RefolkCandidates
Open nowEngineeringOperations

Senior Infrastructure Security Specialist

Kepler Communications · Toronto, Ontario

Location
Toronto, Ontario
Employment
Full time
Level
Senior
Posted
3 weeks ago

About this role

At Kepler Communications, we're not just imagining the future of on-demand space connectivity - we're leading it!

Our mission is to provide real-time on-orbit connectivity for critical missions, enabling a new era of data-driven intelligence and innovation. With 33 satellites launched to date, Kepler operates the first commercial optical data relay constellation, enabling real-time, continuous space communications while supporting advanced on-orbit compute and hosted payload capabilities.

Industry-leading technology is only part of the story. What sets Kepler apart is our team: bold thinkers, skilled builders, and passionate problem-solvers who thrive on pushing the boundaries of what’s possible in space. We believe great ideas come from diverse perspectives, and we’re committed to creating an environment where you can grow, lead, and make a global impact. If you’re ready to reach higher, move faster, and do work that shapes the future space economy - this is your launchpad. Come build the future with Kepler! What We Offer: * Competitive compensation with a robust equity plan to share in our success. * Comprehensive coverage for health, dental, and vision insurance - including dependents. * Unlimited vacation, supportive parental leave policy, and company-wide holiday shutdown. * Semi-annual company-wide parties and frequent in-office team events. * Relocation packages available for approved roles. * $1,500 annual professional development fund to support your growth. * Fully stocked Toronto office kitchen with snacks, drinks, games and top-notch kitchen appliances. * Town Halls, Celebration Calls, and Company-wide events to stay connected and engaged. * We’re a certified Great Place to Work®, seven years in a row!

As Senior Infrastructure Security Specialist, you will protect Kepler’s corporate, cloud, and operational infrastructure. Reporting to the VP, Information Security & CISO, you will own and improve infrastructure security capabilities, including vulnerability management, security monitoring, endpoint protection, system hardening, and incident response.

You will partner with IT, Engineering, Operations, and other teams to reduce security risk while supporting Kepler’s growth. The role also supports regulated and Government of Canada environments that may process Protected or Classified information.

This Toronto-based role follows a hybrid model, with approximately 40% of time spent on-site.

Key Responsibilities:

    Infrastructure Security

    • Provide security expertise for infrastructure, cloud environments, networks, systems, databases, and identity technologies
    • Review architectures and infrastructure changes to identify risks and recommend practical controls
    • Develop secure configuration and hardening standards based on CIS Benchmarks, NIST guidance, and industry best practices
    • Support network security controls, including firewalls, segmentation, secure remote access, and intrusion detection and prevention
    • Partner with IT and Engineering to incorporate security into infrastructure design and operations
    • Vulnerability Management

      • Own Kepler’s infrastructure vulnerability management program
      • Manage authenticated scanning, validate coverage, assess findings, and prioritize remediation based on risk
      • Coordinate remediation with system owners and track vulnerabilities through resolution or approved risk acceptance
      • Measure vulnerability exposure, remediation performance, scanning coverage, and exceptions
      • Administer platforms such as Tenable or equivalent technologies
      • Security Monitoring and Endpoint Protection

        • Own and improve Kepler’s SIEM, security monitoring, and EDR/XDR capabilities
        • Integrate log sources and develop detection use cases across infrastructure, cloud, applications, identity, and security tools
        • Monitor logging coverage, platform health, and detection effectiveness
        • Investigate security alerts and support containment, remediation, and recovery
        • Coordinate investigations and service improvements with Kepler’s MDR/SOC provider
        • Administer platforms such as Securonix, SentinelOne, or comparable technologies
        • Incident Response, Cloud and Automation

          • Support incident investigations involving infrastructure, endpoints, networks, identity, and cloud environments
          • Analyze security telemetry, collect evidence, and coordinate containment and recovery
          • Assess and improve security controls within AWS and/or Microsoft Azure
          • Identify opportunities to automate monitoring, vulnerability management, and security operations using scripts, APIs, and security tools
          • Government and Regulated Environments

            • Implement technical controls for Government of Canada and other regulated environments
            • Support audits, security assessments, inspections, certifications, and remediation activities
            • Maintain documentation and evidence demonstrating that required security controls are operating effectively

Required Skills & Qualifications:

    • Seven or more years of cybersecurity experience in infrastructure security, security engineering, or security operations
    • Strong knowledge of Windows, Linux, networking, cloud platforms, and enterprise IT security
    • Strong hands-on experience administering and operating vulnerability management, SIEM/security monitoring, and EDR/XDR technologies
    • Experience investigating and responding to cybersecurity incidents
    • Knowledge of network security, infrastructure hardening, identity and access management, privileged access, and least-privilege principles
    • Experience securing AWS and/or Microsoft Azure environments
    • Familiarity with NIST CSF, NIST SP 800-171, NIST SP 800-53, and CIS Controls and Benchmarks
    • Ability to communicate technical risks and recommendations to technical and non-technical stakeholders
    • Strong ownership, problem-solving, organization, and cross-functional collaboration skills
    • Ability to obtain and maintain an appropriate Government of Canada security clearance

Bonus Points:

    • Experience with Tenable, Securonix, SentinelOne, or comparable platforms
    • Experience working with an MDR, MSSP, or SOC provider
    • Experience supporting Government of Canada contracts or environments handling Protected or Classified information
    • Familiarity with ITSG-33, ITSP.10.171, the Canadian Program for Cyber Security Certification, and the Contract Security Program
    • Experience with security audits, compliance activities, Python, PowerShell, Bash, APIs, or infrastructure as code
    • Relevant certification such as CISSP, GIAC, CCSP, Security+, CISM, or CISA
    • Relevant degree or an equivalent combination of education and professional experience

What Success Looks Like:

    You will strengthen Kepler’s infrastructure security without unnecessarily slowing the business. Vulnerabilities will be effectively remediated, monitoring will provide appropriate visibility, incidents will be investigated quickly, and environments supporting sensitive government programs will meet applicable security requirements.

$114,000 - 164,000 CAD
Actual total compensation will be determined at the Company’s discretion and is based on a variety of job-related factors, which may include, but are not limited to, relevant knowledge, skills, experience, performance, and education and/or training. The Company encourages all qualified applicants to apply, even if the posted salary range does not align with their expectations, as it does not reflect our total compensation package.
Job Type: This is for a current vacancy
Employment Equity & Accommodation Statement Kepler Communications is an equal opportunity employer committed to building a diverse and inclusive workplace. We welcome applications from all qualified individuals, including women, Indigenous peoples, persons with disabilities, members of visible minorities, and people of all sexual orientations and gender identities. If you require accommodation during any stage of the recruitment process, please contact our People & Culture team at accommodation@kepler.space, and we will work with you to meet your needs.

As published by Kepler Communications. Applications are handled on their site.

Skills this posting mentions

ComplianceData DrivenCloud Services

About Kepler Communications

We are delivering on-orbit data at lightspeed with a constellation of satellites designed to act as Internet exchange points for space-to-space data relay. Headquartered in downtown Toronto, Kepler is vertically integrated with an in-house production facility, designing and deploying a hybrid optical constellation to modernize communications to missions in LEO and beyond.

All 19 openings at Kepler Communications

One click, then it is written

Apply to Kepler Communications with a resume written for this role.

Queue Senior Infrastructure Security Specialist and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Kepler Communications’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Kepler Communications

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Kepler Communications publishes. Refolk is not the employer and does not handle their hiring. Applications go to Kepler Communications directly.