Senior Infrastructure Security Specialist

Kepler

Toronto

Hybrid

CAD 140,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive compensation with equity
Health, dental, and vision insurance—+
Unlimited vacation and parental leave
Company-wide holidays shutdown
Relocation packages for approved roles
Professional development fund: $1,500/
Well-stocked Toronto office kitchen
Great Place to Work certification

Job summary

Kepler Communications is building the future of on-orbit connectivity from Toronto. The Senior Infrastructure Security Specialist will own and improve core infrastructure security across on-premises and cloud environments, including vulnerability management, SIEM, endpoint protection, and incident response.

This role supports regulated environments, engages with IT/Engineering teams, and ensures security controls scale with the business.

Qualifications

  • 7+ years of progressive experience in cybersecurity with hands-on infrastructure security.
  • Hands-on knowledge across Windows, Linux, networking, cloud and enterprise IT.
  • Experience with vulnerability management platforms (Ten able) and SIEM/EDR tooling.

Responsibilities

  • Provide security engineering expertise for existing and new infrastructure, cloud environments, networks, systems, and related technologies.
  • Review architectures to identify security risks and implement practical controls.
  • Develop and maintain secure configuration and hardening standards (CIS, NIST).
  • Collaborate with IT and Engineering to integrate security into design and operations.
  • Own vulnerability management, scanning, remediation prioritization, and metrics reporting.
  • Manage SIEM onboarding and security monitoring use cases; coordinate with MDR/SOC provider.
  • Lead incident response efforts and post-incident improvements.
  • Support security requirements for Government of Canada contracts and regulated environments.
  • Automate security operations using scripting and security tooling.

Skills

Infrastructure security
Security engineering
Security operations
Cloud security
Vulnerability management
SIEM & security monitoring
Endpoint security
Incident response
Government/regulatory security
Python/scripting

Education

Bachelor’s degree in Computer Science / Information Security / Engineering

Tools

Tenable
Securonix
SentinelOne

Job description

At Kepler Communications, we're not just imagining the future of on-demand space connectivity - we're leading it!

Our mission is to provide real-time on-orbit connectivity for critical missions, enabling a new era of data-driven intelligence and innovation. With 33 satellites launched to date, Kepler operates the first commercial optical data relay constellation, enabling real-time, continuous space communications while supporting advanced on-orbit compute and hosted payload capabilities.

Industry-leading technology is only part of the story. What sets Kepler apart is our team: bold thinkers, skilled builders, and passionate problem-solvers who thrive on pushing the boundaries ofwhat’spossible in space. We believe great ideas come from diverse perspectives, andwe’recommitted to creating an environment where you can grow, lead, and make a global impact.

Ifyou’reready to reach higher, move faster, and do work that shapes the future space economy - this is your launchpad. Come build the future with Kepler!

What We Offer:
  • Competitive compensation with a robust equity plan to share in our success.
  • Comprehensive coverage for health, dental, and vision insurance—including dependents.
  • Unlimited vacation, supportive parental leave policy, and company-wide holiday shutdown.
  • Semi-annual company-wide parties and frequent in-office team events.
  • Relocation packages available for approved roles.
  • $1,500 annual professional development fund to support your growth.
  • Fully stocked Toronto office kitchen with snacks, drinks, games and top-notch kitchen appliances.
  • Town Halls, Celebration Calls, and Company-wide events to stay connected and engaged.
  • We’re a certified Great Place to Work®, seven years in a row!

Senior Infrastructure Security Specialist, you will play a key role in protecting Kepler's corporate, cloud, and operational infrastructure. Reporting to the VP, Information Security & CISO, you will be responsible for owning, operating, and continuously improving core infrastructure security capabilities, including vulnerability management, security monitoring and SIEM, endpoint security, infrastructure hardening, and incident response. You will work closely with IT, Engineering, Operations, and other business teams to identify security risks, implement practical security controls, and ensure Kepler's infrastructure remains secure and resilient as the organization continues to scale.

The role will also support security requirements associated with regulated and Government of Canada environments, including environments that may process Protected and Classified information.

This role is based in Toronto and follows a hybrid work model, with approximately 40% of time spent on-site.

