Logo

Principal Linux Security Engineer

CIQ • Remote


No Relocation

Posted: October 6, 2026

Job Description

CIQ OVERVIEW

CIQ builds the enterprise infrastructure that powers the world's most demanding workloads. From the operating system layer through AI infrastructure, high-performance computing, and cloud-native orchestration, CIQ delivers the speed, security, scalability, and sovereignty that major enterprises, government agencies, and research institutions depend on.

CIQ is the founding support and services partner of Rocky Linux and the developer of the RLC Pro family of Enterprise Linux distributions, Fuzzball workload orchestration, Warewulf Pro cluster provisioning, and Ascender Pro automation. Our customers include some of the largest and most technically sophisticated organizations in the world, working across HPC, AI/ML, defense, and regulated industries.

We are a company of builders, operators, and open source practitioners. If you want to do work that matters, at a company that is genuinely changing how enterprise infrastructure gets built and run, we want to talk.

POSITION SUMMARY 

This isn't a traditional job description. It describes the specific person we're looking for: an engineer who understands the Linux operating system from a security perspective.

What does that mean in practice? Here is what we need from this role:

  • How security errata works in an operating system (CSAF, VEX, Advisories) and how to create them and use them in various aspects of the systems, from updateinfo in repos to a security feed for security scanners to ingest. 
  • Compliance on an operating system - Building out STIG and DIS profiles. Understanding how to improve OpenSCAP and building Ansible scripts to apply the security profiles, not just applying scripts that someone else built.
  • Proactive security in an operating system, like build flags, LKRG, SELinux. How to really secure the OS in a way that also allows it to be usable. Not hooking it up to the internet is not an acceptable security answer.
  • How to build tools to make the above happen faster and interact with AI to speed up development, testing, and release. 
  • CVE scoring - How they are scored and what that means.  It doesn’t mean that you know how to look up a score in NIST, but it means you have used the CVSS calculator and you know why it is scored a 7.8 vs. a 5.5
  • CVE affectedness - You understand how to determine if a piece of software is affected by a CVE and how different aspects of build and configuration change the affectedness. 

Is This Role Right for You?

If the requirements above don't resonate with your experience, this position is likely not the right fit. If you meet most of them, we'd like to hear from you. We're looking for candidates who are genuinely engaged with this work, so we ask that automated or mass applications be avoided.

EDUCATION AND EXPERIENCE 

  • Proven work experience in Security and/or Linux Engineering with a focus on the Linux OS.
  • At least 4 years of experience doing security in Linux and at least 2 years of experience building Linux Packages

BENEFITS

  • Medical, dental, and vision insurance.

  • Flexible paid time off.

  • Employee stock options.

  • Remote work; no travel required for most positions.