We are seeking a highly skilled Network Security Engineer with deep expertise in securing Kubernetes/K3s environments, enforcing workload isolation, and minimizing blast radius across hybrid compute infrastructures. The ideal candidate will have hands-on experience with Linux security modules, TPM-based attestation, workload sandboxing, and advanced network segmentation techniques to protect multi-tenant environments.
This role focuses on hardening, isolating, and securing K3s clusters running across x86, ARM, and accelerator-based node pools. The engineer will design and implement end-to-end security controls spanning architecture, runtime security, identity enforcement, and incident response.
Responsibilities Cluster & Network Security ArchitectureDesign and implement security-first Kubernetes/K3s architectures with strong network isolation.
Harden cluster components (API server, etcd, kubelet) following CIS/NSA Kubernetes benchmarks .
Enforce Linux Mandatory Access Control (MAC) using SELinux and AppArmor across nodes and workloads.
Integrate TPM-based secure boot and attestation to ensure hardware and OS integrity.
Establish isolation frameworks including node, pod, namespace, and network segmentation .
Define and implement sandboxing strategies using seccomp, SELinux/AppArmor, gVisor, or Kata Containers.
Configure RBAC , Pod Security Standards , and Network Policies to ensure least-privilege execution.
Implement namespace and node pool partitioning to protect sensitive workloads from lateral movement.
Apply resource limits, quotas, and scheduling constraints to limit denial-of-service impact.
Integrate strong authentication and authorization models across clusters.
Implement TPM-backed secrets protection and integrate with HSM/KMS platforms.
Ensure secure workload secret distribution using Vault, SOPS, or SealedSecrets .
Enforce image signing and verification (cosign/Notary).
Integrate SBOM scanning and vulnerability management in CI/CD workflows.
Deploy runtime monitoring tools such as Falco or Cilium Tetragon .
Implement kernel-level protections including seccomp-bpf, IMA/EVM, and kernel lockdown.
Develop observability pipelines for security events , audit logs, syscalls, and TPM attestations.
Collaborate with SRE/Security teams to build breach containment & blast radius response runbooks .
Support periodic chaos/security drills and simulation-based security testing.
Strong knowledge of K3s/Kubernetes internals , cluster architecture, and security model.
Proven experience with SELinux, AppArmor, seccomp, Linux capabilities , and OS-level hardening.
Hands-on expertise with TPM technology for secure boot and remote attestation.
Deep understanding of Pod Security Standards , OPA/Gatekeeper/Kyverno policies.
Strong knowledge of NetworkPolicies , micro-segmentation, and multi-tenant isolation.
Experience with container runtimes (containerd, CRI-O, gVisor, Kata).
Solid experience in incident response, forensic data collection, and audit logging .
Proficiency with kernel security mechanisms and low-level debugging.
Contributions to Kubernetes SIG-Security or relevant Open Source projects.
Knowledge of supply chain security frameworks (SLSA, NIST 800-190).
Experience with confidential computing (TEE/SGX/SEV).
Hands-on knowledge of Falco, Tetragon, or other runtime detection tools .
Experience working with air-gapped environments or hardened distros (Flatcar, Bottlerocket).
Fully hardened K3s cluster baseline with SELinux/AppArmor profiles.
TPM-enabled secure boot and attestation workflow.
Enforced PodSecurityStandards and workload sandboxing.
Documented cluster isolation strategies (network, namespace, node pools).
Audit-ready artifacts demonstrating CIS/NSA Kubernetes compliance.
Runbooks for containment, isolation, and blast radius reduction.
...detail, then this is the office for you. We are not your typical dental office. All our team members are here for the long term. This... ...initiative. Proactive attitude. Enjoys working as a dental assistant. Honesty/Integrity (what you do when no one is looking)....
...About Piccadilly Market: Piccadilly Market is the evolution of the neighborhood store connecting food and beverage artisans directly with local residents... ...people together, one visit at a time. The Role: Were looking for a Part-Time Wine Buyer to help curate...
Maxim Healthcare is seeking a Registered Nurse (RN) to work one on one with a patient in the school setting. Salary: $38 - $44 / hr Why Join Maxim: + Competitive Pay & Weekly Paychecks+ Health, Dental, Vision, HSA and Life Insurance+ Paid Time Off + 401(k) Savings...
...industrial, commercial, retail, hospitality, healthcare, and forensic/litigation support. Built on decades of experience, we provide... ...design to civil, structural, mechanical, electrical, and plumbing engineering, as well as construction administration and forensic...
...Summary The position is for a Research Assistant I to provide responsible assistance for establishment and propagation of organoid cultures as part of the Baylor College of Medicine 3D Organoid Core. This job is suitable for someone who can handle multiple projects...