Cloud Cybersecurity Engineer (CCS)

Tanium

Tanium

Canada · Remote
Posted on Thursday, August 8, 2024

The Basics

The Cloud Cybersecurity Engineer (K8) will collaborate with Detection, Security, and Software Engineers to actively oversee and constantly evaluate and enhance the cybersecurity of Tanium Cloud's services operating on Kubernetes. You will be an integral part of the Tanium Cloud security engineering processes, responsible for the design, implementation, and operation of preventative and detective security controls to identify, assess, and counter risks and threats before impacting Tanium Cloud.

What you'll do

  • Establish Tanium Cloud's Kubernetes Continuous Monitoring on both Azure and AWS to apply custom security standards and controls with DevOps practices.
  • Consistently review and improve the Kubernetes security baseline design and performance via coding, testing processes, and automation.
  • Create a sustained initiative to identify, evaluate, and detail exploitable configurations, vulnerabilities, and potential risks within our cloud and container builds and systems using SecDataOps.
  • Stay up-to-date with the latest security threats, vulnerabilities, and industry trends to proactively enhance security detection measures.
  • Work alongside engineering, IT, and security teams to create and enhance our security standards with solutions that are both scalable and adaptable.
  • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work.
  • Be on periodic on-call for triage of critical alerts from detections and systems.

We’re looking for someone with

  • Education
    • Bachelor's degree or equivalent experience in DevSecOps, CyberSecurity, or related technical field preferred
  • Cloud Security Engineering Experience:
    • 3-5 years of experience implementing security baselines and performing ongoing assessments of security controls for public cloud systems (e.g. AWS, Azure) within a DevOps environment.
    • 3+ years of hands-on experience in building tailored security controls, policies, baselines, and vulnerability assessments for Kubernetes environments for customer-facing, sensitive container workloads, preferably on AKS and EKS.
    • Reducing common and unique Kubernetes and container vulnerabilities, such as misconfigurations, insecure container runtimes, and supply chain attacks with engineering and security teams.
    • Develop and build custom hardened base images for Docker and cloud as part of secure supply chain with CI/CD tooling.
    • Understand the difference between a CVSS base scoring and custom scoring to prioritize exploitable vulnerability patching and mitigations with engineering teams.
    • Experience in using security query or analytic tools for security data analysis, such as SQL, KQL, or SPL.
    • Experience with tailoring and implementing industry security and risk standards (e.g. CIS Benchmarks, ISO 27001, FedRAMP Moderate) for sensitive data workloads.
  • Engineering Experience:
    • Utilize robust analytical and problem-solving capabilities to confirm our hypotheses using precise data and in-depth root cause investigation.
    • Experience using high-level programming languages (Go, Python) to produce detection-as-code, tools, and automations.
    • Experience managing cloud infrastructure as infrastructure-as-code (e.g. Terraform, CloudFormation, ARM, Pulumi).
    • Deliver high quality PRs daily using modern software engineering development and automation tools like Git and CI/CD pipelines (i.e. Jenkins, GitHub Actions).
  • Other :
    • Must be able to obtain Canadian Reliability status (RS) for Protected A, B, C at a minimum
    • Deliver quality and velocity of contributions using DevOps principles
    • Believes in the power of test and process automation
    • Proven ability to work effectively in cross-functional engineering teams
    • Experienced engineer who can put out fires under pressure when things go wrong in production environments and address the root causes of those fires for the future
    • Have a customer-centric work approach to drive positive experiences for their customers

About Tanium

Tanium, the industry’s only provider of converged endpoint management (XEM), leads the paradigm shift in legacy approaches to managing complex security and technology environments. Only Tanium protects every team, endpoint, and workflow from cyber threats by integrating IT, Operations, Security, and Risk into a single platform that delivers comprehensive visibility across devices, a unified set of controls, and a common taxonomy for a single shared purpose: to protect critical information and infrastructure at scale. Tanium has been named to the Forbes Cloud 100 list for six consecutive years and ranks on Fortune’s list of the Best Large Workplaces in Technology. In fact, more than half of the Fortune 100 and the U.S. armed forces trust Tanium to protect people; defend data; secure systems; and see and control every endpoint, team, and workflow everywhere. That’s the power of certainty. Visit www.tanium.com and follow us on LinkedIn and Twitter.

On a mission. Together.

At Tanium, we are stewards of a culture that emphasizes the importance of collaboration, respect, and diversity. In our pursuit of revolutionizing the way some of the largest enterprises and governments in the world solve their most difficult IT challenges, we are strengthened by our unique perspectives and by our collective actions.

We are an organization with stakeholders around the world and it’s imperative that the diversity of our customers and communities is reflected internally in our team members. We strive to create a diverse and inclusive environment where everyone feels they have opportunities to succeed and grow because we know that only together can we do great things.

Each of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.

What you’ll get

The annual base salary range for this full-time position is C$95,000 to C$280,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.

For more information on how Tanium processes your personal data, please see our Privacy Policy