Full-Time
Cloud-native network security & observability platform
CA$130k - CA$150k/yr
Vancouver, BC, Canada
Hybrid
Hybrid work model with on-site in Vancouver, Canada.
See people who can refer or advise you
Tigera provides an open-core enterprise platform for secure application connectivity in cloud-native environments, built on the open-source Calico project. Calico is a unified Kubernetes networking, security, and observability solution that runs across major cloud providers and distributions, using a high-performance eBPF data plane and gateways to manage traffic between containers and traditional workloads. It differentiates itself by offering enterprise editions (Calico Enterprise and Calico Cloud) that add full-stack observability, runtime security, and CNAPP capabilities beyond the OSS, with a strong open-source heritage. Its goal is to help organizations securely connect, monitor, and protect cloud-native apps across multi-cloud and multi-cluster environments.
Company Size
51-200
Company Stage
Series B
Total Funding
$53M
Headquarters
San Francisco, California
Founded
2016
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Remote Work Options
Flexible Work Hours
Tigera launches eBPF-powered Calico for VMs on Kubernetes: VM migration that doesn't require rebuilding the network. Jul 23, 2026, 09:00 ET Organizations who have decided to migrate their VMs from VMware require an alternative to NSX for network automation and simplicity of operations for virtual machines and containers running on Kubernetes SAN JOSE, Calif., July 23, 2026 /CNW/ - Tigera, Inc., the inventor and maintainer of Calico Open Source and the company behind Calico and Lynx, today launched Calico for VMs on Kubernetes: the industry's first and only eBPF-powered platform to deliver networking and network security for both virtual machines and containers on a single Kubernetes-native control plane. With it, enterprises that have already decided to migrate from VMware can move their VM estates onto Kubernetes and keep every networking and security outcome they had under NSX, without re-designing their network, making the migration process seamless. Enterprises that have decided to migrate their VMs from VMware to Kubernetes platforms such as OpenShift, VKS, SUSE, Mirantis, Canonical, etc., are discovering that migrating compute and storage are the easy parts. The hard part is the network: The VM's network identity is hardcoded into surrounding infrastructure, business rules, and processes. Any changes to the network identity will break all these things. Teams that are used to managing VM networking with NSX are discovering that the native Kubernetes network capabilities are complex, and lack the functionality that VM admins rely on for efficient operations. VMware users who are migrating to Kubernetes have four broad objectives: * Migrate a VM as-is (lift & shift) to minimize disruption to operations and meet tight timelines for migration * Modernize their network architecture to eliminate hard-coded dependencies on their legacy networking stack (VLANs, Firewalls, DNS, DHCP) to reduce costs and simplify operations. In phase 2, teams would like to transition from an L2 network design to an L3 network design, on their own timeline. * Ensure that the new architecture doesn't lock them into a new Kubernetes platform and that they keep their platform options open for the future as they plan for AI workloads. * Build a converged platform that can house both containers and VMs to prepare for AI workloads and agents. To control token costs and keep models physically close to the proprietary data that lives in their own data centers, organizations are increasingly self-hosting open large language models. That pulls high-value, data-adjacent AI workloads back on-prem and onto the same converged platform that already runs everything else. One operating model across any workload, any environment Because the same policy, routing, egress, QoS, and observability patterns apply to VMs and containers alike, platform teams operate a single operating model instead of two. That model extends consistently across clusters, Kubernetes distributions, and on-premises, cloud, and edge deployments, eliminating platform-specific configuration and the vendor lock-in that defined the previous era. Organizations can migrate first and modernize later: preserve existing IPs, VLANs, and firewall rules on day