577,120open jobs
24,628companies
79,541added this week
Browse all
Salary
$129k – $287k per year (Estimated)
Location
Remote/Hybrid (San Francisco, United States)
Employment
Full-Time
Overview
Company
Impact
Profile match

Nexxa is building the best AI systems for heavy industries - enabling machines, systems, and operations to think, decide, and act autonomously across manufacturing, large-scale infrastructure, logistics, and legacy environments.

Our mission is to translate deep technical breakthroughs into operational reality, solving some of the hardest systems-level problems in industry.

About the Role

Selling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us - security and compliance are a precondition for deploying our platform, not a function beside it.

We hold SOC 2 Type 2 and ISO 27001, and we're moving toward more certifications because governing autonomous industrial systems responsibly is a commercial requirement in our market. You'll own our certification programs and the security and infrastructure underneath them - across our multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments, not customer plant-floor or control-system security.

This role is ideal for candidates who want real, ongoing ownership of a security function, including standing up and running one of the industry's first AI management systems, at a company where trust and compliance directly determine whether customers deploy the platform at all.

What You'll Do

  • Own the compliance calendar across SOC 2 Type 2 and ISO 27001 - evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readiness

  • Triage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closure

  • Remediate what you triage directly in infrastructure as code, IAM policy, and pipeline configuration

  • Administer identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycle

  • Support internal IT operations - endpoint fleet and device compliance, SaaS and license administration, asset inventory, support requests - while keeping the human cost of them flat as the company grows

  • Serve as the working interface to external auditors, our certification body, and customer security and procurement reviews

  • Build controls into infrastructure so they hold automatically, replacing manual verification with guardrails that fail closed

  • Harden CI/CD and the software supply chain - build identity, artifact provenance, dependency and secret hygiene

  • Debug production issues across cloud infrastructure, containers, and networking, and write the postmortem that keeps the fix from being forgotten

  • Produce documentation others rely on: runbooks, control narratives, architecture notes, postmortems

Required Qualifications

  • Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical role - broad competence across security, networking, and operating systems, with real depth in at least one

  • Deep hands-on experience with:

    • Security fundamentals - trust boundaries and blast radius, authentication vs. authorization, least privilege, secrets handling, and judging real-world exploitability of findings

    • Networking - diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, and proxies; comfortable with VPN/private connectivity and packet captures

    • Linux operating systems - processes, filesystems, permissions, systemd, resource limits, log analysis, and how containers relate to the host

    • Cloud infrastructure - hands-on with AWS or GCP beyond the console: IAM, networking, compute, and their failure modes

  • Strong scripting/automation skills (Python, Bash, Go, or similar) - recurring manual work gets scripted away, not tracked by hand

  • Strong writing ability: control narratives, runbooks, postmortems, audit responses, risk assessments

  • Proven judgment under ambiguity - able to rank findings honestly and defend the ranking

  • CS/CE degree or equivalent hands-on experience

Preferred Qualifications

  • Hands-on ISO 27001 experience - operating an ISMS, recertification, surveillance audits, internal audit programmes, Statement of Applicability, risk treatment

  • SOC 2 experience in practice - producing evidence, answering auditor requests, remediating findings against a real deadline

  • Any exposure to AI governance or ISO 42001 - AI risk assessment, model inventory, AI lifecycle controls, the EU AI Act

  • Infrastructure as code at scale (Pulumi primarily, Terraform secondarily - deep Terraform experience transfers fine)

  • Multi-account cloud organization experience: landing zones, org-level policy guardrails, centralized logging, cross-account access patterns

  • Identity provider and endpoint management at scale (Google Workspace or Microsoft 365, SSO/SAML/OIDC, MDM and device compliance tooling)

  • Cloud security tooling experience (CSPM, SAST/SCA, vulnerability management platforms), including their false-positive rates

  • Container orchestration on ECS, EKS, or Kubernetes

  • Observability: metrics, logs, traces, and the judgment to instrument what will matter later

  • Experience across both AWS and GCP, including workload identity federation

  • Cloud cost awareness - you notice when spend and value diverge

  • Startup or high-growth experience building process rather than following one

What Success Looks Like

  • You can own ambiguous, high-stakes security and compliance problems end-to-end

  • Controls you build hold automatically as the company scales - you design for guardrails that fail closed, not recurring manual verification

  • You bring strong technical judgment on tradeoffs between security rigor, velocity, and cost

  • You raise the bar for security rigor and operational discipline across the team

  • You help define what's next for the security program, not just execute what's known

Why Join Nexxa.ai?

