← Back to jobs

Redolent  Inc Logo
K3s Security Engineer

Redolent Inc

 

Portland, Oregon, USA

Posted On: 1 day ago
Experience: 5+ years
Availability: Onsite
Openings: 1
Category: Security Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

You will own the security posture and hardening of K3s environments.

This role is on-site.

Responsibilities

  • Design and implement security-first cluster configurations for K3s nodes.
  • Enforce mandatory access control (MAC) using SELinux and AppArmor profiles across pods and system services.
  • Integrate TPM-based attestation and secure boot processes for cluster nodes.
  • Define and enforce workload sandboxing strategies using SecComp, AppArmor, and SELinux contexts.
  • Monitor workloads for runtime anomalies and build observability hooks for security events.

Required Skills

  • Strong knowledge of K3s/Kubernetes internals, particularly security features.
  • Hands-on experience with SELinux, AppArmor, seccomp, and Linux capabilities.
  • Experience with TPM (Trusted Platform Module) for secure boot and attestation.
  • Deep understanding of Pod Security Standards, OPA/Gatekeeper/Kyverno.
  • Experience implementing RBAC, NetworkPolicies, and workload isolation at scale.
  • Proficiency in Linux kernel security mechanisms and debugging.
  • Familiarity with container runtimes (containerd, CRI-O, gVisor, Kata) and their security implications.
  • Strong background in incident response, forensic data collection, and audit logging in Kubernetes.
  • Experience integrating SBOM scanning and vulnerability management into CI/CD pipelines.

Preferred Skills

  • Experience with supply chain security frameworks (SLSA, NIST 800-190).
  • Hands-on with Falco or other runtime security tools.

Education

Any Gradute

Related Jobs

No related jobs found

← Back to jobs