one, then consolidate to Kubernetes-native patterns on their own timeline, without fragmenting operations along the way. Calico for VMs on Kubernetes ends complexity and delivers the network automation and simplicity of operations for VMs running in Kubernetes that VM administrators are used to with NSX. It is one network, one security policy model, and one observability stack spanning VMs and containers alike, so a virtual machine migrated to Kubernetes keeps its IP address, lives on the same network as the containers beside it, and inherits the same microsegmentation, routing, load balancing, quality of service, and flow visibility. What NSX did for the data center, Calico now does natively inside Kubernetes for both workload types, simultaneously. "The market is converging on one self-hosted platform for containers and VMs, and the economics and AI trends driving it are only accelerating," said Pervez Sikora, President at Tigera, Inc. "Calico enables the convergence of VMs and containers under one management plane, turning that converged platform from an aspiration into an operational reality." A complete stack for VM networking on Kubernetes Calico for VMs on Kubernetes is designed to help teams connect, secure and observe VM workloads through a unified set of networking, security and observability capabilities. Every capability and outcome delivered by NSX has a direct Kubernetes-native counterpart in Calico: * Connect - Calico Networks provide connectivity to VM workloads and to the networks and services around them. L2 Bridge capabilities can extend existing network VLANs (Segments) into Kubernetes for workloads that require Layer 2 or network continuity during and after migration. BGP-based routing, egress gateway, load balancing and ingress gateway functions support delivering applications and services to consumers. * Secure - Calico network policy, policy tiers, staged policy and DNS policy provide Kubernetes-native controls for access enforcement and microsegmentation. Policies can be planned, monitored and validated before enforcement, helping teams maintain security posture as workloads move and apply consistent controls across VMs and containers. * Observe - Calico Service Graph, flow logs, DNS logs, L7 visibility and packet capture provide context for troubleshooting and security operations. Teams can investigate VM-to-VM, VM-to-pod, pod-to-pod and cross-cluster flows with Kubernetes-aware workload context using eBPF-enabled deep packet inspection. Every NSX outcome, delivered Kubernetes-natively The Calico Unified Platform is built around a simple principle for architects who have been tasked with a VM migration project: preserve outcomes, not objects. Every capability NSX administrators depend on has a direct, Kubernetes-native counterpart in Calico: * Connectivity and networking - L2 bridge that extends existing VLANs into Kubernetes so VMs keep Layer 2 continuity during migration. * Segmentation and isolation - NSX segments, overlay networks, and VLAN-backed segments map to Calico networks, overlay networks * Distributed firewalling - the NSX distributed firewall maps to Calico network policy, policy tiers, and staged policy, enforcing east-west microsegmentation on workload identity rather than IP address, with safe rollout before enforcement. * North-south control and routing - Tier-0 and Tier-1 gateway behavior maps to Calico BGP peering, Multi-VRF tenant routing, and egress gateways, advertising VM and load balancer IPs upstream with predictable source identity. * Application delivery - the NSX Advanced Load Balancer (AVI) maps to the Calico Load Balancer and Ingress Gateway, providing stable VIPs, Maglev-based L4 distribution, and L7 routing, all Kubernetes-native. * Workload mobility - vMotion maps to KubeVirt live migration with Calico, preserving IP addresses and policy with minimal packet loss and fast route convergence as VMs move between nodes. * Quality of service and observability - NSX QoS and Traceflow map to Calico QoS controls and a full observability stack: Service Graph, flow logs, DNS logs, L7 logs, and packet capture, with complete Kubernetes workload context. * Multi-cluster Ops - Cluster-mesh to help manage multiple clusters across regions. Proven at scale Calico secures more than 1 million clusters daily and is recognized as a Leader and Outperformer by GigaOM for container networking. Leading enterprises