RapidFort, Inc. logo
RapidFort, Inc.

RapidFort is at the intersection of Cybersecurity and AI. RapidFort is the leader in Software Supply Chain Security, delivering a comprehensive end-to-end vulnerability management platform that includes curated near-zero-CVE open-source images, advanced runtime profiling, automated CVE remediation, and software attack-surface-management (hardening) capabilities to continuously secure and optimize containerized applications.

Senior Container Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200

Location

Worldwide

Posted

67 days ago

Salary

$130K - $200K / year

Seniority

Senior

Job Description

Senior Container Security Engineer

RapidFort, Inc.

Role Description We are looking for a hands-on Senior Container Security Engineer to lead vulnerability remediation and image hardening across Linux-based container environments. This role focuses on deep operating system and container security engineering rather than simple vulnerability scanning. You will analyze, remediate, rebuild, harden, and continuously optimize container images used in modern cloud-native platforms. You will work closely with platform engineering, DevOps, infrastructure, and security teams to build automated remediation pipelines, reduce the attack surface, and deliver production-ready hardened images. What You’ll Do - Own end-to-end CVE remediation across Linux-based container images. - Analyze vulnerabilities across OS packages, libraries, runtimes, and dependencies. - Patch, rebuild, validate, and maintain hardened container images at scale. - Reduce attack surface by removing unnecessary packages, binaries, services, and dependencies. - Build and scale automated remediation pipelines for continuous image patching. - Improve image security posture while minimizing operational disruption. - Generate, validate, and maintain SBOMs to support supply chain visibility and compliance. - Integrate remediation workflows into CI/CD and GitOps pipelines. - Optimize image size, startup performance, and operational efficiency. - Research emerging Linux, container, Kubernetes, and software supply chain threats. - Troubleshoot complex dependency, package compatibility, and runtime security issues. - Help define internal standards for hardened images and secure software delivery. Qualifications - 5+ years of experience in Linux systems engineering, platform engineering, DevSecOps, security engineering, or SRE. - Deep understanding of Linux distributions (Debian, Ubuntu, Alpine, RHEL). - Strong hands-on experience with Docker, Kubernetes, and containerized environments. - Proven experience remediating CVEs within Linux packages and container ecosystems. - Proficiency with package management systems (apt, yum/dnf, apk, rpm). - Experience with scanning tools such as Trivy, Grype, or Clair. - Strong scripting or programming skills in Python, Bash, or Go. - Solid understanding of container image layering and filesystem structures. - Familiarity with CI/CD automation and infrastructure-as-code workflows. - Experience with cloud-native infrastructure (AWS, Azure, or GCP). Nice to Have - Experience building minimal or distroless container images. - Familiarity with SBOM standards (SPDX, CycloneDX, Syft). - Experience with image signing and verification tools (Cosign, Sigstore). - Knowledge of software supply chain security frameworks like SLSA. - Familiarity with Kubernetes security controls and eBPF. What Success Looks Like - Delivery of production-ready container images with near-zero exploitable CVEs. - Established scalable automated remediation and image hardening pipelines. - Significant reduction in container attack surface and image bloat. - Improved remediation speed and operational efficiency. - Repeatable standards for secure container image delivery at scale. Compensation & Benefits - Base salary: $130,000 – $200,000 depending on experience and technical depth. - Equity participation. - Comprehensive health, dental, and vision coverage. - Remote-first work environment. - Opportunity to work on cutting-edge cloud-native and container security technologies. - Career growth within a rapidly scaling cybersecurity company.

Related Categories

Related Job Pages

More Security Engineer Jobs

Senior Information Security GRC Analyst

Branch

Branch, founded in 2014, is a trailblazer in mobile linking and measurement, powering seamless digital experiences for over 100,000 apps and reaching more than

• Manage and maintain the Branch Information Security Program, security function programs and processes. Own internal Branch controls. Maintain an accurate security program and all the associated processes across all corporate functions. • Ambassador and champion of the Branch Information Security Program and security awareness. • Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA). • Conduct comprehensive gap analysis to identify deficiencies and areas for improvement in existing controls. • Experience implementing new frameworks and integrating into existing audit cycles. • Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with the frameworks (SOC 2, ISO 27001, PCI, NIST, CCPA) implemented by Branch. • Manage Branch’s Drata GRC platform: • Ensure information is up to date and automated collections are working appropriately. • Ensure that Audit evidence is collected and validated. • Manage access to and keep information up to date for Branch’s Security Trust Center. • Manage and maintain frameworks, policies, control content and control mapping. • Inform the proper stakeholders of important concerns, hazards, and risk to the organization. • Collaborate with stakeholders (Security, Engineering, Cloud Operations, Procurement, and Legal) to ensure security practices are integrated into daily operations, and are aligned with our GRC objectives. • Maintain up-to-date knowledge of procedures and methods that serve to broaden team knowledge and industry expertise. • Write and manage security standards, policies, and practices on an ongoing basis to make sure they meet corporate demands. • Assist the department in responding to inquiries from the business units about ongoing operational compliance. • Be proactive in seeking out areas for improvement and offer insightful advice and value-added guidance and/or automation for process and control enhancements. • Manage the end-to-end third-party vendor management lifecycle, including onboarding, due diligence, and ongoing monitoring of vendor risk, performance, and operational changes through established governance processes. • Partner with the Risk and Legal teams to share information and seek out areas for improvement, streamline processes and to reduce risk throughout the company. • Manage the security training and awareness program, responsible for promoting and enhancing our organization's security culture through effective awareness programs and initiatives. • Support the planning of penetration tests and the coordination of remediation efforts.

United States
$155K - $165K / year
Job Closed
Full TimeRemoteTeam 501-1,000Since 2015H1B Sponsor

• Design and implement a multi-layer AI security framework spanning data classification, detection and response, exfiltration prevention, governance, adversarial testing, and agentic identity management. • Evaluate, deploy, and operate AI-specific security tooling and integrate them into BlinkRx's security operations. • Architect secure MCP (Model Context Protocol) server deployments and define agent-to-agent authentication standards for agentic AI workflows. • Partner with Cloud Security to establish guardrails in AWS for AI workloads. • Define and enforce PHI/PII handling controls for all AI systems. • Design and execute AI red-team assessments against AI applications. • Integrate AI security controls into CI/CD pipelines and engineering workflows. • Develop automated testing and validation for AI applications and AI pipelines. • Build and operate an AI security testing pipeline using tools. • Perform adversarial testing of agentic AI workflows for privilege escalation, tool misuse, and unintended data access patterns.

United States
Elastic logo

Security Sales Executive

Elastic

Self-described as the leading platform for search-powered solutions, Elastic helps organizations, their customers, and their employees find what they need faste

Role Description Elastic is hiring a Security Sales Executive to drive adoption of our Elastic Security solutions across Enterprise and Strategic accounts. This is a specialist overlay role, partnering with our core Enterprise Account Executives to expand the Elastic Security footprint across our customer base. You’ll help customers maximize the value of our SIEM, Security Analytics, Endpoint Security, and Cloud Security offerings. If you're passionate about solving hard security problems through the power of search, we’d love to hear from you! Please Note: This role will only consider candidates who live in California or Pacific Northwest territories. What You Will Be Doing - Driving demand and building awareness of Elastic Security within Enterprise accounts by partnering with Regional Enterprise Account Executives (AEs) and customers. - Collaborating with Elastic Security Specialist SAs on account strategy, planning, and creative programs to generate qualified pipeline. - Evangelizing Elastic Security by communicating our unique value and demonstrating our commercial features across SIEM, endpoint, and cloud security use cases. - Acting as a player/coach, mentoring Regional AEs on how to effectively position and sell Elastic Security. - Working closely with Security Product and Engineering teams to stay current on offerings and advocate for customer needs. - Identifying, developing, and closing new business opportunities—leading the full sales cycle for security-focused opportunities in your region. - Supporting regional teams with responses to RFPs, RFIs, and quote requests as they relate to Elastic Security. - Leading Elastic Security proof-of-concept and proof-of-value engagements with customers. - Delivering compelling presentations, whiteboard sessions, product roadmaps, and working alongside Solutions Architects to showcase Elastic Security demos. - Partnering with regional leadership to track and report on cybersecurity pipeline and deal progression. - Supporting regional marketing with webinars, workshops, and security-focused events to drive pipeline generation. Qualifications - 5+ years of experience selling enterprise platform solutions in SIEM, log management, cybersecurity, data analytics, or data management. - Proven ability to thrive in a fast-paced, dynamic environment. - Track record of success selling to CIOs, CISOs, and cybersecurity teams in the Fortune 500, with strong references and quota overachievement. - A consultative, challenger-oriented sales approach that helps customers rethink their approach to security and data. - Strong ability to work independently while maintaining a collaborative, team-first mindset. - Mastery of a structured sales methodology (e.g., MEDDPICC, MEDDIC, Challenger, Sandler). - Experience in an overlay role, collaborating closely with core sales teams as a trusted partner. - Excellent presentation and communication skills; able to engage both technical users and executive stakeholders. - Ability to build internal trust and alignment with core AEs while also establishing credibility with customer cybersecurity leaders. - Proficiency with Salesforce (SFDC) and a disciplined approach to forecasting and pipeline management. - Appreciation for the open source model and the community of practitioners who rely on Elastic every day. - Prior experience engaging Enterprise customers within the assigned territory. Requirements - Compensation for this role is in the form of base salary plus a variable component, that together comprise the On-Target Earnings (OTE). - The typical starting OTE range for new hires in this role is: - $226,500 — $358,300 USD - The typical starting salary range for this role is: - $135,900 — $215,100 USD - The typical starting Target Variable range for this role is: - $90,600 — $143,300 USD Benefits - Competitive pay based on the work you do here and not your previous salary. - Health coverage for you and your family in many locations. - Ability to craft your calendar with flexible locations and schedules for many roles. - Generous number of vacation days each year. - Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service. - Up to 40 hours each year to use toward volunteer projects you love. - Embracing parenthood with a minimum of 16 weeks of parental leave.

