Location: Remote · Duration: 3–6 months · Full-time offer on performance
What you'll do
- Work on our Kubernetes security scanning product
- Deep dive into managed security products like Guardduty, Inspector, SecurityHub, Cloud Armour, and more.
- Train on DevOps stack.
- Run and interpret cluster security scans — CIS benchmarks, kube-bench, image CVEs
- Write and test policy-as-code with Kyverno / OPA
- Help harden client cloud accounts: IAM, network boundaries, secrets management
- Turn scan noise into findings a client can actually act on
What we're looking for
- Solid grasp of security fundamentals — authn/authz, TLS, least privilege
- Familiarity with Linux and containers
- Can read YAML without flinching; scripting in Python
- Curious about how systems fail, not just how they run
Bonus
CTF experience, security certifications in progress, CVE write-ups, or supply-chain security interest (Sigstore, SBOMs, image signing).