Network Security Engineer Job at Openkyber, Georgia

V1VwT0EyVWtRNWJoSGZWb3oxTldrb3Vpb3c9PQ==
  • Openkyber
  • Georgia

Job Description

Job Title: Network Security Engineer Overview

We are seeking a highly skilled Network Security Engineer with deep expertise in securing Kubernetes/K3s environments, enforcing workload isolation, and minimizing blast radius across hybrid compute infrastructures. The ideal candidate will have hands-on experience with Linux security modules, TPM-based attestation, workload sandboxing, and advanced network segmentation techniques to protect multi-tenant environments.

This role focuses on hardening, isolating, and securing K3s clusters running across x86, ARM, and accelerator-based node pools. The engineer will design and implement end-to-end security controls spanning architecture, runtime security, identity enforcement, and incident response.

Responsibilities Cluster & Network Security Architecture
  • Design and implement security-first Kubernetes/K3s architectures with strong network isolation.

  • Harden cluster components (API server, etcd, kubelet) following CIS/NSA Kubernetes benchmarks .

  • Enforce Linux Mandatory Access Control (MAC) using SELinux and AppArmor across nodes and workloads.

  • Integrate TPM-based secure boot and attestation to ensure hardware and OS integrity.

  • Establish isolation frameworks including node, pod, namespace, and network segmentation .

Blast Radius Reduction & Least Privilege Enforcement
  • Define and implement sandboxing strategies using seccomp, SELinux/AppArmor, gVisor, or Kata Containers.

  • Configure RBAC , Pod Security Standards , and Network Policies to ensure least-privilege execution.

  • Implement namespace and node pool partitioning to protect sensitive workloads from lateral movement.

  • Apply resource limits, quotas, and scheduling constraints to limit denial-of-service impact.

Identity, Secrets & Cryptographic Security
  • Integrate strong authentication and authorization models across clusters.

  • Implement TPM-backed secrets protection and integrate with HSM/KMS platforms.

  • Ensure secure workload secret distribution using Vault, SOPS, or SealedSecrets .

Runtime & Supply Chain Security
  • Enforce image signing and verification (cosign/Notary).

  • Integrate SBOM scanning and vulnerability management in CI/CD workflows.

  • Deploy runtime monitoring tools such as Falco or Cilium Tetragon .

  • Implement kernel-level protections including seccomp-bpf, IMA/EVM, and kernel lockdown.

Monitoring, Logging & Incident Response
  • Develop observability pipelines for security events , audit logs, syscalls, and TPM attestations.

  • Collaborate with SRE/Security teams to build breach containment & blast radius response runbooks .

  • Support periodic chaos/security drills and simulation-based security testing.

Required Skills & Experience
  • Strong knowledge of K3s/Kubernetes internals , cluster architecture, and security model.

  • Proven experience with SELinux, AppArmor, seccomp, Linux capabilities , and OS-level hardening.

  • Hands-on expertise with TPM technology for secure boot and remote attestation.

  • Deep understanding of Pod Security Standards , OPA/Gatekeeper/Kyverno policies.

  • Strong knowledge of NetworkPolicies , micro-segmentation, and multi-tenant isolation.

  • Experience with container runtimes (containerd, CRI-O, gVisor, Kata).

  • Solid experience in incident response, forensic data collection, and audit logging .

  • Proficiency with kernel security mechanisms and low-level debugging.

Nice to Have
  • Contributions to Kubernetes SIG-Security or relevant Open Source projects.

  • Knowledge of supply chain security frameworks (SLSA, NIST 800-190).

  • Experience with confidential computing (TEE/SGX/SEV).

  • Hands-on knowledge of Falco, Tetragon, or other runtime detection tools .

  • Experience working with air-gapped environments or hardened distros (Flatcar, Bottlerocket).

Deliverables
  • Fully hardened K3s cluster baseline with SELinux/AppArmor profiles.

  • TPM-enabled secure boot and attestation workflow.

  • Enforced PodSecurityStandards and workload sandboxing.

  • Documented cluster isolation strategies (network, namespace, node pools).

  • Audit-ready artifacts demonstrating CIS/NSA Kubernetes compliance.

  • Runbooks for containment, isolation, and blast radius reduction.

Job Tags

Remote work,

Similar Jobs

Johns Hopkins Medicine

Software Engineer II - Full Stack Developer (Appian) Job at Johns Hopkins Medicine

 ...expertise across the application lifecycle. Department: IT Application, Development, and Delivery Reports To: Senior Software Engineer / Application Development Asst. Director We are looking for a talented and experienced Software Engineer II with a strong... 

PRO SOURCE SECURITY SOLUTION, LLC

Commissioned Security Officer Job at PRO SOURCE SECURITY SOLUTION, LLC

 ...Pro Source Security Solution, LLC #C15813901 in Irving, TX is looking for a commissioned security officer to join our strong team. Our...  ...firearm. ~ Also must have a flexible work availability. ( Days, Nights, Weekends, Holidays) We are looking forward to hearing from... 

Tyree

Class A CDL Hazmat Driver Job at Tyree

 ...Full Time None $37.00 - $41.00 Hourly Up to 25% Any Transportation Description Job Title: CLASS A CDL HAZMAT Driver Reports To: Branch Operations Manager Location: Eastern Washington / Idaho FLSA Status: Non - Exempt About Us:... 

Quest Diagnostics

Skilled Mobile Phlebotomist Job at Quest Diagnostics

 ...About the Job: Basic Purpose: Mobile Examiner's primary responsibility is to provide coverage in the field ensuring that mobile...  ...the lab indicated on work orders. Must have 1-year minimum experience performing phlebotomy. Must have reliable. transportation... 

Clean Harbors

Class A Hazmat Truck Driver - Healthcare (Hazmat endorsement REQUIRED) Job at Clean Harbors

Clean Harbors in **San Jose, CA** is seeking a **Class A CDL Driver** to operate a variety of heavy and light duty trucks/work equipment...  ...**Required Qualifications:**+ Valid Class A CDL+ Possess Hazmat endorsement+ Obtain Tanker endorsement within 90 days of employment...