Linux Security Engineer

Acestackllc — Canada · Posted ~2 hours ago

Senior Full-time Onsite

Skills

Linux Linux security hardening vulnerability management Qualys Puppet Foreman CIS benchmarks security compliance patch management ServiceNow CIS

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An experienced Linux Security Engineer is sought to define and enforce hardening standards, manage vulnerabilities from discovery through remediation, validate systems against CIS and security baselines, and coordinate enterprise patching. The role works closely with Linux and platform teams and uses security, configuration-management, and IT-service tools.

Highlights

Own the Linux security lifecycle across a large enterprise estate, with responsibility for hardening, vulnerability remediation, compliance validation, and patch coordination. The role offers substantial ownership and cross-team collaboration.

Description

Job Title: Linux Security Engineer Location: Toronto, ON Work Model: Onsite Employment Type: Full-Time (FTE) Experience: 6 -8 + Years 6-8 years -----Skills and Responsibilities: Partner with Linux and Platform Engineering teams to define and enforce hardening standards new Linux systems must enter the estate compliant from day one, not remediated after the fact.Own the Linux vulnerability lifecycle: triage findings from Qualys, prioritize by SLA, and work with the Linux team to drive remediation through Puppet and ForemanTrack and report missed-target vulnerabilities across BTN and CMRI Linux estates; escalate with documented remediation or delegation plans per team ownership modelValidate configuration compliance against CIS benchmarks and BMO security baselines; raise Puppet module gaps to Platform Engineering for remediationCoordinate patching schedules and maintenance windows; ensure BMO patch schedule adherence across the Linux estateSupport evaluation and adoption of ServiceNow as the unified patching orchestration layer, replacing manually-raised per-patch Jira change tickets with automated scheduled pipeline executionDeploy and validate endpoint security agents (CrowdStrike/Falcon) across Linux hosts in partnership with the Linux teamContribute to bi-weekly vulnerability reporting for senior leadership.