Colorado Staffing
Container Security Engineer Vulnerability & Misconfiguration Management
Colorado Staffing, Denver, Colorado, United States, 80285
Container Security Engineer Vulnerability & Misconfiguration Management
We are seeking a skilled and motivated Container Security Engineer to strengthen our cybersecurity posture across containerized environments. This role focuses on the identification, analysis, and mitigation of vulnerabilities and misconfigurations in container images, Kubernetes clusters, and related orchestration platforms. The ideal candidate will bring technical expertise in container security tooling, vulnerability management, and secure configuration practices, while driving collaboration with DevOps and engineering teams to embed security into the container lifecycle. Job Responsibilities
Perform container image scanning to identify vulnerabilities, misconfigurations, and insecure base images. Manage and optimize container security platforms. Develop and enforce Kubernetes security baselines, focusing on RBAC, network policies, secrets management, and runtime controls. Partner with DevOps and applications teams to integrate security checks into CI/CD pipelines. Continuously monitor for container runtime threats, privilege escalations, and drift from security baselines. Collaborate across engineering, operations, and compliance teams to ensure vulnerabilities and misconfigurations are remediated in line with risk priorities. Research and track emerging container security risks, threats, and industry best practices. Contribute to governance, policies, and playbooks for container security lifecycle management. Required Qualifications
3+ years experience in container or cloud-native security Hands-on experience with Kubernetes and container runtimes Experience with container security scanning tools and vulnerability management tools (Aqua, Wiz, Qualys) Knowledge of Kubernetes security principles Familiarity with Linux security fundamentals, container isolation, and namespace/cgroups Strong problem-solving, analytical, and communication skills Understanding of DevSecOps and CI/CD pipeline integration through security engineering lifecycles Ability to communicate complex concepts to all levels of understanding and technical ability Desired Qualifications
CISSP/CCSP/CISM Cloud specific Security certifications such as SANS/GIAC Vendor specific and relevant certifications AZ-500, SC-200, AZ-204, CKA, CKS, RHCE, etc Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent work experience Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws.
We are seeking a skilled and motivated Container Security Engineer to strengthen our cybersecurity posture across containerized environments. This role focuses on the identification, analysis, and mitigation of vulnerabilities and misconfigurations in container images, Kubernetes clusters, and related orchestration platforms. The ideal candidate will bring technical expertise in container security tooling, vulnerability management, and secure configuration practices, while driving collaboration with DevOps and engineering teams to embed security into the container lifecycle. Job Responsibilities
Perform container image scanning to identify vulnerabilities, misconfigurations, and insecure base images. Manage and optimize container security platforms. Develop and enforce Kubernetes security baselines, focusing on RBAC, network policies, secrets management, and runtime controls. Partner with DevOps and applications teams to integrate security checks into CI/CD pipelines. Continuously monitor for container runtime threats, privilege escalations, and drift from security baselines. Collaborate across engineering, operations, and compliance teams to ensure vulnerabilities and misconfigurations are remediated in line with risk priorities. Research and track emerging container security risks, threats, and industry best practices. Contribute to governance, policies, and playbooks for container security lifecycle management. Required Qualifications
3+ years experience in container or cloud-native security Hands-on experience with Kubernetes and container runtimes Experience with container security scanning tools and vulnerability management tools (Aqua, Wiz, Qualys) Knowledge of Kubernetes security principles Familiarity with Linux security fundamentals, container isolation, and namespace/cgroups Strong problem-solving, analytical, and communication skills Understanding of DevSecOps and CI/CD pipeline integration through security engineering lifecycles Ability to communicate complex concepts to all levels of understanding and technical ability Desired Qualifications
CISSP/CCSP/CISM Cloud specific Security certifications such as SANS/GIAC Vendor specific and relevant certifications AZ-500, SC-200, AZ-204, CKA, CKS, RHCE, etc Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent work experience Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws.