> Markdown version of [/jobs/ext/558756-container-security-exposure-management-analyst](https://www.wearedevelopers.com/jobs/ext/558756-container-security-exposure-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Container Security & Exposure Management Analyst - **Company:** SYNERGIS - **Location:** Atlanta, GA, United States - **Salary:** $104,000.0 - $156,000.0 - **Contract:** Temporary to permanent - **Skills:** Kubernetes Security, Microsoft Windows, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Perl (Programming Language), Python (Programming Language), Log Analysis, OpenShift, Open Web Application Security, Windows PowerShell, Role-Based Access Control, Security Information and Event Management, Software Vulnerability Management, Scripting, Enterprise Software Applications, Kubernetes Helm Charts, Containerization, Kubernetes, Information Technology, Azure AKS, Devsecops, Docker, Vulnerability Analysis - **Published:** June 15, 2026 - **Apply:** https://www.dice.com/job-detail/f7495ff3-23d8-4d7f-a0aa-8388473387ed ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, or equivalent experience. * 2+ years in container platform engineering, DevSecOps, or related security roles. * Experience supporting, securing, or troubleshooting containerized environments such as Kubernetes, Docker, OpenShift, AKS, EKS, GKE, or similar platforms. * Ability to assess vulnerabilities in container images, base images, package dependencies, Kubernetes manifests, Helm charts, and cluster configurations. * Working knowledge of container security controls and hardening practices, including image scanning, least privilege, non-root containers, secrets handling, network policies, RBAC, pod security standards, and runtime monitoring. * Proficiency in scripting languages (Python, PowerShell, Bash; PERL a plus). * Knowledge of vulnerability management, attack surface management, cloud security posture, and exposure management concepts. * Familiarity with OWASP testing methodologies and common vulnerabilities. * Understanding of security threats and vulnerabilities such as buffer overflows, cross-site scripting, code injection, race conditions, and others. * Competency with Windows and Linux/Unix operating systems. * Experience with SIEM platforms for detection validation and log analysis. * Excellent communication skills for translating technical findings into business risk narratives. * Ability to think creatively and like an attacker, demonstrating persistence and attention to detail. * Ability to adapt in a fast-paced environment and drive consensus across stakeholders. * Strong critical thinking, curiosity, and analytical skills. * Ability to work independently or within a team, managing multiple priorities and meeting schedules. * Ability to pass NERC CIP and Insider Threat Protection background checks. Preferred Experience: * One or more relevant industry certifications (e.g., CKS, CKAD, CKA, OSCP, CEH, GSEC, CISSP, CISA). * Occasional travel to local and regional locations in pursuit of job duties. ## Description * Support the cybersecurity team in a technical, hands-on role focused on containerized and cloud-native environments. * Identify, validate, and assess security exposures across enterprise systems, emphasizing Openshift, Kubernetes, Docker, container runtimes, and orchestration platforms. * Support day-to-day CTEM operations by validating exposure paths, confirming exploit potential, and understanding vulnerabilities impacting containerized workloads, images, clusters, nodes, and supporting services. * Translate platform knowledge into practical recommendations to reduce exposure and improve security posture of container environments. ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)