Security Engineer (K3s Security & Isolation Specialist)

Posted 12 Days Ago
Easy Apply
Be an Early Applicant
Hillsboro, OR
In-Office
Senior level
Artificial Intelligence • Information Technology • Consulting
Talent Solutions for the AI Era
The Role
The Security Engineer will harden and isolate K3s clusters, enforce security policies, implement TPM, monitor incidents, and ensure secure workload management.
Summary Generated by Built In

The Security Engineer will focus on hardening and isolating K3s clusters to minimize blast radius in the event of compromise. This includes enforcing Linux security modules (SELinux, AppArmor), leveraging TPM for secure boot and attestation, implementing least privilege across nodes and workloads, and ensuring multi-tenant isolation within hybrid Kubernetes environments (x86, ARM, accelerators).


Responsibilities

Security Architecture & Policy Enforcement

  • Design and implement security-first cluster configurations for K3s nodes.
  • Enforce mandatory access control (MAC) using SELinux and AppArmor profiles for pods and system services.
  • Integrate TPM-based attestation and secure boot for cluster nodes to ensure trust in hardware and OS integrity.
  • Establish node, pod, and namespace isolation strategies to reduce lateral movement risk.
  • Harden cluster components (API server, etcd, kubelet) following CIS and NSA Kubernetes security benchmarks.

Blast Radius Reduction

  • Define and enforce workload sandboxing strategies (seccomp, AppArmor, SELinux contexts, gVisor/Kata if applicable).
  • Configure minimal privilege policies (RBAC, PodSecurityStandards, NetworkPolicies) to ensure least-privilege execution.
  • Implement namespace, node pool, and hardware partitioning to confine workloads and protect sensitive applications.
  • Apply resource quotas, limits, and scheduling constraints to contain denial-of-service blast radius.

Integration with Identity & Secrets Management

  • Work with Security team to ensure strong identity, authentication, and authorization models.
  • Integrate TPM-backed secrets storage and HSM/KMS systems for cryptographic operations.
  • Ensure secure distribution of workload secrets with solutions like SealedSecrets, HashiCorp Vault, or SOPS.

Runtime & Supply Chain Security

  • Enforce image signing and verification with cosign or Notary.
  • Integrate SBOM scanning and vulnerability management into CI/CD pipelines.
  • Monitor workloads for runtime anomalies (Falco, Cilium Tetragon, or equivalent).
  • Apply kernel hardening measures (seccomp-bpf, kernel lockdown, IMA/EVM with TPM).

Monitoring & Incident Response

  • Build observability hooks for security events (audit logs, syscall monitoring, TPM attestations).
  • Define blast radius response runbooks for compromised pods or nodes.
  • Work with SRE and Security teams to test chaos/security drills simulating breaches.

Deliverables

  • K3s cluster baseline hardened with SELinux and AppArmor profiles.
  • TPM-enabled secure boot and node attestation pipeline.
  • Enforced PodSecurityStandards and workload sandboxing (seccomp, gVisor/Kata optional).
  • Documentation of isolation strategies (namespaces, node pools, network segmentation).
  • Audit-ready evidence of compliance with CIS/NSA Kubernetes security benchmarks.
  • Security runbooks for containment and blast radius reduction.

Required Skills & Experience

  • Strong knowledge of K3s/Kubernetes internals, especially security features.
  • Hands-on experience with SELinux, AppArmor, seccomp, and Linux capabilities.
  • Experience with TPM (Trusted Platform Module) for secure boot and attestation.
  • Deep understanding of Pod Security (PodSecurityPolicies/Standards, OPA/Gatekeeper/Kyverno).
  • Experience implementing RBAC, NetworkPolicies, and workload isolation at scale.
  • Proficiency in Linux kernel security mechanisms and debugging.
  • Familiarity with container runtimes (containerd, CRI-O, gVisor, Kata) and their security implications.
  • Strong background in incident response, forensic data collection, and audit logging in Kubernetes.

Nice to Have

  • Contributions to Kubernetes SIG-Security or open-source security tooling.
  • Experience with supply chain security frameworks (SLSA, NIST 800-190).
  • Familiarity with confidential computing (TEE/SGX/SEV) for workload isolation.
  • Hands-on with Cilium Tetragon, Falco, or other runtime security tools.
  • Knowledge of air-gapped deployments and hardened Linux distributions (e.g., Flatcar, Bottlerocket).

Top Skills

Apparmor
Cilium Tetragon
Containerd
Cri-O
Falco
Gvisor
K3S
Kata
Kubernetes
Linux
Networkpolicies
Rbac
Seccomp
Selinux
Tpm
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Livermore, CA
9 Employees
Year Founded: 2025

What We Do

We provide Talent Solutions for the AI Era. Our mission is to connect businesses with exceptional talent and consulting solutions that align with your company’s culture and values. We offer AI consulting services to enable businesses in leveraging cutting-edge artificial intelligence. We help discover, design and deploy AI solutions that streamline operations, boost productivity, and unlock new growth opportunities. Our team of AI experts, strategists, and technology specialists work closely with organizations to integrate AI-driven solutions that align with their unique goals and challenges. From automation and data analytics to predictive modeling and AI-based customer experiences, we provide end-to-end support for businesses embarking on their AI transformation journey.

Similar Jobs

Mondelēz International Logo Mondelēz International

Project Engineer

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
5 Locations
90000 Employees
106K-146K Annually

CrowdStrike Logo CrowdStrike

Sr. Threat Hunting Intelligence Analyst (Remote, West Coast)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
11 Locations
10000 Employees
100K-155K Annually

Imprivata Logo Imprivata

Senior Deal Desk Analyst

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
3 Locations
1372 Employees
112K-143K Annually

PwC Logo PwC

Software Engineer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
67 Locations
370000 Employees
77K-202K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
10 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees
Idler Thumbnail
Artificial Intelligence
San Francisco, California
6 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account