Description:
Linux Security Engineer
Location: Toronto, ON
Work Model: Onsite
Employment Type: Full-Time (FTE)
Experience: 6 -8 + Years
6-8 years -----Skills and Responsibilities:
- Partner with Linux and Platform Engineering teams to define and enforce hardening standards new Linux systems must enter the estate compliant from day one, not remediated after the fact.
- Own the Linux vulnerability lifecycle: triage findings from Qualys, prioritize by SLA, and work with the Linux team to drive remediation through Puppet and Foreman
- Track and report missed-target vulnerabilities across BTN and CMRI Linux estates; escalate with documented remediation or delegation plans per team ownership model
- Validate configuration compliance against CIS benchmarks and BMO security baselines; raise Puppet module gaps to Platform Engineering for remediation
- Coordinate patching schedules and maintenance windows; ensure BMO patch schedule adherence across the Linux estate
- Support evaluation and adoption of ServiceNow as the unified patching orchestration layer, replacing manually-raised per-patch Jira change tickets with automated scheduled pipeline execution
- Deploy and validate endpoint security agents (CrowdStrike/Falcon) across Linux hosts in partnership with the Linux teamContribute to bi-weekly vulnerability reporting for senior leadership.