Cybersecurity Cloud Engineer: Container Security
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Systems Engineer
Software Guidance & Assistance, Inc., (SGA), is searching for a Cybersecurity Cloud Engineer:
Container Security for a contract/right to hire/direct placement assignment with one of our premier Infrastructure services clients in La Vista (Omaha), NE, Atlanta, GA, Scottsdale, AZ, St Petersburg, FL, or Oakdale, MN
.
Seeking a hands‑on Cyber Security Engineer with a strong focus on container security to develop standards/policies, design and implement controls, and support operationalization of security measures across our estate. You’ll work across both Windows and Linux platforms, with a minimum of 3 years practical experience in Docker and Kubernetes. The role requires a self‑starter who can work independently, produce clear documentation, and contribute to our broader cybersecurity initiatives.
Azure experience is preferred.Standards & Policy Development
Author, maintain, and socialize container security standards, baseline configurations, and operational runbooks.
Define control requirements for Kubernetes clusters and Docker runtimes (networking, RBAC, secrets, compliance, logging).
Control Design & Implementation
Engineer and deploy container‑specific security controls across the estate (on‑prem & cloud), including:
Kubernetes RBAC, Network Policies, Pod Security standards (or replacements), admission controls (OPA/Gatekeeper/Kyverno).
Image security (registry governance, signing/verification, SBOM, vulnerability management).
Runtime protection (CIS benchmarks, syscall/behavior policies, workload isolation, secrets management).
Secure CI/CD integrations (image scanning gates, IaC security checks, policy‑as‑code).
Operational Support
Own day‑to‑day health and performance of deployed controls; troubleshoot issues with clusters, workloads, and pipelines.
Partner with platform engineering/SRE to triage, remediate, and tune policies without breaking delivery velocity.
Documentation & Enablement
Produce clear, actionable documentation: standards, architecture diagrams, procedures, FAQs, and “how‑to” guides.
Provide guidance and training to engineering teams to adopt secure‑by‑default patterns.
Broader Cybersecurity Support
Contribute to vulnerability management, incident response (for containerized workloads), audit support, and control assurance.
Participate in threat modeling for new services and changes.
Day to day work load:
Check the SCRUM board for ready work items, attend meetings with stakeholders, collaborate with security and infrastructure team members.
- OS Expertise:
Proficient in both Windows and Linux administration and security fundamentals. - Containers: 3 years hands‑on experience with Docker and Kubernetes (design, deployment, security hardening).
- Security Engineering:
Proven ability to design, implement, and operationalize technical controls in production environments. - Networking & Access Control:
Solid grasp of container networking (CNI), service‑to‑service policies, identity/RBAC, and secrets handling. - Dev Sec Ops Mindset:
Experience integrating security into CI/CD (e.g., image scanning, policy gates, IaC checks). - Documentation:
Strong technical writing skills (standards, procedures, diagrams). - Work Style:
Able to work independently with minimal oversight; strong ownership and follow‑through. - Technical Depth & Pragmatism:
Balances strong security posture with developer productivity and uptime. - Problem Solving:
Able to diagnose complex production issues across networking, policy, identity, and runtime. - Communication:
Explains trade‑offs, documents clearly, and influences stakeholders. - Ownership & Autonomy:
Drives initiatives end to end—requirements, build, deploy, monitor, and improve.
- Certifications:
AZ‑500, AZ‑700, SC‑200, SC‑100 - Cloud:
Experience with Microsoft Azure (AKS, ACR, Azure Defender/Defender for Cloud, Key Vault, Azure Policy). - Security Tools & Frameworks:
Familiarity with admission/policy tools (OPA/Gatekeeper, Kyverno), image scanning (Trivy, Aqua, Prisma, Clair), SBOM (Cyclone
DX). - Kubernetes security benchmarks (CIS), Pod Security standards, runtime protection.
- Infrastructure as Code & Automation:
Terraform, Bicep/ARM, Helm;
Git Hub Actions/Azure…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).