Principal Linux Security Engineer

CIQ

United States

Remote

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
Flexible paid time off
Employee stock options
Remote work

Job summary

CIQ is seeking a Linux security-focused engineer to join our security team in the United States, with a strong emphasis on proactive OS hardening and secure configurations.

You will build STIG/DIS profiles, improve OpenSCAP, and develop Ansible scripts to enforce security settings, while creating tools that accelerate security workflows and leverage AI-assisted testing and release processes.

Qualifications

  • Proven work experience in Security and/or Linux Engineering with a focus on the Linux OS.
  • At least 4 years of experience doing security in Linux and at least 2 years of experience building Linux Packages.

Responsibilities

  • Own OS security posture, including CSAF, VEX, and advisories.
  • Build STIG/DIS profiles and Ansible automation.
  • Advance OpenSCAP and security tooling with Ansible.
  • Create tools to speed security workflows and integrate AI.
  • Assess CVSS scores and CVE affectedness.

Skills

Linux Security
Linux Engineering
Ansible
OpenSCAP
SELinux
LKRG
CVSS
Security Updates

Tools

RPM Packaging

Job description

CIQ builds the enterprise infrastructure that powers the world's most demanding workloads. From the operating system layer through AI infrastructure, high-performance computing, and cloud-native orchestration, CIQ delivers the speed, security, scalability, and sovereignty that major enterprises, government agencies, and research institutions depend on.

CIQ is the founding support and services partner of Rocky Linux and the developer of the RLC Pro family of Enterprise Linux distributions, Fuzzball workload orchestration, Warewulf Pro cluster provisioning, and Ascender Pro automation. Our customers include some of the largest and most technically sophisticated organizations in the world, working across HPC, AI/ML, defense, and regulated industries.

We are a company of builders, operators, and open source practitioners. If you want to do work that matters, at a company that is genuinely changing how enterprise infrastructure gets built and run, we want to talk.

POSITION SUMMARY

This isn\'t a traditional job description. It describes the specific person we\'re looking for: an engineer who understands the Linux operating system from a security perspective.

What does that mean in practice? Here is what we need from this role:

  • How security errata works in an operating system (CSAF, VEX, Advisories) and how to create them and use them in various aspects of the systems, from updateinfo in repos to a security feed for security scanners to ingest.
  • Compliance on an operating system - Building out STIG and DIS profiles. Understanding how to improve OpenSCAP and building Ansible scripts to apply the security profiles, not just applying scripts that someone else built.
  • Proactive security in an operating system, like build flags, LKRG, SELinux. How to really secure the OS in a way that also allows it to be usable. Not hooking it up to the internet is not an acceptable security answer.
  • How to build tools to make the above happen faster and interact with AI to speed up development, testing, and release.
  • CVE scoring - How they are scored and what that means. It doesn\'t mean that you know how to look up a score in NIST, but it means you have used the CVSS calculator and you know why it is scored a 7.8 vs. a 5.5
  • CVE affectedness - You understand how to determine if a piece of software is affected by a CVE and how different aspects of build and configuration change the affectedness.

Is This Role Right for You?

If the requirements above don\'t resonate with your experience, this position is likely not the right fit. If you meet most of them, we\'d like to hear from you. We\'re looking for candidates who are genuinely engaged with this work, so we ask that automated or mass applications be avoided.

EDUCATION AND EXPERIENCE

  • Proven work experience in Security and/or Linux Engineering with a focus on the Linux OS.
  • At least 4 years of experience doing security in Linux and at least 2 years of experience building Linux Packages

BENEFITS

Medical, dental, and vision insurance.

Flexible paid time off.

Employee stock options.

Remote work; no travel required for most positions.

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.

How would you describe your gender identity? Select...

How would you describe your racial/ethnic background? Select...

How would you describe your sexual orientation? Select...

Do you identify as transgender? Select...

Do you have a disability or chronic condition (physical, visual, auditory, cognitive, mental, emotional, or other) that substantially limits one or more of your major life activities, including mobility, communication (seeing, hearing, speaking), and learning? Select...

Are you a veteran or active member of the United States Armed Forces? Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in CIQ’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran\'s discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

By checking this box, I consent to CIQ collecting, storing, and processing my responses to the demographic data surveys above.

Application Disclosure

Use of Recruiting Technology

As part of our recruiting process, CIQ uses technology tools within our applicant tracking system to assist recruiters in reviewing and organizing applications. These tools may help identify candidates whose qualifications align with job-related criteria, detect potential fraud or spam activity, and support recruiting workflow efficiencies.

These tools do not make hiring decisions. All employment decisions are made by CIQ personnel based on a holistic review of candidate qualifications and other job-related factors.

Candidates who require an accommodation, alternative application process, or other assistance during the recruiting process should contact CIQ Human Resources at hr@ciq.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Linux Security Engineer (Fully Remote)
Principal Linux Security Engineer (Fully Remote)

CIQ • United States

Remote
USD 120,000 - 180,000
Remote-first culture
Open source culture
Software Integration Engineer 3 (On-Call) - Linux/Bash/Python/Docker/Kubernetes/Helm/Grafana/Jira
Software Integration Engineer 3 (On-Call) - Linux/Bash/Python/Docker/Kubernetes/Helm/Grafana/Jira

Captivation-Software • Maryland

On-site
USD 130,000 - 270,000
401k contribution
Insurance coverage
HSA contribution
+1
Software Engineer - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED
Software Engineer - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Maryland

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+4
AI Platform Engineer for Hardware Intelligence
AI Platform Engineer for Hardware Intelligence

Nominal • Washington

On-site
USD 140,000 - 210,000
100% coverage of medical, dental, and
Unlimited PTO and sick leave
Free lunch, snacks, and coffee
+2
Software Engineer - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED
Software Engineer - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Fort Meade (MD)

On-site
USD 130,000 - 190,000
Healthcare options
Dental insurance
Vision with employer-paid premium
+4
Staff DevOps Engineer
Staff DevOps Engineer

NightDragon Acquisition Corp. • Santa Clara (CA)

On-site
USD 180,000 - 240,000
Senior SecDevOps Engineer for AI Cloud Platform
Senior SecDevOps Engineer for AI Cloud Platform

Re:Build Manufacturing • Boston (MA), Los Angeles (CA), Seattle (WA)

Hybrid
USD 165,000 - 200,000
Health/dental/vision
401K + bonus
Paid time off + learning stipend
+1
Sr. Manager, Security Engineering
Sr. Manager, Security Engineering

6Sense Insights • United States

Remote
USD 205,000 - 254,000
Health insurance
401K plan
Stock options
+1
Software Engineers - multiple levels - CLEARANCE REQUIRED
Software Engineers - multiple levels - CLEARANCE REQUIRED

Constellation Technologies, Inc • Columbia (MD)

On-site
USD 100,000 - 140,000
Healthcare options
Dental insurance
Vision insurance
+7
Senior SRE & Systems Engineer — TS/SCI Clearance
Senior SRE & Systems Engineer — TS/SCI Clearance

Chameleon Consulting Group LLC • Herndon (VA)

On-site
USD 80,000 - 120,000