CIQ

Principal Linux Security Engineer

CIQ
Apply
16 hours ago
Remote, United StatesStaff+
H1B sponsor

Responsibilities

  • Create and use operating-system security errata, including CSAF, VEX, advisories, repository update metadata, and security feeds.
  • Build STIG and DISA security profiles and improve OpenSCAP implementations.
  • Develop Ansible scripts to apply operating-system security profiles.
  • Implement proactive Linux security through build flags, LKRG, SELinux, and usable system-hardening practices.
  • Build tools to accelerate security development, testing, and release workflows, including AI-assisted development.
  • Evaluate CVE severity using the CVSS calculator and determine CVE affectedness based on software builds and configurations.

Requirements

  • Proven work experience in security and/or Linux engineering focused on the Linux operating system.
  • At least 4 years of experience doing security in Linux.
  • At least 2 years of experience building Linux packages.
  • Practical knowledge of CSAF, VEX, security advisories, STIG, DISA profiles, OpenSCAP, Ansible, build flags, LKRG, SELinux, CVSS, and CVE affectedness.

Benefits

  • Medical, dental, and vision insurance.
  • Flexible paid time off.
  • Employee stock options.
  • Remote work; no travel required for most positions.

Tech Stack

AnsibleLinux

Categories

CIQ

About CIQ

51-200 employees

CIQ builds and supports open-source and commercial software for high-performance computing and AI infrastructure, from Linux distributions to workload orchestration. It is the founding support and services partner of Rocky Linux and offers RLC Pro, Fuzzball, Warewulf Pro, and Ascender Pro, plus Apptainer support. Privately held and founded in 2020, CIQ is headquartered in Reno, Nevada, and sells subscriptions and services to enterprises, government, and research institutions.

Contact me