Security Software Engineer — Container Network Security
TLDR
Build AI-assisted traffic inspection and prevention components for Kubernetes clusters, balancing Linux networking performance with enforceable threat-detection rules.
We are looking for a security programmer to help us build the next generation AI container network security system.
This role sits at the intersection of systems programming, network security, and cloud-native infrastructure.
What You'll Do
- Help design and implement traffic inspection and prevention components that run in-line within Kubernetes clusters (as a DaemonSet, sidecar, or CNI-integrated component)
- Build or contribute to protocol parsers and signature/rule-matching engines
- Contribute to an AI-assisted signature generation pipeline
- Work with the Linux networking stack to intercept and act on traffic with acceptable latency overhead
- Help ensure the data path is efficient enough to run under the resource budgets typical of Kubernetes workloads
- Collaborate with detection research and cloud security teams to translate threat intelligence into enforceable rules and behaviors
- Professional experience in Rust or C/C++ (comfort with both, or willingness to pick up the second, is a plus — not a hard requirement)
- Security background - experience with developing security products - such as IPS, firewall, researcher, API security, etc
- General familiarity with Kubernetes and at least one public cloud (AWS, Azure, or GCP) — production experience is preferred, but strong infrastructure/networking experience elsewhere is also welcome
- Comfort working on systems/infrastructure-level software rather than purely application-level code
- Hands on AI SDLC experience
- Curious
- Tech savvy
- Good communication skills
- Independent
Advantage
- Experience with DPI engines, protocol parsers, or signature-matching systems (e.g., Snort/Suricata-style rules)
- Exposure to ML/AI approaches for anomaly detection, classification, or rule generation
- Linux kernel/networking internals: netfilter/nftables, eBPF/XDP, TCP/IP, TLS
- Kubernetes networking specifics: CNI, NetworkPolicy, service mesh data planes (Envoy/Istio)
- Container runtime/isolation experience: containerd/CRI-O, namespaces/cgroups
- Low-latency/high-throughput systems experience (zero-copy design, lock-free structures)
- Familiarity with attacker techniques and IPS/IDS evasion
- Comfort with ambiguous, greenfield technical work
Check Point Software builds advanced cybersecurity solutions that protect over 100,000 organizations globally from sophisticated cyber and AI-driven threats. Their innovative platforms, including Agentic Network Security Orchestration, leverage AI to secure hybrid networks, cloud environments, and digital workspaces, enabling customers to navigate a complex digital landscape with confidence.
- Founded
- Founded 1993
- Employees
- 500+ employees
- Industry
- computer & network security
- Funding stage
- Public
- Stock ticker
- Publicly traded (CHKP)
- Total raised
- $1.8B raised
- Last funding
- Raised December 2025