> Markdown version of [/jobs/ext/189751-kubernetes-security-engineer](https://www.wearedevelopers.com/jobs/ext/189751-kubernetes-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Kubernetes Security Engineer - **Company:** Capgemini - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $76,200.0 - $187,740.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Systems Engineering, Cyber Security, Continuous Integration, Key Management, Linux Distribution, Linux Security Modules, Role-Based Access Control, Reliability Engineering, Software Vulnerability Management, Selinux, Kubernetes, Information Technology, Hashicorp - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=57010e894db22902 ## About the Role * Bachelor's degree in Computer Science, Engineering, or a related technical field, with 8-10 years of experience in infrastructure, security, or systems engineering. * Deep expertise in Kubernetes internals, including cluster hardening, multi-tenant isolation, and security architecture. * Advanced proficiency in Linux security features such as SELinux, AppArmor, seccomp, and kernel-level protections. * Hands-on experience with TPM for secure boot, attestation, and integration with HSM/KMS for cryptographic operations and secrets management. * Strong understanding of Pod Security frameworks (PodSecurityStandards, OPA, Gatekeeper, Kyverno) and implementation of RBAC, NetworkPolicies, and workload isolation at scale. * Familiarity with container runtimes (containerd, CRI-O, gVisor, Kata) and their security implications in hybrid environments. * Experience with runtime and supply chain security tools and frameworks, including Falco, Cilium Tetragon, cosign, Notary, SLSA, and NIST 800-190. * Knowledge of confidential computing (TEE, SGX, SEV), air-gapped deployments, and hardened Linux distributions like Flatcar and Bottlerocket. ## Description We're seeking a Kubernetes Security Engineer to help design and operate security-first platforms for complex, multi-tenant environments. In this role, you'll architect and deploy hardened Kubernetes clusters across diverse hardware architectures, applying advanced Linux security controls, hardware-rooted trust, and least-privilege principles to protect critical workloads. You'll work hands-on with modern container runtimes, supply-chain security, and runtime threat detection, collaborating closely with infrastructure, SRE, and security teams to build resilient systems that minimize risk and scale securely. Your role * Architect and deploy security-first Kubernetes cluster configurations across diverse hardware platforms, including x86, ARM, and accelerators. * Enforce Linux security modules (SELinux, AppArmor) and sandboxing techniques (seccomp, gVisor, Kata) to protect workloads and system services. * Integrate TPM for secure boot and attestation, ensuring hardware and OS integrity, and support cryptographic operations with HSM/KMS systems. * Design multi-tenant isolation strategies using namespaces, node pools, and hardware partitioning to prevent lateral movement and reduce blast radius. * Apply least-privilege policies using RBAC, PodSecurityStandards, NetworkPolicies, and resource constraints to secure workload execution and mitigate denial-of-service risks. * Harden Kubernetes components (API server, etcd, kubelet) using CIS and NSA benchmarks, and implement kernel-level protections like seccomp-bpf and IMA/EVM. * Secure workload secrets using TPM-backed storage and tools like SealedSecrets, HashiCorp Vault, or SOPS for safe distribution and access control. * Strengthen supply chain security through image signing (cosign, Notary), SBOM scanning, and CI/CD vulnerability management. * Monitor runtime behavior with tools like Falco and Cilium Tetragon, and collaborate with SRE and Security teams to develop incident response runbooks and conduct breach simulation drills. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) ## Related Articles - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)