SlipstreamJobsFresh Startup & VC-Backed Jobs

Security & Infrastructure Engineer

Nexxa.ai - San Francisco, CA, USA - In-office - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Nexxa.ai is building autonomous AI systems for heavy industries—manufacturing, infrastructure, and logistics. This role owns the security and compliance foundation that enables customers to trust and deploy the platform. You will own the end-to-end security and compliance program, including SOC 2 Type 2 and ISO 27001 certifications, and drive toward additional certifications as the company scales. This is not customer plant-floor security; it covers Nexxa's corporate and cloud environments across AWS, GCP, and internal engineering platforms. Key responsibilities: - Manage the compliance calendar: evidence collection, access reviews, vendor audits, control monitoring, internal audits, policy refresh, and audit readiness for SOC 2 Type 2 and ISO 27001 - Triage and remediate security findings across cloud posture, code scanning, dependencies, and secrets - Remediate findings directly in infrastructure as code, IAM policy, and CI/CD pipeline configuration - Administer identity and access across cloud and SaaS: SSO/federation, least-privilege roles, joiner/mover/leaver lifecycle - Support internal IT operations—endpoint fleet, device compliance, SaaS administration, asset inventory—while keeping manual overhead flat as the company grows - Serve as the working interface to external auditors, certification bodies, and customer security/procurement reviews - Build controls into infrastructure so they hold automatically; design guardrails that fail closed rather than rely on manual verification - Harden CI/CD and the software supply chain: build identity, artifact provenance, dependency and secret hygiene - Debug production issues across cloud infrastructure, containers, and networking; write postmortems that prevent recurrence - Produce documentation others rely on: runbooks, control narratives, architecture notes, postmortems REQUIREMENTS: - Professional experience in security engineering, infrastructure/platform engineering, or closely related technical role with broad competence across security, networking, and operating systems, and real depth in at least one - Deep hands-on experience with: - Security fundamentals: trust boundaries, blast radius, authentication vs. authorization, least privilege, secrets handling, real-world exploitability judgment - Networking: diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, proxies; comfortable with VPN/private connectivity and packet captures - Linux operating systems: processes, filesystems, permissions, systemd, resource limits, log analysis, container relationships to host - Cloud infrastructure: hands-on AWS or GCP beyond the console—IAM, networking, compute, and failure modes - Strong scripting/automation skills (Python, Bash, Go, or similar); recurring manual work gets scripted, not tracked by hand - Strong writing ability: control narratives, runbooks, postmortems, audit responses, risk assessments - Proven judgment under ambiguity; able to rank findings honestly and defend the ranking - CS/CE degree or equivalent hands-on experience PREFERRED QUALIFICATIONS: - Hands-on ISO 27001 experience: operating an ISMS, recertification, surveillance audits, internal audit programs, Statement of Applicability, risk treatment - SOC 2 Type 2 experience in practice: producing evidence, answering auditor requests, remediating findings against real deadlines - Exposure to AI governance or ISO 42001: AI risk assessment, model inventory, AI lifecycle controls, EU AI Act - Infrastructure as code at scale (Pulumi primarily, Terraform secondarily) - Multi-account cloud organization experience: landing zones, org-level policy guardrails, centralized logging, cross-account access patterns - Identity provider and endpoint management at scale (Google Workspace or Microsoft 365, SSO/SAML/OIDC, MDM and device compliance tooling) - Cloud security tooling experience (CSPM, SAST/SCA, vulnerability management platforms) including false-positive rates - Container orchestration on ECS, EKS, or Kubernetes - Observability: metrics, logs, traces, and judgment to instrument what matters later - Experience across both AWS and GCP, including workload identity federation - Cloud cost awareness - Startup or high-growth experience building process rather than following one

Similar roles