08 Sep
|
AceStack
|
Toronto
Job Title: Linux Security Engineer
Location: Toronto, ON
Work Model: Onsite
Employment Type: Full-Time (FTE)
Experience: 6 -8 + Years
6-8 years -----Skills and Responsibilities:
- Partner with Linux and Platform Engineering teams to define and enforce hardening standards recent Linux systems must enter the estate compliant from day one, not remediated after the fact.
- Own the Linux vulnerability lifecycle: triage findings from Qualys, prioritize by SLA, and work with the Linux team to drive remediation through Puppet and Foreman
- Track and report missed-target vulnerabilities across BTN and CMRI Linux estates; escalate with documented remediation or delegation plans per team ownership model
- Validate configuration compliance against CIS benchmarks and BMO security baselines; raise Puppet module gaps to Platform Engineering for remediation
- Coordinate patching schedules and maintenance windows; ensure BMO patch schedule adherence across the Linux estate
- Support evaluation and adoption of ServiceNow as the unified patching orchestration layer, replacing manually-raised per-patch Jira change tickets with automated scheduled pipeline execution
- Deploy and validate endpoint security agents (CrowdStrike/Falcon) across Linux hosts in partnership with the Linux teamContribute to bi-weekly vulnerability reporting for senior leadership.
📌 Linux Security Engineer / Toronto, ON (Onsite) - FTE
🏢 AceStack
📍 Toronto