Linux Security Engineer

Acestackllc — Canada · Posted ~3 hours ago

Senior Full-time Onsite

Skills

Linux security Linux administration Vulnerability management Qualys Puppet Foreman CIS benchmarks Security hardening Patch management ServiceNow Linux

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Own Linux security across a large enterprise environment. You will define and enforce hardening standards, manage the vulnerability lifecycle, validate systems against security benchmarks, coordinate patching and maintenance windows, and partner with platform teams to improve automation and compliance.

Highlights

Full-time onsite security role focused on protecting and hardening a large Linux estate. The position offers ownership of vulnerability management, compliance, patching, and security standards while collaborating closely with platform teams.

Description

Job Title: Linux Security Engineer Location: Toronto, ON Work Model: Onsite Employment Type: Full-Time (FTE) Experience: 6 -8 + Years 6-8 years -----Skills and Responsibilities: Partner with Linux and Platform Engineering teams to define and enforce hardening standards new Linux systems must enter the estate compliant from day one, not remediated after the fact.Own the Linux vulnerability lifecycle: triage findings from Qualys, prioritize by SLA, and work with the Linux team to drive remediation through Puppet and Foreman Track and report missed-target vulnerabilities across BTN and CMRI Linux estates; escalate with documented remediation or delegation plans per team ownership modelValidate configuration compliance against CIS benchmarks and BMO security baselines; raise Puppet module gaps to Platform Engineering for remediationCoordinate patching schedules and maintenance windows; ensure BMO patch schedule adherence across the Linux estateSupport evaluation and adoption of ServiceNow as the unified patching orchestration layer, replacing manually-raised per-patch Jira change tickets with automated scheduled pipeline executionDeploy and validate endpoint security agents (CrowdStrike/Falcon) across Linux hosts in partnership with the Linux teamContribute to bi-weekly vulnerability reporting for senior leadership.