Infrastructure Security
  • Provide security engineering expertise for existing and new infrastructure, cloud environments, networks, systems, and related technologies.
  • Review infrastructure and solution architectures to identify security risks and recommend practical security controls and risk mitigation measures.
  • Assess and improve security controls across networks, servers, operating systems, cloud infrastructure, databases, firewalls, identity systems, and other infrastructure technologies.
  • Develop, maintain, and continuously improve secure configuration and system-hardening standards based on recognized security frameworks and industry best practices, including CIS Benchmarks and NIST guidance; assess systems against established baselines and work with system owners to remediate identified configuration gaps.
  • Work closely with IT and Engineering teams to integrate security requirements into infrastructure design, implementation, and operational processes.
  • Support the design, implementation, and improvement of infrastructure security controls, including firewalls, network segmentation, secure remote access, and other network security technologies.
Vulnerability & Configuration Management
  • Own, operate, and continuously improve Kepler's infrastructure vulnerability management capability.
  • Manage vulnerability scanning across infrastructure environments, including authenticated scanning and validation of scanning coverage.
  • Review and analyze vulnerability findings and apply risk-based prioritization to support effective remediation.
  • Coordinate remediation activities with IT, Engineering, Operations, and system owners, and track vulnerabilities through remediation or approved risk acceptance.
  • Assess infrastructure against established secure configuration baselines and identify configuration deviations requiring remediation.
  • Develop and report metrics related to vulnerability exposure, remediation performance, scanning coverage, exceptions, and overall vulnerability management effectiveness.
  • Administer, maintain, and optimize enterprise vulnerability management technologies such as Tenable or equivalent platforms.
Security Monitoring, SIEM & MDR
  • Own and continuously improve Kepler's SIEM and security monitoring capabilities.
  • Manage the onboarding and integration of infrastructure, cloud, application, identity, and security technology log sources into the SIEM.
  • Develop, maintain, and tune security monitoring and detection use cases to improve threat detection effectiveness.
  • Monitor SIEM health, logging coverage, and detection effectiveness, and identify and address gaps in security visibility.
  • Serve as a key technical security contact for Kepler's MDR/SOC provider, coordinating escalations, investigations, and continuous service improvements.
  • Support investigation and response to security alerts and coordinate escalations with internal stakeholders and external security providers.
  • Administer, maintain, and optimize SIEM technologies such as Securonix or equivalent platforms.
Endpoint Security
  • Own and continuously improve Kepler's endpoint security and Endpoint Detection and Response (EDR/XDR) capabilities.
  • Maintain endpoint security policies, configurations, agent coverage, and security posture across supported environments.
  • Investigate endpoint security alerts and support containment, remediation, and recovery activities.
  • Work with IT and system owners to address endpoint security gaps and improve endpoint protection.
  • Administer, maintain, and optimize endpoint security technologies such as SentinelOne or equivalent platforms.
Incident Response
  • Serve as a key technical contributor during cybersecurity incidents and investigations, particularly those involving infrastructure, endpoints, identity, network, and cloud environments.
  • Perform security analysis using SIEM, endpoint, network, vulnerability, and other available security telemetry.
  • Support incident containment, remediation, recovery, and evidence collection activities.
  • Work with internal teams and external security providers during security investigations.
  • Participate in post-incident reviews and identify opportunities to improve security controls, monitoring, detection, and response capabilities.
Cloud Security & Automation
  • Assess security risks and controls within cloud environments, including AWS and/or Microsoft Azure.
  • Support secure configuration of cloud infrastructure, identity and access management, logging, network security, and other cloud security controls.
  • Review infrastructure changes and projects and provide practical security recommendations aligned with business and operational requirements.
  • Identify opportunities to automate security operations, monitoring, vulnerability management, and other infrastructure security processes using scripting, APIs, and security tooling.
Government & Regulated Environments
  • Support security requirements associated with Government of Canada contracts and other regulated or sensitive environments.
  • Assist with implementing technical controls required for systems processing or supporting Protected and Classified information.
  • Work with Security, IT, Engineering, Facilities, and program teams to implement security requirements related to access control, system hardening, vulnerability management, logging, monitoring, and secure infrastructure.
  • Support security assessments, audits, inspections, certification activities, and remediation efforts associated with customer, regulatory, contractual, and Government of Canada cybersecurity requirements.
  • Maintain appropriate documentation and evidence demonstrating implementation and operation of applicable infrastructure security controls.
  • 7+ years of progressive experience in cybersecurity, with demonstrated hands-on experience in infrastructure security, security engineering, security operations, or a related technical security role.
  • Strong hands-on knowledge of infrastructure security across Windows, Linux, networking, cloud, and enterprise IT environments.
  • Demonstrated experience operating or supporting enterprise vulnerability management platforms, including vulnerability scanning, analysis, prioritization, and remediation.
  • Experience with SIEM and security monitoring technologies, including log analysis, security investigations, detection use cases, and monitoring.
  • Experience with endpoint security and EDR/XDR technologies, including alert investigation, containment, and security policy management.
  • Strong understanding of network security concepts including firewalls, network segmentation, intrusion detection/prevention, secure protocols, and network monitoring.
  • Experience supporting cybersecurity incident investigations and remediation.
  • Experience securing cloud environments such as AWS and/or Microsoft Azure.
  • Knowledge of infrastructure and operating-system hardening and secure configuration practices.
  • Knowledge of security frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST SP 800-171, NIST SP 800-53, and CIS Controls/Benchmarks.
  • Understanding of identity and access management, privileged access, authentication, authorization, and least-privilege principles.
  • Ability to analyze technical security risks and clearly communicate findings and recommendations to technical and non-technical stakeholders.
  • Strong problem-solving skills with demonstrated ownership and accountability.
  • Strong organizational skills and the ability to manage multiple priorities in a fast-paced environment.
  • Ability to work independently while collaborating effectively across Security, IT, Engineering, Operations, and other teams.
  • Ability to obtain and maintain a Government of Canada security clearance appropriate to the role.
  • Hands-on experience with Tenable, Securonix, SentinelOne, or comparable vulnerability management, SIEM, and endpoint security platforms.
  • Experience working with an external MDR/MSSP/SOC provider.
  • Experience supporting Government of Canada contracts or environments handling Protected or Classified information.
  • Familiarity with Government of Canada security requirements and guidance, including ITSG-33, ITSP.10.171, the Canadian Program for Cyber Security Certification (CPCSC), and the Contract Security Program (CSP).
  • Understanding of Government of Canada personnel, information, IT, and facility security requirements.
  • Experience supporting security audits, assessments, compliance activities, or customer security reviews.
  • Experience with security automation or scripting using technologies such as Python, PowerShell, Bash, or APIs.
  • Experience with infrastructure-as-code, cloud security tooling, or automated configuration management.
  • Relevant security or technology certifications such as CISSP, GIAC, CCSP, Security+, CISM, CISA, or equivalent technical certifications.
  • Bachelor’s degree in computer science, Information Security, Engineering, Information Technology, or a related discipline, or an equivalent combination of education and relevant professional experience.

