Skills and Responsibilities: • Partner with Linux and Platform Engineering teams to define and enforce hardening standards new Linux systems must enter the estate compliant from day one, not remediated after the fact • Own the Linux vulnerability lifecycle: triage findings from Qualys, prioritize by SLA, and work with the • Linux team to drive remediation through Puppet and Foreman • Track and report missed-target vulnerabilities across BTN and CMRI Linux estates; escalate with documented remediation or delegation plans per team ownership model • Validate configuration compliance against CIS benchmarks and BMO security baselines; raise Puppet module gaps to Platform Engineering for remediation • Coordinate patching schedules and maintenance windows; ensure BMO patch schedule adherence across the Linux estate • Support evaluation and adoption of ServiceNow as the unified patching orchestration layer, replacing manually-raised per-patch Jira change tickets with automated scheduled pipeline execution • Deploy and validate endpoint security agents (CrowdStrike/Falcon) across Linux hosts in partnership with the Linux teamContribute to bi-weekly vulnerability reporting for senior leadership"