Back to jobs
Senior Container Security Engineer
re
Senior Container Security Engineer – CVE Remediation & Image Hardening
About the Role
We are looking for a hands-on Senior Container Security Engineer to lead vulnerability remediation and image hardening across Linux-based container environments.
This role focuses on deep operating system and container security engineering rather than simple vulnerability scanning. You will analyze, remediate, rebuild, harden, and continuously optimize container images used in modern cloud-native platforms. You will work closely with platform engineering, DevOps, infrastructure, and security teams to build automated remediation pipelines, reduce the attack surface, and deliver production-ready hardened images.
What You’ll Do
- Own end-to-end CVE remediation across Linux-based container images.
- Analyze vulnerabilities across OS packages, libraries, runtimes, and dependencies.
- Patch, rebuild, validate, and maintain hardened container images at scale.
- Reduce attack surface by removing unnecessary packages, binaries, services, and dependencies.
- Build and scale automated remediation pipelines for continuous image patching.
- Improve image security posture while minimizing operational disruption.
- Generate, validate, and maintain SBOMs to support supply chain visibility and compliance.
- Integrate remediation workflows into CI/CD and GitOps pipelines.
- Optimize image size, startup performance, and operational efficiency.
- Research emerging Linux, container, Kubernetes, and software supply chain threats.
- Troubleshoot complex dependency, package compatibility, and runtime security issues.
- Help define internal standards for hardened images and secure software delivery.
What You Bring
- 5+ years of experience in Linux systems engineering, platform engineering, DevSecOps, security engineering, or SRE.
- Deep understanding of Linux distributions (Debian, Ubuntu, Alpine, RHEL).
- Strong hands-on experience with Docker, Kubernetes, and containerized environments.
- Proven experience remediating CVEs within Linux packages and container ecosystems.
- Proficiency with package management systems (apt, yum/dnf, apk, rpm).
- Experience with scanning tools such as Trivy, Grype, or Clair.
- Strong scripting or programming skills in Python, Bash, or Go.
- Solid understanding of container image layering and filesystem structures.
- Familiarity with CI/CD automation and infrastructure-as-code workflows.
- Experience with cloud-native infrastructure (AWS, Azure, or GCP).
Nice to Have
- Experience building minimal or distroless container images.
- Familiarity with SBOM standards (SPDX, CycloneDX, Syft).
- Experience with image signing and verification tools (Cosign, Sigstore).
- Knowledge of software supply chain security frameworks like SLSA.
- Familiarity with Kubernetes security controls and eBPF.
What Success Looks Like
- Delivery of production-ready container images with near-zero exploitable CVEs.
- Established scalable automated remediation and image hardening pipelines.
- Significant reduction in container attack surface and image bloat.
- Improved remediation speed and operational efficiency.
- Repeatable standards for secure container image delivery at scale.
Compensation & Benefits
- Base salary: $130,000 – $200,000 depending on experience and technical depth
- Equity participation
- Comprehensive health, dental, and vision coverage
- Remote-first work environment
- Opportunity to work on cutting-edge cloud-native and container security technologies
- Career growth within a rapidly scaling cybersecurity company
Apply for this job
*
indicates a required field