08 Sep
|
AceStack
|
Toronto
Linux Security Engineer Location: Toronto, ON Work Arrangement: Onsite Employment Type: Fulltime FTE - Permanent Experience: 6 8 Years Job Description: We are seeking an experienced Linux Security Engineer to strengthen Linux security, vulnerability management, configuration compliance, and patching across the enterprise Linux estate.
The ideal candidate will have strong experience with Linux hardening, Qualys, Puppet, Foreman, CIS benchmarks, security baselines, patch management, and endpoint security solutions.
Key Responsibilities Partner with Linux and Platform Engineering teams to define and enforce Linux hardening standards, ensuring new Linux systems are compliant with security requirements from day one.
Own the Linux vulnerability management lifecycle , including triaging findings from Qualys , prioritizing vulnerabilities based on SLA, and coordinating remediation with Linux teams.
Drive vulnerability remediation through Puppet and Foreman , ensuring vulnerabilities are addressed within defined timelines.
Track and report missed-target vulnerabilities across BTN and CMRI Linux environments.
Escalate overdue or missed vulnerabilities with documented remediation plans or delegation plans based on the team ownership model.
Validate Linux configuration compliance against CIS Benchmarks and enterprise security baselines.
Identify and raise Puppet module gaps to Platform Engineering teams and coordinate remediation.
Coordinate Linux patching schedules and maintenance windows and ensure adherence to enterprise patching requirements.
Support the evaluation and adoption of Service
Now as a unified patch orchestration platform.
Help transition from manually created, per-patch Jira change tickets to automated scheduled pipeline execution through Service
Now.
Deploy, configure, and validate endpoint security agents , including Crowd
Strike Falcon , across Linux hosts in partnership with Linux engineering teams.
Monitor endpoint security agent deployment and ensure Linux hosts maintain required security coverage.
Contribute to bi-weekly vulnerability reporting for senior leadership, providing status, trends, risks, remediation progress, and missed-target details.
Collaborate with security, infrastructure, platform, and application teams to improve Linux security posture and remediation processes.
Required Skills & Experience 6 8 years of experience in Linux Security, Linux Engineering, Infrastructure Security, or a related role.
Strong hands-on experience with Linux security hardening and vulnerability management .
Experience with Qualys for vulnerability assessment, triage, prioritization, and remediation tracking.
Strong experience with Puppet for configuration management and security remediation.
Experience with Foreman and Linux infrastructure management.
Strong understanding of CIS Benchmarks and enterprise Linux security baselines.
Experience with Linux patch management , maintenance windows, and vulnerability remediation SLAs.
Experience with Service
Now for change management, patch orchestration, or automated workflows.
Understanding of Jira change management and migration toward automated change/pipeline processes.
Hands-on experience deploying and validating Crowd
Strike Falcon or similar endpoint security agents on Linux systems.
Strong understanding of vulnerability lifecycle management, security compliance, remediation tracking, and reporting.
Ability to work effectively with Linux Engineering, Platform Engineering, Cybersecurity, and Infrastructure teams .
Solid analytical, troubleshooting, documentation, and communication skills.
Preferred Skills Experience supporting large-scale enterprise Linux estates .
Experience with automated patching and configuration management pipelines.
Knowledge of Dev
SecOps and infrastructure security automation .
Experience preparing vulnerability and compliance reports for senior leadership .
Financial services or other highly regulated enterprise environment experience is an asset.
Key Skills Linux Security | Linux Hardening | Qualys | Puppet | Foreman | CIS Benchmarks | Vulnerability Management | Patch Management | Service
Now | Jira | Crowd
Strike Falcon | Endpoint Security | Configuration Compliance | Security Baselines | SLA Management | Remediation | Infrastructure Security | Automation | Enterprise Linux
📌 Linux Security Engineer || Toronto, ON - Onsite || Fulltime FTE
🏢 AceStack
📍 Toronto