Security & Infrastructure Engineer
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
Nexxa is building the best AI systems for heavy industries — enabling machines, systems, and operations to think, decide, and act autonomously across manufacturing, large-scale infrastructure, logistics, and legacy environments.
Our mission is to translate deep technical breakthroughs into operational reality, solving some of the hardest systems-level problems in industry.
About the RoleSelling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not a function beside it.
We hold SOC 2 Type 2 and ISO 27001, and we're moving toward more certifications because governing autonomous industrial systems responsibly is a commercial requirement in our market. You'll own our certification programs and the security and infrastructure underneath them — across our multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments, not customer plant-floor or control-system security.
This role is ideal for candidates who want real, ongoing ownership of a security function, including standing up and running one of the industry's first AI management systems, at a company where trust and compliance directly determine whether customers deploy the platform at all.
What You'll DoOwn the compliance calendar across SOC 2 Type 2 and ISO 27001 — evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readiness
Triage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closure
Remediate what you triage directly in infrastructure as code, IAM policy, and pipeline configuration
Administer identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycle
Support internal IT operations — endpoint fleet and device compliance, SaaS and license administration, asset inventory, support requests — while keeping the human cost of them flat as the company grows
Serve as the working interface to external auditors, our certification body, and customer security and procurement reviews
Build controls into infrastructure so they hold automatically, replacing manual verification with guardrails that fail closed
Harden CI/CD and the software supply chain — build identity, artifact provenance, dependency and secret hygiene
Debug production issues across cloud infrastructure, containers, and networking, and write the postmortem that keeps the fix from being forgotten
Produce documentation others rely on: runbooks, control narratives, architecture notes, postmortems
Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical role — broad competence across security, networking, and operating systems, with real depth in at least one
Deep hands‑on experience with:
Security fundamentals — trust boundaries and blast radius, authentication vs. authorization, least privilege, secrets handling, and judging real‑world exploitability of findings
Networking — diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, and proxies; comfortable with VPN/private connectivity and packet captures
Linux operating systems — processes, file systems, permissions, systemd, resource limits, log analysis, and how containers relate to the host
Cloud infrastructure — hands‑on with AWS or GCP beyond the console: IAM, networking, compute, and their failure modes
Strong scripting/automation skills (Python, Bash, Go, or similar) — recurring manual work gets…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).