The successful candidate will take ownership of Kepler's core infrastructure security capabilities and work collaboratively with teams across the organization to reduce security risk without unnecessarily slowing the business.

You will help ensure vulnerabilities are identified, prioritized, and remediated effectively; security monitoring provides appropriate visibility and detection coverage; endpoints and infrastructure remain appropriately protected; security incidents can be rapidly investigated and contained; and infrastructure supporting sensitive and Government of Canada programs meets applicable security requirements.

Employment Equity & Accommodation Statement

Kepler Communications is an equal opportunity employer committed to building a diverse and inclusive workplace. We welcome applications from all qualified individuals, including women, Indigenous peoples, persons with disabilities, members of visible minorities, and people of all sexual orientations and gender identities.

If you require accommodation during any stage of the recruitment process, please contact our People & Culture team at accommodation@kepler.space, and we will work with you to meet your needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Infrastructure Security Specialist
Senior Infrastructure Security Specialist

Kepler Communications • Toronto

Hybrid
CAD 157,000 - 226,000
Equity plan
Health insurance
Unlimited vacation
+6
IT Manager
IT Manager

Linuxconfig • Toronto

On-site
CAD 145,000 - 170,000
Competitive compensation
Health/dental/vision insurance
Unlimited vacation
+5
Embedded Software Designer
Embedded Software Designer

Kepler Communications Inc. • Toronto

On-site
CAD 156,000 - 182,000
Equity plan
Unlimited vacation
Parental leave
+5
Principal Engineer - Satellite Systems
Principal Engineer - Satellite Systems

Kepler Communications Inc. • Toronto

Hybrid
CAD 180,000 - 240,000
Competitive compensation with equity
Health, dental & vision Insurance
Unlimited vacation
+6
Staff Program Manager
Staff Program Manager

Kepler Communications Inc. • Toronto

On-site
CAD 143,000 - 193,000
Competitive equity plan
Health, dental, vision insurance for 2
Unlimited vacation
+7
Systems Verification and Validation (V&V) Specialist
Systems Verification and Validation (V&V) Specialist

Kepler Communications Inc. • Toronto

On-site
CAD 101,000 - 151,000
Competitive equity plan'
Health, dental, vision insurance
Unlimited vacation and parental leave
+6
Program Chief Engineer
Program Chief Engineer

Kepler Communications Inc. • Toronto

Hybrid
CAD 180,000 - 240,000
Competitive compensation with equity
Health, dental, and vision insurance (
Unlimited vacation and parental leave
+4
Senior Electrical Engineer & Team Lead
Senior Electrical Engineer & Team Lead

Kepler Communications Inc. • Toronto

On-site
CAD 133,346 - 183,346
Competitive compensation with equity plan
Comprehensive health, dental, and vision insurance
Unlimited vacation
+3
Staff Program Manager
Staff Program Manager

Kepler Communications Inc. • Toronto

On-site
CAD 142,000 - 193,000
Equity plan
Unlimited vacation
Parental leave
+7
Senior Electrical Engineer & Team Lead
Senior Electrical Engineer & Team Lead

Clutch Canada • Toronto

On-site
CAD 120,000 - 180,000
Competitive compensation
Comprehensive health insurance
Unlimited vacation
+3