including NVIDIA, Royal Bank of Canada, Bloomberg, Chipotle, GoDaddy, and Upwork rely on the Calico platform. That same platform is now extended to carry their virtual machines. Availability Calico for VMs on Kubernetes is now generally available. To learn more about migrating VMs without losing NSX-grade network automation and security, and to see the platform in action, schedule a demo or view a self-paced demo. About Tigera Tigera, Inc., the inventor and maintainer of Calico Open Source and the company behind Calico and Lynx, secures and governs VMs, Kubernetes workloads and AI agents across the enterprise by providing deep visibility and enforcement control via eBPF. The company's offerings secure Kubernetes workloads and AI agents across 1M+ clusters in multicloud and hybrid environments. Leading enterprises including NVIDIA, Royal Bank of Canada, Bloomberg, Chipotle, GoDaddy, and Upwork trust Tigera for their Kubernetes security, networking and AI agent security needs. SOURCE Tigera, Inc. Media Contact: Tigera Press Relations, [email protected]
Tigera has launched Calico for VMs on Kubernetes, an eBPF-powered platform enabling enterprises to migrate virtual machines from VMware to Kubernetes without redesigning their networks. The solution provides networking and network security for both VMs and containers on a single Kubernetes-native control plane. The platform addresses challenges organisations face when migrating from VMware's NSX, particularly preserving network identities hardcoded into infrastructure and business processes. It allows VM administrators to maintain existing IP addresses, VLANs, and firewall rules whilst transitioning to Kubernetes-native patterns. Calico for VMs delivers NSX-equivalent capabilities including connectivity, security controls, and observability features. The platform supports workload mobility, distributed firewalling, and multi-cluster operations. Tigera reports that Calico currently secures over 1 million clusters daily, with clients including NVIDIA, Royal Bank of Canada, and Bloomberg. The solution is now generally available.
Tigera launches Calico Unified Platform 3.23: the definitive VMware migration solution with one network and one security model for every VM and container on Kubernetes. Organizations undertaking VMware migration initiatives require an alternative to NSX for network automation and simplicity of operations for virtual machines and containers in a single unified platform. Tigera, Inc., the inventor and maintainer of Calico Open Source and the company behind Calico and Lynx, launched the Calico Unified Platform: the industry's first and only platform to deliver networking and network security for both virtual machines and containers on a single Kubernetes-native control plane.With it, enterprises migrating from VMware can move their VM estates onto Kubernetes and keep every networking and security outcome they had under NSX, without operating two parallel stacks and without redesigning their network. The timing is not incidental. Broadcom's post-acquisition licensing changes have driven significant price increases pushing a wave of organizations to move virtual machines off vSphere and onto Kubernetes using KubeVirt and OpenShift Virtualization. But migrating the VM is the easy part. The hard part is the network: VMs depend on static IPs, VLANs, distributed firewalls, and route advertisement that NSX provided, and none of that functionality is Kubernetes native. Teams have been forced to bolt a legacy network-virtualization stack onto their new Kubernetes platform, recreating the very complexity and lock-in they are migrating off of VMware to escape. The Calico Unified Platform ends that complexity. It is one network, one policy model, and one observability stack spanning VMs and containers alike, so a virtual machine migrated to Kubernetes keeps its IP address, lives on the same network as the containers beside it, and inherits the same microsegmentation, routing, load balancing, quality of service, and flow visibility. What NSX did for the data center, Calico now does natively inside Kubernetes for both workload types, simultaneously. "Organizations are urgently exploring modernization projects to migrate off of VMware estates" said Alain Mayer, VP, product, Tigera, Inc. "With the Calico Unified Platform, a VM and a container are first-class citizens of the same network, governed by