Software Guidance & Assistance, Inc. (SGA, Inc.) · 2 weeks ago
Cybersecurity Cloud Engineer: Container Security
Software Guidance & Assistance, Inc. is searching for a Cybersecurity Cloud Engineer: Container Security for a contract assignment with a premier Infrastructure services client. The role involves developing standards and policies, designing and implementing security controls, and supporting operationalization of security measures across various platforms.
Information TechnologyStaffing Agency
Responsibilities
Seeking a hands-on Cyber Security Engineer with a strong focus on container security to develop standards/policies, design and implement controls, and support operationalization of security measures across our estate. You'll work across both Windows and Linux platforms, with a minimum of 3+ years practical experience in Docker and Kubernetes. The role requires a self-starter who can work independently, produce clear documentation, and contribute to our broader cybersecurity initiatives. Azure experience is preferred
Standards & Policy Development
Author, maintain, and socialize container security standards, baseline configurations, and operational runbooks
Define control requirements for Kubernetes clusters and Docker runtimes (networking, RBAC, secrets, compliance, logging)
Control Design & Implementation
Engineer and deploy container-specific security controls across the estate (on-prem & cloud), including:
Kubernetes RBAC, NetworkPolicies, PodSecurity standards (or replacements), admission controls (OPA/Gatekeeper/Kyverno)
Image security (registry governance, signing/verification, SBOM, vulnerability management)
Runtime protection (CIS benchmarks, syscall/behavior policies, workload isolation, secrets management)
Secure CI/CD integrations (image scanning gates, IaC security checks, policy-as-code)
Operational Support
Own day-to-day health and performance of deployed controls; troubleshoot issues with clusters, workloads, and pipelines
Partner with platform engineering/SRE to triage, remediate, and tune policies without breaking delivery velocity
Documentation & Enablement
Produce clear, actionable documentation: standards, architecture diagrams, procedures, FAQs, and "how-to” guides
Provide guidance and training to engineering teams to adopt secure-by-default patterns
Broader Cybersecurity Support
Contribute to vulnerability management, incident response (for containerized workloads), audit support, and control assurance
Participate in threat modeling for new services and changes
Day to day work load: Check the SCRUM board for ready work items, attend meetings with stakeholders, collaborate with security and infrastructure team members
Qualification
Required
Proficient in both Windows and Linux administration and security fundamentals
3+ years hands-on experience with Docker and Kubernetes (design, deployment, security hardening)
Proven ability to design, implement, and operationalize technical controls in production environments
Solid grasp of container networking (CNI), service-to-service policies, identity/RBAC, and secrets handling
Experience integrating security into CI/CD (e.g., image scanning, policy gates, IaC checks)
Strong technical writing skills (standards, procedures, diagrams)
Able to work independently with minimal oversight; strong ownership and follow-through
Balances strong security posture with developer productivity and uptime
Able to diagnose complex production issues across networking, policy, identity, and runtime
Explains trade-offs, documents clearly, and influences stakeholders
Drives initiatives end to end—requirements, build, deploy, monitor, and improve
Preferred
AZ- 500, AZ-700, SC-200, SC-100 certifications
Experience with Microsoft Azure (AKS, ACR, Azure Defender/Defender for Cloud, Key Vault, Azure Policy)
Familiarity with admission/policy tools (OPA/Gatekeeper, Kyverno), image scanning (Trivy, Aqua, Prisma, Clair), SBOM (CycloneDX)
Experience with Kubernetes security benchmarks (CIS), Pod Security standards, runtime protection
Experience with Infrastructure as Code & Automation: Terraform, Bicep/ARM, Helm; GitHub Actions/Azure DevOps pipelines
Experience with centralized logging and metrics for containers (e.g., Prometheus, Grafana, ELK/EFK)
Experience mapping controls to frameworks (CIS, NIST CSF, ISO 27001, PCI, SOC 2) for containerized workloads
AZ-500, CKA/CKS, Security+, CISSP, CCSP certifications (nice to have)
Company
Software Guidance & Assistance, Inc. (SGA, Inc.)
SGA is the technology and resource solutions provider driven to stand out. We are a certified women-owned business.
H1B Sponsorship
Software Guidance & Assistance, Inc. (SGA, Inc.) has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (13)
2024 (12)
2023 (19)
2022 (25)
2021 (41)
2020 (44)
Funding
Current Stage
Growth StageCompany data provided by crunchbase