Member of Technical Staff Infrastructure Security
Summary
Secures Reflection's multi-cloud Kubernetes and cloud environments day to day: auditing and hardening clusters, unifying authentication and authorization policy, automating security posture monitoring, protecting container workloads, and building incident-response tooling. Core stack includes Kubernetes/GKE, Rancher, Helm, ArgoCD, Terraform/Pulumi, GCP/AWS/Azure, and Python or Go.
You will secure geographically distributed multi-cloud Kubernetes and cloud environments. You will audit and harden clusters, centralize authentication and authorization, automate security posture monitoring, protect container workloads, build incident-response tooling, and define an infrastructure-security roadmap.
Responsibilities
- Audit and harden multi-cloud Kubernetes clusters
- Unify and harden authentication across Kubernetes clusters
- Design and implement centralized auditable authorization policy enforcement
- Automate Kubernetes security posture monitoring and benchmarking
- Develop defense-in-depth boundaries for containerized workloads
- Build and deploy incident detection and response tooling
Requirements
- Experience securing Kubernetes clusters and hardening containerized workloads
- Knowledge of managed Kubernetes services such as GKE
- Experience with CI/CD systems such as ArgoCD
- Knowledge of Rancher and Helm
- Experience securing artifact repositories and build artifact provenance
- Experience with infrastructure as code such as Terraform or Pulumi
- Experience with GCP AWS or Azure
- Experience with neocloud GPU providers
- Python or Golang programming experience
- Recent hands-on engineering experience
- Experience building infrastructure security controls from zero to one
Benefits
- Stock options
- Medical dental vision and life insurance
- Annual wellness allowance
- Daily office lunch and dinner
- 22 weeks of paid parental leave
- Unlimited paid time off in the United States
- 30 days of vacation in the United Kingdom
- Visa sponsorship support
- Regular off-sites happy hours and team celebrations