Bastion Talent is retained by a specialist cybersecurity firm working in critical infrastructure to fill this role. Our client works with large organisations — operators, governments and enterprises — to find and fix serious security weaknesses. The client’s identity is shared with shortlisted candidates under NDA.
The role
Secure the client’s Kubernetes platforms — including bare-metal clusters running sensitive, security-critical telecom workloads — from the control plane and container supply chain through to runtime.
Key responsibilities
- Harden Kubernetes clusters: CIS benchmarks, admission control, network policies and RBAC.
- Secure the container supply chain: image signing, scanning and provenance.
- Implement policy-as-code (OPA/Gatekeeper, Kyverno) and runtime security / threat detection (Falco or similar).
- Manage secrets, workload identity and service-mesh security.
- Assess and strengthen multi-tenant isolation and network segmentation.
- Support audits and penetration tests of cloud-native infrastructure and remediate findings.
What we’re looking for
- Deep Kubernetes expertise, ideally including bare-metal deployments.
- Strong grasp of container and cloud-native security: CIS, RBAC, network policies, admission control.
- Policy-as-code (OPA/Gatekeeper, Kyverno), runtime security (Falco), supply-chain security (Sigstore/cosign).
- Linux, infrastructure-as-code and CI/CD security.
- Scripting in Go, Python or Bash.
- Bonus: telecom, NFV or CNF exposure.
- Fluent English (mandatory); French optional.
Engagement & location
This position is fully remote within Europe (CET overlap preferred). Unless otherwise stated, it can be structured either as a freelance / contract engagement or as full-time employment — whichever suits you.
About the client
Our client is a specialist cybersecurity firm and a recognised leader in offensive security for critical infrastructure. They help large organisations — operators, governments and major enterprises — find and fix serious weaknesses in the systems that keep essential services running, pairing hands-on security assessment with their own detection and analysis tooling. The team is small, highly technical and fully distributed across Europe.
Hiring process
- Intro call (10–20 min)
- Manager call (30 min)
- Capability exercise
- Leadership call (30 min)