
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
We are seeking a skilled and motivated Container Security Engineer to strengthen our cybersecurity posture across containerized environments. This role focuses on the identification, analysis, and mitigation of vulnerabilities and misconfigurations in container images, Kubernetes clusters, and related orchestration platforms. The ideal candidate will bring technical expertise in container security tooling, vulnerability management, and secure configuration practices, while driving collaboration with DevOps and engineering teams to embed security into the container lifecycle.
Job Responsibilities:
• Perform container image scanning to identify vulnerabilities, misconfigurations, and insecure base images.
• Manage and optimize container security platforms.
• Develop and enforce Kubernetes security baselines, focusing on RBAC, network policies, secrets management, and runtime controls.
• Partner with DevOps and applications teams to integrate security checks into CI/CD pipelines.
• Continuously monitor for container runtime threats, privilege escalations, and drift from security baselines.
• Collaborate across engineering, operations, and compliance teams to ensure vulnerabilities and misconfigurations are remediated in line with risk priorities.
• Research and track emerging container security risks, threats, and industry best practices.
• Contribute to governance, policies, and playbooks for container security lifecycle management.
Required Qualifications
• 3+ years experience in container or cloud-native security
• Hands-on experience with Kubernetes and container runtimes
• Experience with container security scanning tools and vulnerability management tools (Aqua, Wiz, Qualys)
• Knowledge of Kubernetes security principles
• Familiarity with linuz security fundamentals, container isolation, and namespace/cgroups
• Strong problem-solving, analytical, and communication skills.
• Understanding of DevSecOps and CI/CD pipeline integration through security engineering lifecycles.
• Ability to communicate complex concepts to all levels of understanding and technical ability.
Desired Qualifications:
• CISSP/CCSP/CISM
• Cloud specific Security certifications such as SANS/GIAC
• Vendor specific and relevant certifications – AZ-500, SC-200, AZ-204, CKA, CKS, RHCE, etc
• Bachelor’s degree in Computer Science, Cybersecurity, or related field, or equivalent work experience.
Shift:
1st shift (United States of America)Hours Per Week:
40Learn more about this role