The Basics
The Cloud Cybersecurity Engineer (K8) will collaborate with Detection, Security, and Software Engineers to actively oversee and constantly evaluate and enhance the cybersecurity of Tanium Cloud's services operatingon Kubernetes.You will be an integral part of the Tanium Cloudsecurityengineering processes, responsible forthe design, implementation, and operation of preventative and detectivesecuritycontrols toidentify, assess, and counter risks and threats beforeimpactingTanium Cloud.
What you'll do
- Establish Tanium Cloud's Kubernetes Continuous Monitoring on both Azure and AWS to apply custom security standards and controls with DevOps practices.
- Consistently review and improve the Kubernetes security baseline design and performance via coding, testing processes, and automation.
- Create a sustained initiative to identify, evaluate, and detail exploitable configurations, vulnerabilities, and potential risks within our cloud and container builds and systems using SecDataOps.
- Stay up-to-date with the latest security threats, vulnerabilities, and industry trends to proactively enhance security detection measures.
- Work alongside engineering, IT, and security teams to create and enhance our security standards with solutions that are both scalable and adaptable.
- Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work.
- Be on periodic on-call for triage of critical alerts from detections and systems.
We’re looking for someone with
- Education
- Bachelor's degree or equivalent experience in DevSecOps, CyberSecurity, or related technical field preferred
- Cloud Security Engineering Experience:
- 3-5 years of experience implementing security baselines and performing ongoing assessments of security controls for public cloud systems (e.g. AWS, Azure) within a DevOps environment.
- 3+ years of hands-on experience in building tailored security controls, policies, baselines, and vulnerability assessments for Kubernetes environments for customer-facing, sensitive container workloads, preferably on AKS and EKS.
- Reducing common and unique Kubernetes and container vulnerabilities, such as misconfigurations, insecure container runtimes, and supply chain attacks with engineering and security teams.
- Develop and build custom hardened base images for Docker and cloud as part of secure supply chain with CI/CD tooling.
- Understand the difference between a CVSS base scoring and custom scoring to prioritize exploitable vulnerability patching and mitigations with engineering teams.
- Experience in using security query or analytic tools for security data analysis, such as SQL, KQL, or SPL.
- Experience with tailoring and implementing industry security and risk standards (e.g. CIS Benchmarks, ISO 27001, FedRAMP Moderate) for sensitive data workloads.
- Engineering Experience:
- Utilize robust analytical and problem-solving capabilities to confirm our hypotheses using precise data and in-depth root cause investigation.
- Experience using high-level programming languages (Go, Python) to produce detection-as-code, tools, and automations.
- Experience managing cloud infrastructure as infrastructure-as-code (e.g. Terraform, CloudFormation, ARM, Pulumi).
- Deliver high quality PRs daily using modern software engineering development and automation tools like Git and CI/CD pipelines (i.e. Jenkins, GitHub Actions).
- Other :
- Must be able to obtain Canadian Reliability status (RS) for Protected A, B, C at a minimum
- Deliver quality and velocity of contributions using DevOps principles
- Believes in the power of test and process automation
- Proven ability to work effectively in cross-functional engineering teams
- Experienced engineer who can put out fires under pressure when things go wrong in production environments and address the root causes of those fires for the future
- Have a customer-centric work approach to drive positive experiences for their customers
About Tanium
Tanium delivers the industry's only true real-time cloud-based endpoint management and security offering. Its converged endpoint management (XEM) platform is real-time, seamless, and autonomous, allowing security-conscious organizations to break down silos between IT and Security operations that results in reduced complexity, cost, and risk. Securing more than 32M endpoints around the world, Tanium's customers include Fortune 100 organizations, top US retailers, top US commercial banks, and branches of the U.S. Military. It also partners with the world's biggest technology companies, system integrators, and managed service providers to help customers realize the full potential of their IT investments. Tanium has been named to the Forbes Cloud 100 list for nine consecutive years and ranks on the Fortune 100 Best Companies to Work For. For more information on The Power of Certainty™, visitwww.tanium.comand follow us onLinkedIn andX.
On a mission. Together.
At Tanium, we are stewards of a culture that emphasizes the importance of collaboration, respect, and diversity. In our pursuit of revolutionizing the way some of the largest enterprises and governments in the world solve their most difficult IT challenges, we are strengthened by our unique perspectives and by our collective actions.
We are an organization with stakeholders around the world and it’s imperative that the diversity of our customers and communities is reflected internally in our team members. We strive to create a diverse and inclusive environment where everyone feels they have opportunities to succeed and grow because we know that only together can we do great things.
Each of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.
What you’ll get
The annual base salary range for this full-time position is C$95,000 to C$280,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
For more information on how Tanium processes your personal data, please see our Privacy Policy