About the RoleSelling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us - security and compliance are a precondition for deploying our platform, not a function beside it.
We hold SOC 2 Type 2 and ISO 27001, and we're moving toward more certifications because governing autonomous industrial systems responsibly is a commercial requirement in our market. You'll own our certification programs and the security and infrastructure underneath them - across our multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments, not customer plant-floor or control-system security.
This role is ideal for candidates who want real, ongoing ownership of a security function, including standing up and running one of the industry's first AI management systems, at a company where trust and compliance directly determine whether customers deploy the platform at all.
What You'll Do- Own the compliance calendar across SOC 2 Type 2 and ISO 27001 - evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readiness
- Triage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closure
- Remediate what you triage directly in infrastructure as code, IAM policy, and pipeline configuration
- Administer identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycle
- Support internal IT operations - endpoint fleet and device compliance, SaaS and license administration, asset inventory, support requests - while keeping the human cost of them flat as the company grows
- Serve as the working interface to external auditors, our certification body, and customer security and procurement reviews
- Build controls into infrastructure so they hold automatically, replacing manual verification with guardrails that fail closed
- Harden CI/CD and the software supply chain - build identity, artifact provenance, dependency and secret hygiene
- Debug production issues across cloud infrastructure, containers, and networking, and write the postmortem that keeps the fix from being forgotten
- Produce documentation others rely on: runbooks, control narratives, architecture notes, postmortems
Required Qualifications- Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical role - broad competence across security, networking, and operating systems, with real depth in at least one
- Deep hands-on experience with:
- Security fundamentals - trust boundaries and blast radius, authentication vs. authorization, least privilege, secrets handling, and judging real-world exploitability of findings
- Networking - diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, and proxies; comfortable with VPN/private connectivity and packet captures
- Linux operating systems - processes, filesystems, permissions, systemd, resource limits, log analysis, and how containers relate to the host
- Cloud infrastructure - hands-on with AWS or GCP beyond the console: IAM, networking, compute, and their failure modes
- Strong scripting/automation skills (Python, Bash, Go, or similar) - recurring manual work gets scripted away, not tracked by hand
- Strong writing ability: control narratives, runbooks, postmortems, audit responses, risk assessments
- Proven judgment under ambiguity - able to rank findings honestly and defend the ranking
- CS/CE degree or equivalent hands-on experience
Preferred Qualifications- Hands-on ISO 27001 experience - operating an ISMS, recertification, surveillance audits, internal audit programmes, Statement of Applicability, risk treatment
- SOC 2 experience in practice - producing evidence, answering auditor requests, remediating findings against a real deadline
- Any exposure to AI governance or ISO 42001 - AI risk assessment, model inventory, AI lifecycle controls, the EU AI Act
- Infrastructure as code at scale (Pulumi primarily, Terraform secondarily - deep Terraform experience transfers fine)
- Multi-account cloud organization experience: landing zones, org-level policy guardrails, centralized logging, cross-account access patterns
- Identity provider and endpoint management at scale (Google Workspace or Microsoft 365, SSO/SAML/OIDC, MDM and device compliance tooling)
- Cloud security tooling experience (CSPM, SAST/SCA, vulnerability management platforms), including their false-positive rates
- Container orchestration on ECS, EKS, or Kubernetes
- Observability: metrics, logs, traces, and the judgment to instrument what will matter later
- Experience across both AWS and GCP, including workload identity federation
- Cloud cost awareness - you notice when spend and value diverge
- Startup or high-growth experience building process rather than following one
What Success Looks Like- You can own ambiguous, high-stakes security and compliance problems end-to-end
- Controls you build hold automatically as the company scales - you design for guardrails that fail closed, not recurring manual verification
- You bring strong technical judgment on tradeoffs between security rigor, velocity, and cost
- You raise the bar for security rigor and operational discipline across the team
- You help define what's next for the security program, not just execute what's known