Develop tooling to generate and automate regulatory benchmark guidance
AI driven tooling (MCP servers/toolsets) that integrates with IDEs (Claude Code/Cursor)
Understanding Compliance Operator resources, like CustomRules and Profiles
Implementing checks using multiple scanning technologies, like OpenSCAP and CEL expressions
Developing and maintaining operators that improve OpenShift security posture
Contribute to industry benchmark regulatory bodies where applicable (CIS)
Requirements
Have an understanding of security and hardening techniques for container management (e.g., Security Context Constraints, Validation Admission Policies, RBAC)
Have an understanding of Machine Configs, SCCs and RHCOS (operating systems optimized for running containers)
Have an understanding of Concept of operators within the Kubernetes ecosystem, and how they function and OLM (Red Hat’s package manager for operators)
Fluent in git
Experience developing and maintaining projects in Golang and/or Python
Project management experience and tracking with task tracking tools (e.g., Jira)
Compliance Scanning workflows with various tools like Remediate, Rescan or Repeat
Familiarity with specific regulatory bodies and their benchmarks (CIS, PCI, DISA, NIST, etc.)
Familiar with Cursor and/or Claude Code
since we’re looking to lean heavily on AI tools to help with the profiles
Experience with GitOps-based workflows or Tekton pipelines