Job Summary:
Tesla is seeking a Staff Site Reliability Engineer specializing in Platform Security to manage and enhance security across its Kubernetes clusters. The role involves conducting security audits, implementing RBAC strategies, and collaborating with the Infosec team to ensure a robust security posture throughout the company's cloud infrastructure.
Responsibilities:
• Conduct comprehensive security audits across all Kubernetes clusters, identifying RBAC misconfigurations, overprivileged service accounts, and policy gaps
• Design and implement RBAC strategy enforcing principle of least privilege (PoLP) across all clusters, namespaces, and workloads with granular role definitions and access controls
• Establish continuous audit and compliance monitoring using admission controllers (OPA/Gatekeeper, Kyverno), audit logging, and runtime security tooling to detect and prevent policy violations
• Harden container and pod security by implementing Pod Security Standards (PSS/PSA), security contexts, network policies, and eliminating privileged containers and root execution
• Secure software supply chain through image scanning, signing (Sigstore/Cosign), SBOM generation, admission webhooks, and private registry governance
• Deploy cluster-wide security mitigations at scale using GitOps workflows, policy-as-code, and automated remediation across the entire cluster fleet
• Implement network segmentation and zero-trust architecture using service mesh, network policies, mTLS, and microsegmentation to limit blast radius
• Build secrets management infrastructure migrating from in-cluster secrets to external vaults (HashiCorp Vault, AWS Secrets Manager) with dynamic credential rotation
• Collaborate with Infosec and red team on threat detection and automated incident response playbooks
• Security tooling standardization and automation, creating reusable Helm charts, Terraform modules, and CI/CD pipelines for consistent security posture across all clusters
Qualifications:
Required:
• 7+ years of Kubernetes security experience with proven track record securing large-scale, multi-cluster production environments
• Deep RBAC expertise including ClusterRoles, RoleBindings, service account management, and complex multi-tenant authorization models
• Active contributor to major open-source container security projects (e.g., Falco, Open Policy Agent, Trivy, Kubescape, KubeArmor, Cilium, or CNCF security projects) with verifiable GitHub contributions
• Expert-level knowledge of Kubernetes security primitives: Pod Security Standards, SecurityContext, NetworkPolicies, admission controllers, audit logging, and CIS benchmarks
• Hands-on experience with security tooling: OPA/Gatekeeper, Kyverno, Falco, Trivy, Aqua Security or similar platforms
• Strong automation and IaC skills: Terraform, Helm, GitOps (ArgoCD/Flux), Python/Go for building security automation and policy-as-code frameworks
• Container security expertise: Image hardening, vulnerability management, supply chain security (SLSA, SBOM, Sigstore), and rootless/distroless containers
• Experience deploying changes at scale across distributed cluster fleets using multi-cluster management tools (Rancher, Anthos, EKS Anywhere, Cluster API)
• Strong incident response and forensics background in containerized environments, including experience with eBPF-based monitoring, log analysis (ELK/Splunk), and breach containment strategies
Company:
Tesla is an electric vehicle and clean energy company that provides electric cars, solar, and renewable energy solutions. Founded in 2003, the company is headquartered in Austin, USA, with a team of 10001+ employees. The company is currently Late Stage.