the same policy, seen through the same lens. This is the best solution on the market for automating and simplifying networking and network security across VMs and containers, solving one of the most difficult components in the migration process." Every NSX outcome, delivered Kubernetes-natively The Calico Unified Platform is built around a simple principle for architects considering a VMware migration project: preserve outcomes, not objects. Every capability NSX administrators depend on has a direct, Kubernetes-native counterpart in Calico: * Segmentation and isolation - NSX segments, overlay networks, and VLAN-backed segments map to Calico networks, overlay networks, and an L2 bridge that extends existing VLANs into Kubernetes so VMs keep Layer 2 continuity during migration * Distributed firewalling - the NSX distributed firewall maps to Calico network policy, policy tiers, and staged policy, enforcing east-west microsegmentation on workload identity rather than IP address, with safe rollout before enforcement * North-south control and routing - Tier-0 and Tier-1 gateway behavior maps to Calico BGP peering, Multi-VRF tenant routing, and egress gateways, advertising VM and load balancer IPs upstream with predictable source identity * Application delivery - the NSX Advanced Load Balancer (AVI) maps to the Calico Load Balancer and Ingress Gateway, providing stable VIPs, Maglev-based L4 distribution, and L7 routing, all Kubernetes-native * Workload mobility - vMotion maps to KubeVirt live migration with Calico, preserving IP addresses and policy with minimal packet loss and fast route convergence as VMs move between nodes * Quality of service and observability - NSX QoS and Traceflow map to Calico QoS controls and a full observability stack: Service Graph, flow logs, DNS logs, L7 logs, and packet capture, with complete Kubernetes workload context * One model across any workload, any environment Because the same policy, routing, egress, QoS, and observability patterns apply to VMs and containers alike, platform teams operate a single model instead of two. That model extends consistently across clusters, distributions, and on-premises, cloud, and edge deployments, eliminating platform-specific configuration and the vendor lock-in that defined the previous era. Organizations can migrate first and modernize later: preserve existing IPs, VLANs, and firewall rules on day one, then consolidate to Kubernetes-native patterns on their own timeline, without fragmenting operations along the way. Availability The Calico Unified Platform is available across Calico Enterprise, Calico Cloud, and Calico Open Source. Tigera offers a structured VMware-to-Kubernetes migration path: assess the VMware topology, map VLAN and overlay segments, migrate VMs with networking and security preserved, then modernize.
Tigera launches Lynx, a unified control plane for Kubernetes-native AI agents. Jun 17, 2026, 19:37 ET Building on years of deep experience in Kubernetes network security, Lynx provides AI, platform, security, and compliance teams a central hub to discover, authenticate, authorize, control, and audit every AI agent - without any changes to agent code. SAN JOSE, California, June 18, 2026 /PRNewswire/ - Tigera, the creator and maintainer of Calico Open Source, today announced the general availability of Tigera Lynx - a unified control plane for Kubernetes-native AI agents. With Lynx, organizations can, from a single central location, inventory all agents in their Kubernetes environment, harden security, assign a sandbox, give each agent a cryptographic identity, enforce policy on every action, audit agent activity as it actually happens, and detect anomalous behavior - without ever modifying a line of agent code. AI agents do not behave like the workloads that enterprise security infrastructure was originally designed for. They are autonomous and non-deterministic: they act on behalf of a user, reach out to arbitrary tools, LLMs, or other agents, hold a chain of delegation, and read untrusted input. This causes three teams to view the same problem from different angles: the AI team wants to experiment with the newest technology and iterate quickly, the platform-engineering team is measured on velocity of deployment but can't prove the platform is under control; and the security team is asked to approve agents it cannot guarantee the security posture for. Valid credentials