We are seeking a highly skilled Network Security Engineer with deep expertise in securing Kubernetes/K3s environments, enforcing workload isolation, and minimizing blast radius across hybrid compute infrastructures. The ideal candidate will have hands-on experience with Linux security modules, TPM-based attestation, workload sandboxing, and advanced network segmentation techniques to protect multi-tenant environments.
This role focuses on hardening, isolating, and securing K3s clusters running across x86, ARM, and accelerator-based node pools. The engineer will design and implement end-to-end security controls spanning architecture, runtime security, identity enforcement, and incident response.
Responsibilities Cluster & Network Security ArchitectureDesign and implement security-first Kubernetes/K3s architectures with strong network isolation.
Harden cluster components (API server, etcd, kubelet) following CIS/NSA Kubernetes benchmarks .
Enforce Linux Mandatory Access Control (MAC) using SELinux and AppArmor across nodes and workloads.
Integrate TPM-based secure boot and attestation to ensure hardware and OS integrity.
Establish isolation frameworks including node, pod, namespace, and network segmentation .
Define and implement sandboxing strategies using seccomp, SELinux/AppArmor, gVisor, or Kata Containers.
Configure RBAC , Pod Security Standards , and Network Policies to ensure least-privilege execution.
Implement namespace and node pool partitioning to protect sensitive workloads from lateral movement.
Apply resource limits, quotas, and scheduling constraints to limit denial-of-service impact.
Integrate strong authentication and authorization models across clusters.
Implement TPM-backed secrets protection and integrate with HSM/KMS platforms.
Ensure secure workload secret distribution using Vault, SOPS, or SealedSecrets .
Enforce image signing and verification (cosign/Notary).
Integrate SBOM scanning and vulnerability management in CI/CD workflows.
Deploy runtime monitoring tools such as Falco or Cilium Tetragon .
Implement kernel-level protections including seccomp-bpf, IMA/EVM, and kernel lockdown.
Develop observability pipelines for security events , audit logs, syscalls, and TPM attestations.
Collaborate with SRE/Security teams to build breach containment & blast radius response runbooks .
Support periodic chaos/security drills and simulation-based security testing.
Strong knowledge of K3s/Kubernetes internals , cluster architecture, and security model.
Proven experience with SELinux, AppArmor, seccomp, Linux capabilities , and OS-level hardening.
Hands-on expertise with TPM technology for secure boot and remote attestation.
Deep understanding of Pod Security Standards , OPA/Gatekeeper/Kyverno policies.
Strong knowledge of NetworkPolicies , micro-segmentation, and multi-tenant isolation.
Experience with container runtimes (containerd, CRI-O, gVisor, Kata).
Solid experience in incident response, forensic data collection, and audit logging .
Proficiency with kernel security mechanisms and low-level debugging.
Contributions to Kubernetes SIG-Security or relevant Open Source projects.
Knowledge of supply chain security frameworks (SLSA, NIST 800-190).
Experience with confidential computing (TEE/SGX/SEV).
Hands-on knowledge of Falco, Tetragon, or other runtime detection tools .
Experience working with air-gapped environments or hardened distros (Flatcar, Bottlerocket).
Fully hardened K3s cluster baseline with SELinux/AppArmor profiles.
TPM-enabled secure boot and attestation workflow.
Enforced PodSecurityStandards and workload sandboxing.
Documented cluster isolation strategies (network, namespace, node pools).
Audit-ready artifacts demonstrating CIS/NSA Kubernetes compliance.
Runbooks for containment, isolation, and blast radius reduction.
...expertise across the application lifecycle. Department: IT Application, Development, and Delivery Reports To: Senior Software Engineer / Application Development Asst. Director We are looking for a talented and experienced Software Engineer II with a strong...
...Pro Source Security Solution, LLC #C15813901 in Irving, TX is looking for a commissioned security officer to join our strong team. Our... ...firearm. ~ Also must have a flexible work availability. ( Days, Nights, Weekends, Holidays) We are looking forward to hearing from...
...Full Time None $37.00 - $41.00 Hourly Up to 25% Any Transportation Description Job Title: CLASS A CDL HAZMAT Driver Reports To: Branch Operations Manager Location: Eastern Washington / Idaho FLSA Status: Non - Exempt About Us:...
...About the Job: Basic Purpose: Mobile Examiner's primary responsibility is to provide coverage in the field ensuring that mobile... ...the lab indicated on work orders. Must have 1-year minimum experience performing phlebotomy. Must have reliable. transportation...
Clean Harbors in **San Jose, CA** is seeking a **Class A CDL Driver** to operate a variety of heavy and light duty trucks/work equipment... ...**Required Qualifications:**+ Valid Class A CDL+ Possess Hazmat endorsement+ Obtain Tanker endorsement within 90 days of employment...