Start Your Search Here

push notification bell

Would you like to receive notifications about jobs in Sunnyvale?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

Nexxa.ai

Sunnyvale / Global

Security & Infrastructure Engineer

Job Description

Nexxa Security And Compliance EngineerSelling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not a function beside it.We hold SOC 2 Type 2 and ISO 27001, and we're moving toward more certifications because governing autonomous industrial systems responsibly is a commercial requirement in our market. You'll own our certification programs and the security and infrastructure underneath them — across our multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments, not customer plant-floor or control-system security.This role is ideal for candidates who want real, ongoing ownership of a security function, including standing up and running one of the industry's first AI management systems, at a company where trust and compliance directly determine whether customers deploy the platform at all.ResponsibilitiesOwn the compliance calendar across SOC 2 Type 2 and ISO 27001 — evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readinessTriage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closureRemediate what you triage directly in infrastructure as code, IAM policy, and pipeline configurationAdminister identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycleSupport internal IT operations — endpoint fleet and device compliance, SaaS and license administration, asset inventory, support requests — while keeping the human cost of them flat as the company growsServe as the working interface to external auditors, our certification body, and customer security and procurement reviewsBuild controls into infrastructure so they hold automatically, replacing manual verification with guardrails that fail closedHarden CI/CD and the software supply chain — build identity, artifact provenance, dependency and secret hygieneDebug production issues across cloud infrastructure, containers, and networking, and write the postmortem that keeps the fix from being forgottenProduce documentation others rely on: runbooks, control narratives, architecture notes, postmortemsRequired QualificationsProfessional experience in security engineering, infrastructure/platform engineering, or a closely related technical role — broad competence across security, networking, and operating systems, with real depth in at least oneDeep hands-on experience with:Security fundamentals — trust boundaries and blast radius, authentication vs. authorization, least privilege, secrets handling, and judging real-world exploitability of findingsNetworking — diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, and proxies; comfortable with VPN/private connectivity and packet capturesLinux operating systems — processes, filesystems, permissions, systemd, resource limits, log analysis, and how containers relate to the hostCloud infrastructure — hands-on with AWS or GCP beyond the console: IAM, networking, compute, and their failure modesStrong scripting/automation skills (Python, Bash, Go, or similar) — recurring manual work gets scripted away, not tracked by handStrong writing ability: control narratives, runbooks, postmortems, audit responses, risk assessmentsProven judgment under ambiguity — able to rank findings honestly and defend the rankingCS/CE degree or equivalent hands-on experiencePreferred QualificationsHands-on ISO 27001 experience — operating an ISMS, recertification, surveillance audits, internal audit programmes, Statement of Applicability, risk treatmentSOC 2 experience in practice — producing evidence, answering auditor requests, remediating findings against a real deadlineAny exposure to AI governance or ISO 42001 — AI risk assessment, model inventory, AI lifecycle controls, the EU AI ActInfrastructure as code at scale (Pulumi primarily, Terraform secondarily — deep Terraform experience transfers fine)Multi-account cloud organization experience: landing zones, org-level policy guardrails, centralized logging, cross-account access patternsIdentity provider and endpoint management at scale (Google Workspace or Microsoft 365, SSO/SAML/OIDC, MDM and device compliance tooling)Cloud security tooling experience (CSPM, SAST/SCA, vulnerability management platforms), including their false-positive ratesContainer orchestration on ECS, EKS, or KubernetesObservability: metrics, logs, traces, and the judgment to instrument what will matter laterExperience across both AWS and GCP, including workload identity federationCloud cost awareness — you notice when spend and value divergeStartup or high-growth experience building process rather than following oneWhat Success Looks LikeYou can own ambiguous, high-stakes security and compliance problems end-to-endControls you build hold automatically as the company scales — you design for guardrails that fail closed, not recurring manual verificationYou bring strong technical judgment on tradeoffs between security rigor, velocity, and costYou raise the bar for security rigor and operational discipline across the teamYou help define what's next for the security program, not just execute what's knownWhy Join Nexxa.ai?Innovative Environment: Play a critical role in transforming heavy industries through groundbreaking AI and automation technologiesCollaborative Culture: Be part of a team that values innovation, discipline, and continuous improvementProfessional Growth: Benefit from significant opportunities for career development and advancementCompetitive Compensation: Enjoy a comprehensive salary and equity package reflective of your expertise and contributionsIf you're passionate about building the security and compliance backbone for advanced AI solutions in the real world, we'd love to connect.
Apply Now

Similar Opportunities

View all jobs

Get Job Alerts

Don't miss the perfect fit. Get Daily curated job alerts.

Job Title or Keyword(s)
Location