United States
$226.5K - $358.3K / year
Job Closed
Duetto Research logo

Lead Security Engineer

Duetto Research

Duetto is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by applicable law. Sound like you? If this role has you excited, we'd love to hear from you — even if you don't tick every box. At Duetto, we hire for potential, perspective, and the drive to make things happen. Apply and let's start a conversation.

Full TimeRemoteTeam 51-200

Role Description Duetto's platform processes real-time pricing decisions for thousands of hotels, resorts, and casinos worldwide — and this role owns the security posture that makes that possible. As Senior Security Engineer, you'll lead security across cloud infrastructure, engineering, operations, compliance, and customer trust: - Own Duetto's overall security posture across cloud, product, infrastructure, IT, compliance, and customer assurance. - Lead cloud security across AWS (IAM, logging, network security, encryption, Kubernetes and container security, backup posture, and configuration risk). - Partner with Engineering and DevOps to embed security into the SDLC, CI/CD pipelines, and production operations. - Lead vulnerability management end-to-end — owning Snyk Pro and Lacework (or equivalents) for code, dependency, and cloud security operations. - Serve as the primary security incident leader for major incidents, investigations, escalations, root cause analysis, and executive reporting. - Lead IR tabletop exercises, DR tabletop exercises, backup testing coordination, and BCP security reviews. - Own SOC 2 Type 2 readiness, ISO 27001 readiness, ISO 42001 AI governance alignment, and NIST CSF maturity tracking. - Partner with Legal and Privacy on DPA, DTIA, DPF, GDPR, SCCs, and subprocessor management. - Own customer-facing security assurance including strategic RFPs, security questionnaires, enterprise security reviews, Trust page content, and sales support calls. - Provide security guidance to IT on MDM, endpoint security, AV/EDR coverage, access reviews, and SaaS security controls. - Report security posture, risks, incidents, remediation status, and audit readiness to executive leadership. Qualifications - 8+ years of experience in security, cloud security, DevSecOps, security engineering, infrastructure security, or security operations. - Strong hands-on knowledge of AWS — able to review cloud architecture and identify risk. - Experience securing DevOps environments, CI/CD pipelines, Kubernetes and container environments, cloud IAM, logging, secrets management, and infrastructure-as-code. - Experience with SOC 2 Type 2 audits and familiarity with ISO 27001, NIST CSF, and GDPR security requirements. - Experience with vulnerability management, penetration testing programmes, and incident response. - Ability to translate technical risks into business-level priorities and communicate clearly with Engineering, Legal, Sales, auditors, customers, and executives. Requirements - Hands-on experience with Snyk, Lacework, Vanta, MDM platforms, endpoint protection, and cloud posture tools. - Prior ownership of SOC 2 Type 2 audit readiness end-to-end. - ISO 27001 implementation or certification support experience. - Experience supporting enterprise SaaS security reviews and customer trust programmes. - Familiarity with ISO 42001 or AI governance frameworks. Benefits - Full ownership of a consequential security programme. - AI-first engineering organisation, working at the frontier of how security intersects with AI-augmented software development. - Technical depth meets commercial exposure, reviewing cloud architecture and supporting enterprise security reviews. - A platform that demands real security, processing millions of pricing decisions daily with high stakes. Company Description Duetto is the hospitality industry's leading revenue management platform, founded in 2012 by former Wynn Resorts executives. We built the world's first Revenue & Profit Operating System — a suite of tools that gives hotels, resorts, and casinos a complete picture of their revenue and profitability. Trusted by clients ranging from independent boutique hotels to global chains, we've been named the #1 Revenue Management Software by HotelTechAwards four years running and the #1 Best Place to Work in Hotel Tech in 2025.

United States + 1 moreAll locations: United States | Canada