
Senior Infrastructure Security Specialist
Job Description
Our mission is to provide real-time on-orbit connectivity for critical missions, enabling a new era of data-driven intelligence and innovation. With 33 satellites launched to date, Kepler operates the first commercial optical data relay constellation, enabling real-time, continuous space communications while supporting advanced on-orbit compute and hosted payload capabilities.
As a Senior Infrastructure Security Specialist, you will play a key role in protecting Kepler's corporate, cloud, and operational infrastructure. Reporting to the VP, Information Security & CISO, you will be responsible for owning, operating, and continuously improving core infrastructure security capabilities, including vulnerability management, security monitoring and SIEM, endpoint security, infrastructure hardening, and incident response. You will work closely with IT, Engineering, Operations, and other business teams to identify security risks, implement practical security controls, and ensure Kepler's infrastructure remains secure and resilient as the organization continues to scale.
The role will also support security requirements associated with regulated and Government of Canada environments, including environments that may process Protected and Classified information.
This role is based in Toronto and follows a hybrid work model, with approximately 40% of time spent on-site.
Key Responsibilities:
Infrastructure Security
- Provide security engineering expertise for existing and new infrastructure, cloud environments, networks, systems, and related technologies.
- Review infrastructure and solution architectures to identify security risks and recommend practical security controls and risk mitigation measures.
- Assess and improve security controls across networks, servers, operating systems, cloud infrastructure, databases, firewalls, identity systems, and other infrastructure technologies.
- Develop, maintain, and continuously improve secure configuration and system-hardening standards based on recognized security frameworks and industry best practices, including CIS Benchmarks and NIST guidance; assess systems against established baselines and work with system owners to remediate identified configuration gaps.
- Work closely with IT and Engineering teams to integrate security requirements into infrastructure design, implementation, and operational processes.
- Support the design, implementation, and improvement of infrastructure security controls, including firewalls, network segmentation, secure remote access, and other network security technologies.
- Own, operate, and continuously improve Kepler's infrastructure vulnerability management capability.
- Manage vulnerability scanning across infrastructure environments, including authenticated scanning and validation of scanning coverage.
- Review and analyze vulnerability findings and apply risk-based prioritization to support effective remediation.
- Coordinate remediation activities with IT, Engineering, Operations, and system owners, and track vulnerabilities through remediation or approved risk acceptance.
- Assess infrastructure against established secure configuration baselines and identify configuration deviations requiring remediation.
- Develop and report metrics related to vulnerability exposure, remediation performance, scanning coverage, exceptions, and overall vulnerability management effectiveness.
- Administer, maintain, and optimize enterprise vulnerability management technologies such as Tenable or equivalent platforms.
- Own and continuously improve Kepler's SIEM and security monitoring capabilities.
- Manage the onboarding and integration of infrastructure, cloud, application, identity, and security technology log sources into the SIEM.
- Develop, maintain, and tune security monitoring and detection use cases to improve threat detection effectiveness.
- Monitor SIEM health, logging coverage, and detection effectiveness, and identify and address gaps in security visibility.
- Serve as a key technical security contact for Kepler's MDR/SOC provider, coordinating escalations, investigations, and continuous service improvements.
- Support investigation and response to security alerts and coordinate escalations with internal stakeholders and external security providers.
- Administer, maintain, and optimize SIEM technologies such as Securonix or equivalent platforms.
- Own and continuously improve Kepler's endpoint security and Endpoint Detection and Response (EDR/XDR) capabilities.
- Maintain endpoint security policies, configurations, agent coverage, and security posture across supported environments.
- Investigate endpoint security alerts and support containment, remediation, and recovery activities.
- Work with IT and system owners to address endpoint security gaps and improve endpoint protection.
- Administer, maintain, and optimize endpoint security technologies such as SentinelOne or equivalent platforms.
- Serve as a key technical contributor during cybersecurity incidents and investigations, particularly those involving infrastructure, endpoints, identity, network, and cloud environments.
- Perform security analysis using SIEM, endpoint, network, vulnerability, and other available security telemetry.
- Support incident containment, remediation, recovery, and evidence collection activities.
- Work with internal teams and external security providers during security investigations.
- Participate in post-incident reviews and identify opportunities to improve security controls, monitoring, detection, and response capabilities.
- Assess security risks and controls within cloud environments, including AWS and/or Microsoft Azure.
- Support secure configuration of cloud infrastructure, identity and access management, logging, network security, and other cloud security controls.
- Review infrastructure changes and projects and provide practical security recommendations aligned with business and operational requirements.
- Identify opportunities to automate security operations, monitoring, vulnerability management, and other infrastructure security processes using scripting, APIs, and security tooling.
- Support security requirements associated with Government of Canada contracts and other regulated or sensitive environments.
- Assist with implementing technical controls required for systems processing or supporting Protected and Classified information.
- Work with Security, IT, Engineering, Facilities, and program teams to implement security requirements related to access control, system hardening, vulnerability management, logging, monitoring, and secure infrastructure.
- Support security assessments, audits, inspections, certification activities, and remediation efforts associated with customer, regulatory, contractual, and Government of Canada cybersecurity requirements.
- Maintain appropriate documentation and evidence demonstrating implementation and operation of applicable infrastructure security controls.
Vulnerability & Configuration Management
Security Monitoring, SIEM & MDR
Endpoint Security
Incident Response
Cloud Security & Automation
Government & Regulated Environments
Required Skills & Qualifications:
- 7+ years of progressive experience in cybersecurity, with demonstrated hands-on experience in infrastructure security, security engineering, security operations, or a related technical security role.
- Strong hands-on knowledge of infrastructure security across Windows, Linux, networking, cloud, and enterprise IT environments.
- Demonstrated experience operating or supporting enterprise vulnerability management platforms, including vulnerability scanning, analysis, prioritization, and remediation.
- Experience with SIEM and security monitoring technologies, including log analysis, security investigations, detection use cases, and monitoring.
- Experience with endpoint security and EDR/XDR technologies, including alert investigation, containment, and security policy management.
- Strong understanding of network security concepts including firewalls, network segmentation, intrusion detection/prevention, secure protocols, and network monitoring.
- Experience supporting cybersecurity incident investigations and remediation.
- Experience securing cloud environments such as AWS and/or Microsoft Azure.
- Knowledge of infrastructure and operating-system hardening and secure configuration practices.
- Knowledge of security frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST SP 800-171, NIST SP 800-53, and CIS Controls/Benchmarks.
- Understanding of identity and access management, privileged access, authentication, authorization, and least-privilege principles.
- Ability to analyze technical security risks and clearly communicate findings and recommendations to technical and non-technical stakeholders.
- Strong problem-solving skills with demonstrated ownership and accountability.
- Strong organizational skills and the ability to manage multiple priorities in a fast-paced environment.
- Ability to work independently while collaborating effectively across Security, IT, Engineering, Operations, and other teams.
- Ability to obtain and maintain a Government of Canada security clearance appropriate to the role.
Bonus Points:
- Hands-on experience with Tenable, Securonix, SentinelOne, or comparable vulnerability management, SIEM, and endpoint security platforms.
- Experience working with an external MDR/MSSP/SOC provider.
- Experience supporting Government of Canada contracts or environments handling Protected or Classified information.
- Familiarity with Government of Canada security requirements and guidance, including ITSG-33, ITSP.10.171, the Canadian Program for Cyber Security Certification (CPCSC), and the Contract Security Program (CSP).
- Understanding of Government of Canada personnel, information, IT, and facility security requirements.
- Experience supporting security audits, assessments, compliance activities, or customer security reviews.
- Experience with security automation or scripting using technologies such as Python, PowerShell, Bash, or APIs.
- Experience with infrastructure-as-code, cloud security tooling, or automated configuration management.
- Relevant security or technology certifications such as CISSP, GIAC, CCSP, Security+, CISM, CISA, or equivalent technical certifications.
- Bachelor’s degree in computer science, Information Security, Engineering, Information Technology, or a related discipline, or an equivalent combination of education and relevant professional experience.
What Success Looks Like:
The successful candidate will take ownership of Kepler's core infrastructure security capabilities and work collaboratively with teams across the organization to reduce security risk without unnecessarily slowing the business.
You will help ensure vulnerabilities are identified, prioritized, and remediated effectively; security monitoring provides appropriate visibility and detection coverage; endpoints and infrastructure remain appropriately protected; security incidents can be rapidly investigated and contained; and infrastructure supporting sensitive and Government of Canada programs meets applicable security requirements.
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Department
- Operations
- Category
- Security
- Employment Type
- Full Time
- Location
- Toronto, Canada (Hybrid)
- Posted
About Kepler Communications
Kepler Communications is a satellite communications company that is working towards establishing an in-space telecommunications network for space-borne assets. Put simply, we are building cell phone towers in space. This infrastructure will resolve the problem of intermittent connectivity for non-geostationary satellites, will open new business opportunities that necessitate real-time connectivity to satellites, and will reduce reliance on costly and difficult to deploy ground infrastructure.
More Roles at Kepler Communications





Similar Security Roles
Found this role interesting?
