21 день назад
Kubernetes and Container Platform Security Specialist (Kubernetes)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Kubernetes and Container Platform Security Specialist (Kubernetes): Defining and verifying the security standard for a multi-tenant Kubernetes and container platform with an accent on tenant isolation, GPU security, supply chain integrity, and policy enforcement. Focus on designing hardening and network security models, specifying runtime detection and attack simulations, and turning ecosystem research into actionable remediation and compliance evidence.
Location: Helsinki, Finland or London, United Kingdom. Hybrid work requires three days per week from the Helsinki or London office.
Company
is building a full-stack AI cloud spanning data centers, hardware, and a cloud platform for AI teams.
What you will do
- Own the security design of the Kubernetes offering, container registry, registry credentials, image provenance, signing, and admission verification.
- Define tenant isolation across shared Kubernetes infrastructure, including namespace, node, cluster, kubelet, and API server boundaries.
- Set security requirements for GPU infrastructure, device plugins, privileged workloads, and partitioning boundaries.
- Define Kubernetes hardening, policy-as-code, admission enforcement, container runtime, etcd, secrets, and network security standards.
- Specify runtime detection and attack simulation requirements, assess advisories, research new ecosystem technologies, and prioritize remediation.
- Support compliance through technical evidence and audit work while influencing platform engineers without directly managing them.
Requirements
- Strong production experience with Kubernetes and Linux.
- Direct experience securing multi-tenant Kubernetes environments with shared clusters and untrusted workloads.
- Deep knowledge of Kubernetes architecture, container runtimes, container security, image security, and Kubernetes networking.
- Practical experience with policy-as-code, admission control, signing, provenance, SBOMs, and software supply chain security.
- Ability to define standards, verify implementation conformance, conduct research, build proofs of concept, and influence engineering teams.
- Full-time permanent employment with hybrid attendance in Helsinki or London is required.
Nice to have
- GPU infrastructure, multi-tenant container registries, eBPF observability or runtime security, and cluster lifecycle tooling.
- CVE analysis, advisory triage, or upstream contributions in the Kubernetes or CNCF ecosystem.
- Experience with confidential computing, attested execution environments, or infrastructure products certified to ISO 27001, SOC 2, or C5.
Culture & Benefits
- Cash and equity compensation with healthcare, lunch, wellbeing, and other benefits.
- Work alongside engineers, researchers, and partners across the AI ecosystem.
- International environment with more than 40 nationalities.
- Profitable operations with rapid, sustained growth.
Hiring process
- Applications are submitted through the Careers page; applications by email are not accepted.
- Hiring proceeds without an artificial deadline and moves forward when a suitable candidate is identified.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Engineering Manager (Application Security)
103 958 - 124 750GBP
7 дней назад
Cybersecurity Engineer - Cloud
6 дней назад
Security Technical Risk Advisor 1 (Cyber Security)
7 дней назад
VP of Security & Infrastructure (FemTech)
200 000 - 220 000GBP
6 дней назад
Senior Software Engineer, PKI & Cryptographic Systems (Cryptography)
66 000 - 83 000€
6 дней назад