Point72

Linux Security Lead

Point72 • $200K — $300K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of experience in Linux system administration or security engineering, with 3 years focused on Linux security hardening in enterprise environments.
  • Expertise in configuration management tooling like Ansible and infrastructure-as-code practices.
  • Hands-on experience with CIS Benchmarks for Linux and familiarity with the NIST Cybersecurity Framework.
  • Proven ability to build drift detection and reconciliation tooling; experience with endpoint monitoring platforms.
  • Knowledge of Linux kernel security features and secure engineering principles.
  • Experience in an engineering delivery model with sprint cadence and backlog prioritization.
  • Collaboration skills to communicate posture risk with various stakeholders.

Responsibilities

  • Own the end-to-end Linux security baseline program, enforcing standards through Ansible and configuration management tooling.
  • Build automated drift detection workflows translating desired state into enforcement and generating alerts.
  • Integrate Linux compliance and vulnerability signals into detection pipelines and access policies.
  • Partner with security automation teams to create scalable delivery patterns with validation safeguards.
  • Maintain exception governance, managing explicit ownership and compensating controls.
  • Drive vulnerability closure for Linux exposure classes and integrate secure engineering principles into standards.
  • Contribute to CIS Benchmark compliance and maintain mappings for audit and regulatory purposes.

Benefits

  • Fully-paid health care benefits
  • Generous parental and family leave policies
  • Mental and physical wellness programs
  • Volunteer opportunities
  • Non-profit matching gift program
  • Support for employee-led affinity groups
  • Tuition assistance
  • 401(k) savings program with an employer match
Full Job Description
What you'll do

As the Linux Security Lead, you will own and drive a consistent and enforceable security posture across the firm's Linux fleet - building enforceable baselines, automated drift detection, and verified remediation patterns that scale across a hybrid on-premises and cloud environment. You will report directly to the Head of Infrastructure Security and serve as the technical authority for Linux hardening, operating within a sprint-based engineering discipline and working closely with the Linux Infrastructure team. Specifically, you will:

  • Own the Linux security baseline program end-to-end, including defining hardening intent per distribution and workload class (RHEL, Ubuntu, Amazon Linux), enforcing standards through Ansible and configuration management tooling, and driving continuous drift reconciliation.
  • Build and operate automated drift detection workflows by translating desired state into enforcement, generating alerts with remediation paths, and reducing MTTR for high-risk deviations.
  • Integrate Linux posture signals, including compliance state, vulnerability exposure, and audit telemetry, into broader access policy and detection pipelines.
  • Partner with security automation teams to build scalable, version-controlled delivery patterns with validation and rollout safeguards.
  • Maintain exception governance discipline, such as time-bounded exceptions with explicit ownership, compensating controls, and regular burn-down reviews.
  • Drive verified vulnerability closure for Linux-specific exposure classes
  • Establish and embed Linux-specific secure engineering principles, such as least privilege daemons, immutable configuration patterns, kernel hardening, and audit telemetry standards, into engineering standards and peer review processes.
  • Contribute to the firm's broader CIS Benchmark compliance posture, maintaining mappings to CIS Controls v8 and NIST CSF 2.0 for audit and regulatory defensibility.


What's required
  • 6+ years of experience in Linux system administration or security engineering, with at least 3 years focused on Linux security hardening and compliance in an enterprise environment.
  • Demonstrated expertise with configuration management tooling, specifically Ansible, and infrastructure-as-code practices, including version control, peer review workflows, and pipeline-driven enforcement.
  • Hands-on experience with CIS Benchmarks for Linux (RHEL, Ubuntu, or equivalent) and familiarity with the NIST Cybersecurity Framework (CSF 2.0) and STIG compliance frameworks.
  • Proven ability to build and operate drift detection and reconciliation tooling, as well as experience with Qualys, CrowdStrike, or equivalent endpoint monitoring platforms.
  • Working knowledge of Linux kernel security features such as SELinux or AppArmor, auditd, system hardening, privilege separation, and secure boot patterns.
  • Experience operating in an engineering delivery model, specifically with sprint cadence, backlog prioritization, Definition of Done tied to verification, and peer review for high-impact changes.
  • Strong collaboration skills with the ability to define and maintain explicit interfaces with adjacent teams and communicate posture risk clearly to technical and non-technical stakeholders.
  • Commitment to the highest ethical standards.


We take care of our people

We invest in our people, their careers, their health, and their well-being. When you work here, we provide:
  • Fully-paid health care benefits
  • Generous parental and family leave policies
  • Mental and physical wellness programs
  • Volunteer opportunities
  • Non-profit matching gift program
  • Support for employee-led affinity groups representing women, minorities and the LGBT+ community
  • Tuition assistance
  • A 401(k) savings program with an employer match and more


The annual base salary range for this role is $200,000-$300,000 (USD), which does not include discretionary bonus compensation or our comprehensive benefits package. Actual compensation offered to the successful candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level, among other things.

About Point72

Point72 Asset Management is a hedge fund and family office founded by Steven Cohen in 2014. The company is headquartered in Stamford, Connecticut and manages over $16 billion in assets. Point72 primarily invests in public equity markets, but also has a private equity arm. The company has a global presence with offices in New York, London, Hong Kong, Tokyo, and Singapore. Point72 has been involved in several high-profile legal cases, including a $1.8 billion settlement with the SEC in 2013.
Learn more about Point72
Size
1,500 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Point72

More Information Technology Jobs

Find similar Linux Security Lead jobs: