSP, GIAC, CCSP, Security+, CISM, or CISA
- Relevant degree or an equivalent combination of education and professional experience
What Success Looks Like:
You will strengthen Kepler’s infrastructure security without unnecessarily slowing the business. Vulnerabilities will be effectively remediated, monitoring will provide appropriate visibility, incidents will be investigated quickly, and environments supporting sensitive government programs will meet applicable security requirements.
114000 - 164000 CAD a year
Actual total compensation will be determined at the Company’s discretion and is based on a variety of job-related factors, which may include, but are not limited to, relevant knowledge, skills, experience, performance, and education and/or training. The Company encourages all qualified applicants to apply, even if the posted salary range does not align with their expectations, as it does not reflect our total compensation package.
Job Type: This is for a current vacancy
