Teladoc Health
Website:
teladochealth.com
Job details:
About the Role
The Cloud Native Security Lead will ensure that containerized workloads and orchestration platforms are securely configured, processes are developed and maintained, and systems are continuously monitored and protected against potential threats. This role demands a robust understanding of Kubernetes security across Azure AKS with a keen ability to identify and mitigate risks in container orchestration environments.
Responsibilities:
- Collaborate with DevOps, platform engineering, application development, and operations teams to identify and drive solutions for cloud-native security projects.
- Define, document, and implement robust security controls for Kubernetes clusters across multiple cloud providers (Azure).
- Establish and maintain security monitoring and governance for containerized workloads and orchestration platforms.
- Design and implement security policies using tools such as OPA/Gatekeeper, Wiz, Kyverno, and Pod Security Standards/Admission Controllers.
- Continuously seek opportunities for automation and process improvements in cloud-native security workflows.
- Stay current with Kubernetes security best practices, CVEs, and emerging threats, translating these into effective security solutions across multi-cloud environments.
- Conduct regular security assessments and audits of Kubernetes clusters and cloud-native applications to ensure compliance with internal policies and external regulations.
- Develop and deliver training and awareness programs on cloud-native and Kubernetes security best practices for internal teams.
Qualifications:
- 8+ years of experience in Cloud Security or related disciplines, including Application Security, Microservices Security, DevSecOps, DevOps, and/or Site Reliability Engineering (SRE).
- 6+ years of experience in various information security domains, including threat modeling, secure coding, cryptography, system administration, and network security.
- 3+ years of hands-on experience with Kubernetes security, including implementing security controls across multiple cloud providers.
- 5+ years' experience and deep understanding of cloud security principles and experience with major cloud platforms (AWS, Azure).
- Strong knowledge of container security, including image scanning, runtime protection, and supply chain security.
- Experience with Kubernetes-native security tools and practices (RBAC, Network Policies, admission controller, Service Mesh security, Secrets management, workload identities, SPIFFE).
Preferred Skills:
- Familiarity with cloud-native tooling and platforms (e.g., Helm, ArgoCD, Istio, Cilium, Azure Service Mesh, Trivy).
- Experience with Infrastructure as Code (Terraform, CloudFormation) and GitOps practices.
- Hands-on experience with security scanning and policy enforcement tools (Wiz, Crowdstrike, Synk).
- Experience with security information and event management (SIEM) tools like Microsoft Sentinel.
- Relevant certifications such as CKS (Certified Kubernetes Security Specialist), CKA (Certified Kubernetes Administrator), or Azure Security Engineer.
- Advanced degree in Computer Science, Information Security, or equivalent experience.
- Publications or presentations in cloud-native security forums or conferences (e.g., KubeCon, Cloud Native Security Con).
Click on Apply to know more.