do not guarantee well-behaved operations, and the blast radius shifts every time a new agent or tool goes online or there are platform changes. Lynx sits in the path of every agent call - agent-to-agent, agent-to-tool, and agent-to-LLM - to authenticate, authorize, broker, and audit each one. It integrates into the tools that companies already use, including their identity providers (EntraID, Okta) or via SPIFFE/SPIRE as well as into existing observability systems, and is based on open standards rather than proprietary lock-in. One control plane, five functions * Discovery, registration and observability. A central registry catalogs every agent with owner, purpose, and version, while eBPF-powered automatic discovery catches agents that no one registered. Shadow agents are flagged and quarantined, and every agent's actions can be end-to-end reconstructed through OpenTelemetry traces. * Configuration and security posture management. AI-CSPM continuously evaluates each agent against a baseline, surfacing drift and over-permissioned agents the moment they appear - with per-agent sandboxing and pre-built compliance packs that address regulatory requirements from GDPR, HIPAA, SOC 2, and financial-services mandates. A red-team agent continuously scans for security posture weaknesses and misconfigurations. * Identity and authentication. Each agent gets a verifiable cryptographic identity via integration with an enterprise identity provider (EntraID, Okta), or via SPIFFE/SPIRE, without shared secrets. Long-lived API keys are replaced with short-lived, tightly scoped, auto-rotating tokens. A JWT token is generated for each step in a multi-agent workflow. * Policy definition and enforcement. A single default-deny policy governs LLM, MCP and agent access using the Cedar policy language, and is enforced at the gateway before a call is executed - with no modifications to agent code. Misbehaving agents can be put under quarantine immediately and risky calls can be escalated to a human. * Anomalous behavior detection. eBPF and LSM monitors every system call, network call, and file access at a level agents cannot tamper with, catching credential theft and lateral movement even if the action complies with policy. This provides a forensic audit trail. The guardian agent detects anomalous behavior and isolates suspicious agents. 10 years of Kubernetes-security experience, now extended into AI agents and AI applications "For over a decade, Tigera's Calico platform has been helping Global 2000 companies operate the world's biggest Kubernetes platforms, securing tens of millions of business-critical transactions every day. AI agents are the next generation of workloads: autonomous, distributed, and embedded into business-critical processes. Lynx brings the same unified control-tower security discipline to AI agents. We build on our core strength - high-performance, high-performance enforcement of business-critical workloads at scale on Kubernetes," said Ratan Tipirneni, CEO of Tigera. "Control only matters if you enforce it consistently. Lynx assigns a cryptographic identity to every agent, scopes access to single-hop policies, and assesses every LLM, MCP and tool call against default-deny policy enforced at the gateway - without changing agent code. Because we monitor behavior with eBPF and LSM in the kernel, we can detect when an agent is operating in error, even though it holds valid credentials - and provide a reproducible audit trail to prove it," said Peter Kelly, Chief Technology Officer of Tigera. Availability Lynx is generally available from today. Lynx is generally available from today. It scales horizontally on a Kubernetes-native architecture and uses eBPF instrumentation without per-call overhead; it is already deployed in production at major global banks. About Tigera Tigera, the creator and maintainer of the open-source project Calico, delivers security and control for Kubernetes workloads and AI agents across the enterprise, delivering comprehensive visibility and enforcement. The company's solutions secure Kubernetes workloads and AI agents in deploy-em of over 1M clusters across multicloud and hybrid environments. Industry leaders such as NVIDIA, the Royal Bank of Canada, Bloomberg, Chipotle, GoDaddy, and Upwork trust Tigera for their Kubernetes security, networking, and AI-agent security needs. To learn more about the Tigera offering, go to tigera.io.
