2h ago
New

Principal Linux Security Engineer

Remotelead
EngineeringSecurity Engineer
1 views0 saves0 applied

Quick Summary

Requirements Summary

How security errata works in an operating system (CSAF, VEX, Advisories) and how to create them and use them in various aspects of the systems,

Technical Tools
EngineeringSecurity Engineer

CIQ OVERVIEW

CIQ builds the enterprise infrastructure that powers the world's most demanding workloads. From the operating system layer through AI infrastructure, high-performance computing, and cloud-native orchestration, CIQ delivers the speed, security, scalability, and sovereignty that major enterprises, government agencies, and research institutions depend on.

CIQ is the founding support and services partner of Rocky Linux and the developer of the RLC Pro family of Enterprise Linux distributions, Fuzzball workload orchestration, Warewulf Pro cluster provisioning, and Ascender Pro automation. Our customers include some of the largest and most technically sophisticated organizations in the world, working across HPC, AI/ML, defense, and regulated industries.

We are a company of builders, operators, and open source practitioners. If you want to do work that matters, at a company that is genuinely changing how enterprise infrastructure gets built and run, we want to talk.

POSITION SUMMARY 

This isn't a traditional job description. It describes the specific person we're looking for: an engineer who understands the Linux operating system from a security perspective.

What does that mean in practice? Here is what we need from this role:

  • How security errata works in an operating system (CSAF, VEX, Advisories) and how to create them and use them in various aspects of the systems, from updateinfo in repos to a security feed for security scanners to ingest. 
  • Compliance on an operating system - Building out STIG and DIS profiles. Understanding how to improve OpenSCAP and building Ansible scripts to apply the security profiles, not just applying scripts that someone else built.
  • Proactive security in an operating system, like build flags, LKRG, SELinux. How to really secure the OS in a way that also allows it to be usable. Not hooking it up to the internet is not an acceptable security answer.
  • How to build tools to make the above happen faster and interact with AI to speed up development, testing, and release. 
  • CVE scoring - How they are scored and what that means.  It doesn’t mean that you know how to look up a score in NIST, but it means you have used the CVSS calculator and you know why it is scored a 7.8 vs. a 5.5
  • CVE affectedness - You understand how to determine if a piece of software is affected by a CVE and how different aspects of build and configuration change the affectedness. 

Is This Role Right for You?

If the requirements above don't resonate with your experience, this position is likely not the right fit. If you meet most of them, we'd like to hear from you. We're looking for candidates who are genuinely engaged with this work, so we ask that automated or mass applications be avoided.

EDUCATION AND EXPERIENCE 

  • Proven work experience in Security and/or Linux Engineering with a focus on the Linux OS.
  • At least 4 years of experience doing security in Linux and at least 2 years of experience building Linux Packages

BENEFITS

  • Medical, dental, and vision insurance.

  • Flexible paid time off.

  • Employee stock options.

  • Remote work; no travel required for most positions.

 

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location

Listing Details

Posted
October 6, 2026
First seen
October 6, 2026
Last seen
October 6, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
67%
Scored at
October 6, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Principal Linux Security Engineer