INTL India - Remote Container/Kubernetes Security SME

Insight Global
Boston, MA, United States
3 months ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$27,040.0 - $35,360.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Security Python (Programming Language) Software Vulnerability Management Cloudformation Terraform Serverless Computing Service Stack

Job description

Insight Global is seeking a remote Container Security SME to join a global consulting firm. This person would be joining their Attack Surface Management team and would work to strengthen security posture across the organizations cloud-native technology stack. This contractor will provide deep technical expertise in container and Kubernetes security, drive vulnerability remediation, and shape security standards for

containerized workloads across BCG’s multi-cloud environment.

Success in this role will be measured by the following outcomes:

-Assess and harden containerized environments, identifying gaps and driving remediation to

closure with development and platform teams.

-Own the end-to-end vulnerability management lifecycle for container workloads - from scan

configuration through prioritization, tracking, and remediation coordination.

-Advice on securing the container build and deployment pipeline, including image integrity and

registry governance.

-Configure and optimize our CNAPP tooling to meet BCG-specific visibility and compliance

requirements.

-Conduct threat modeling for containerized and serverless architectures.

-Design and implement automated remediation workflows to reduce time-to-resolution.

-Deliver security metrics and reporting that give leadership clear visibility into posture and

progress.

-Maintain detailed tracking of all identified vulnerabilities through their full remediation lifecycle,

including ownership assignment, status updates, and closure verification.

-Monitor and enforce remediation SLAs across teams, flagging breaches early and driving

accountability for timely resolution.

Requirements

4+ years of cloud security experience with a primary focus on container security and vulnerability management

-Hands-on experience securing container orchestration platforms and workloads at

scale (working with hundreds of thousands of vulnerabilities)

-Experience with Wiz or Orca

-Production experience with CNAPP/CWPP tooling in an enterprise setting

*Familiarity with at least one major cloud provider (AWS, Azure, or GCP)

-Strong communication skills - able to translate technical findings into clear, actionable guidance

-Experience with Infrastructure as Code security scanning (Terraform, CloudFormation, or Helm

chart analysis) -Proficiency in scripting (Python, Bash, or Go) for automation and tool integration

-Any of the following certifications: CKS, CKA, CCSP, CCSK, AWS Security Specialty, Azure Security Engineer, GCP Professional Cloud Security Engineer

Benefits & conditions

$13/hr to $17/hr

Exact compensation may vary based on several factors, including skills, experience, and education.

Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401K retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

3:47 min

Solving the knowledge deficit in large language models

Alejandro Saucedo Alejandro Saucedo +3 · World Congress 2024

1:39 min

Introduction to Kubernetes security challenges and opportunities

Marc Nimmerrichter · World Congress 2022

41 sec

Operating critical stack observability and service monitoring

Michael Cade · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all