Tigera launches Lynx, a unified control plane for Kubernetes native AI agents. Jun 17, 2026, 19:34 ET Building on a decade of deep Kubernetes network security expertise, Lynx gives AI, platform, security, and compliance teams a single space to inventory, authenticate, authorize, manage, and audit every AI agent - without modifying any agent code. SAN JOSE, Calif., June 18, 2026 /PRNewswire/ - Tigera, inventor and maintainer of Calico Open Source, today announced the general availability of Tigera Lynx, a unified control plane for Kubernetes native AI agents. Lynx provides enterprises with a single platform to inventory all agents in their Kubernetes environment, strengthen security, assign a test environment, equip each agent with a cryptographic identity, apply rules to each of their actions, audit their actual activities, and detect any abnormal behavior - without modifying a single line of agent code. AI agents do not behave like the workloads for which enterprise security infrastructures were designed. They are autonomous and non-deterministic: they act on behalf of a user, use any tool, LLM, or other agent, have a delegation chain, and process untrusted input data. So three teams remain that address the same problem from different angles: the AI team wants to test the latest technologies and act quickly; the platform engineering team is evaluated on deployment speed, but cannot guarantee that the platform is under control; and the security team is tasked with approving agents whose security they cannot guarantee. A valid identity does not ensure proper behavior, and the impact scope varies each time a new agent or tool is deployed, or when platform changes are made. Lynx intervenes at every step of agent-to-agent communications - whether agent-to-agent, agent-to-tool, or agent-to-LLM - to authenticate, authorize, moderate, and control each one. It integrates with tools already used by enterprises, including their identity provider (EntraID, Okta) or via SPIFFE/SPIRE, as well as existing observability systems, and relies on open standards rather than proprietary technology dependencies. One control plane, five features * Discovery, inventory, and observability. A central registry lists all agents indicating their owner, function, and version, while eBPF-based automatic detection identifies agents that have not been registered. Ghost agents are flagged and quarantined, and each agent's actions can be traced end-to-end via OpenTelemetry traces. * Configuration and compliance management. AI-CSPM continuously evaluates each agent against a baseline, flagging drifts and excessive permissions as soon as they occur, thanks to a per-agent test environment and ready-to-use compliance packs adapted to GDPR, HIPAA, SOC 2, and financial services sector requirements. A "Red Team" agent continuously searches for security flaws and misconfigurations. * Identity and authentication. Each agent is assigned a verifiable cryptographic identity via integration with the enterprise's identity provider (EntraID, Okta) or via SPIFFE/SPIRE, without any shared secrets. Long-lived API keys are replaced with short-lived, strictly scoped, automatically rotated tokens. A JWT token is generated at each step of a multi-agent workflow. * Policy definition and enforcement. A single "deny by default" policy governs access to LLMs, MCPs, and agents using the Cedar policy language; this policy is enforced at the gateway level before any call is executed, without requiring any agent code modifications. Agents that violate rules can be immediately quarantined, and critical calls can be escalated to a human operator. * Abnormal behavior detection. eBPF and LSM monitor every system call, network call, and file access at a level where agents cannot interfere, allowing detection of credential theft and lateral movement even when an action is policy-compliant. This provides a legally admissible audit trail. Guardian Agent detects abnormal behaviors and quarantines suspicious agents. 10 years of Kubernetes security expertise, now extended to AI agents and applications "For over a decade, Tigera's Calico platform has served Global 2000 enterprises operating the world's largest Kubernetes platforms, securing tens of millions of business-critical transactions daily. AI agents are the next generation of workloads: autonomous, decentralized, and increasingly integrated into core business processes. Lynx applies this same unified control and security rigor to AI agents. We are building on our core business: securing business-critical workloads on Kubernetes at scale, while ensuring high performance," said Ratan Tipirneni, CEO of Tigera. "Control only matters if it is uniformly applied. Lynx assigns each agent a cryptographic identity, limits access rights to a single hop, and evaluates every call to an LLM, MCP, or tool against a default-deny policy at the gateway level - without any agent code changes. Since we monitor behaviors using eBPF and LSM at the kernel level, we can detect a misbehaving agent even if it has a valid identity, and generate a reproducible audit trail to prove it," said Peter Kelly, CTO of Tigera. Availability Lynx is now available for everyone. It scales horizontally on a native Kubernetes architecture via eBPF instrumentation, with no per-call overhead, and is already deployed in production at the world's largest banks. About Tigera Tigera, creator and maintainer of Calico Open Source, secures and governs Kubernetes workloads and AI agents at enterprise scale, providing deep visibility and rigorous policy enforcement. The company's solutions secure Kubernetes workloads and AI agents across over one million clusters in multicloud and hybrid environments. Leading companies such as NVIDIA, Royal Bank of Canada, Bloomberg, Chipotle, GoDaddy, and Upwork trust Tigera for their Kubernetes security, networking, and AI agent security needs. To learn more about Tigera's offerings, visit tigera.io.