  • Innovative Environment: Play a critical role in transforming heavy industries through groundbreaking AI and automation technologies

  • Collaborative Culture: Be part of a team that values innovation, discipline, and continuous improvement

  • Professional Growth: Benefit from significant opportunities for career development and advancement

  • Competitive Compensation: Enjoy a comprehensive salary and equity package reflective of your expertise and contributions

If you're passionate about building the security and compliance backbone for advanced AI solutions in the real world, we'd love to connect.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
577,120 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
$28k – $66k per year (Estimated) • In office • 4+ years exp • Bengaluru
Python
Go
Rust
DevOps
GCP
AWS
Incident Management
Apply
$122k – $354k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Edinburgh
Python
Go
JavaScript
Java
TypeScript
Java
Spring Boot
Frontend
Angular
DevOps
Helm
Docker
Kubernetes
Management
Agile
Scrum
Apply
$65k – $156k per year (Estimated) • In office • Full-Time • Master's Degree • Edinburgh
Python
MATLAB
MATLAB
Simulink
Apply
$25k – $63k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • High School Diploma • Hanoi • Ho Chi Minh City
DevOps
GCP
Apply
$15k per year • In office • Yekaterinburg
Python
SQL
Python
FastAPI
Django
DevOps
Git
Apply
Product Team 1 day ago
$122k – $273k per year (Estimated) • Remote/Hybrid • Full-Time • San Francisco
Design
Figma
Apply
$88k – $243k per year (Estimated) • Equity • Remote • Full-Time • Toronto
Python
Bash
AI/ML
EU AI Act
ISO 42001
DevOps
Terraform
GCP
Pulumi
CI/CD
AWS
Kubernetes
Platform Engineering
Amazon EKS
IAM
Amazon ECS
Cybersecurity
ISO 27001
SOC 2
Least Privilege
Management
Google Workspace
Apply
Staff DevOps Engineer 15 days ago
$140k – $266k per year (Estimated) • Equity • Remote • Full-Time • 6+ years exp • Toronto
Python
Go
Databases
Snowflake
Databricks
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Feature Store
DevOps
Terraform
GCP
GitHub Actions
OpenTelemetry
CircleCI
Datadog
Prometheus
Pulumi
GitLab CI
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Grafana
Platform Engineering
Service Mesh
Incident Management
Cybersecurity
SOC 2
Zero Trust
Apply
Staff DevOps Engineer 15 days ago
$143k – $262k per year (Estimated) • Equity • Remote • Full-Time • 6+ years exp
Python
Go
Databases
Snowflake
Databricks
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Feature Store
DevOps
Terraform
GCP
GitHub Actions
OpenTelemetry
CircleCI
Datadog
Prometheus
Pulumi
GitLab CI
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Grafana
Platform Engineering
Service Mesh
Incident Management
Cybersecurity
SOC 2
Zero Trust
Apply
$64k – $171k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • Toronto
Python
AI/ML
Weights & Biases
Function Calling
AI Agents
Arize Phoenix
DeepEval
Langfuse
LangSmith
Promptfoo
LLM
RAG
Hallucination
Human-in-the-Loop
LLM Evaluation
DevOps
CI/CD
Apply
$106k – $130k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • San Francisco • Chicago • Scottsdale
DevOps
GCP
Azure
CI/CD
AWS
Harbor
Platform Engineering
Incident Management
Apply
$186k – $345k per year (Estimated) • In office • Full-Time • 12+ years exp • Master's Degree • San Francisco
DevOps
Incident Management
Apply
$160k – $236k per year • Equity • Remote/Hybrid • Full-Time • 2+ years exp • Chicago • Austin • San Francisco
Apply
$63k – $122k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Chicago • San Francisco • Dallas • Boston • Philadelphia
Python
JavaScript
Java
TypeScript
SQL
C++
AI/ML
Prompt Engineering
Function Calling
AI Agents
LLM
Anthropic
Agentic Workflows
Tool Use
Frontend
Angular
React.js
DevOps
GCP
Azure
AWS
GitHub
Cybersecurity
Threat Modeling
Apply
In office • Full-Time • 12+ years exp • Associate's Degree • Atlanta • Milwaukee • Dallas • Columbus • Kirkland
Python
C++
AI/ML
Synthetic Data
Physical AI
Robotics
ROS
Gazebo
Isaac Sim
SLAM
Sensor Fusion
Motion Planning
Imitation Learning
Digital Twin
IoT
MQTT
OPC UA
Apply
See all jobs
This is one of many
577,120 more open roles from verified company boards, updated every day.