Staff Software Engineer (Malware Detection)
Chainguard7 hours ago
Remote, CanadaStaff+
Responsibilities
- Own the architecture, scale, reliability, and production operation of Chainguard’s shared malware-scanning platform.
- Build detection-quality pipelines, metrics, dashboards, feedback loops, review workflows, escalation systems, and bulk-correction capabilities.
- Develop scan orchestration, verdict storage, APIs, event-driven pipelines, and analysis systems for multiple artifact types and ecosystems.
- Partner with Product Security to move emerging-threat detections from research prototypes into reliable production systems.
- Build customer-facing services for investigating, enforcing, and appealing scanner findings, including policy-management and enterprise-operation backends.
- Operate the scanner in the critical path of customer installations, including alerting, queue health, verdict-before-serve guarantees, and incident response.
- Provide technical leadership, make complex architecture and prioritization decisions, mentor engineers, and improve design and code review standards.
Requirements
- Multiple years of experience building and operating production backend or infrastructure systems with a track record of staff-level ownership and technical leadership.
- Strong Go experience or deep backend systems experience with the ability to ramp quickly in Go.
- Experience owning highly technical platforms or backend infrastructure serving multiple products or internal customers.
- Experience with high-throughput, event-driven pipelines where throughput, latency, and correctness are all important.
- Strong understanding of software supply chain security, malware detection, vulnerability management, or adjacent security domains.
- Experience making engineering design and prioritization decisions in technically complex and ambiguous environments.
- Experience measuring and improving metrics such as false-positive rate in a high-consequence detection domain.
- Experience deploying and operating production services, with sound judgment regarding reliability, observability, and operational tradeoffs.
- Experience mentoring engineers and raising standards for design and code review.
- Strong cross-functional collaboration and ability to influence Product, Security, Design, and go-to-market partners.
- Preferred experience with malware detection, static analysis, software composition analysis, vulnerability scanning, package ecosystems, reusable platform capabilities, cloud infrastructure, software supply chain security, enterprise security platforms, AI-assisted security analysis, sandboxing, dynamic analysis, eBPF, gVisor, seccomp, container isolation, Terraform, or infrastructure-as-code tools.
Benefits
- Remote-first work with team meetups, bi-annual destination summits, and a monthly coworking, phone, and internet stipend.
- Stock options upon hire and promotion, participation in secondary offerings, and 10 years to exercise options.
- 100% employer-covered health, vision, and dental insurance premiums for employees and dependents.
- Flexible paid time off.
- 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents, usable at once or throughout the child’s first year.
About Chainguard
Chainguard provides secure, hardened container images and production-ready builds of open source software for enterprises and developers, typically sold via subscriptions and support. Its offerings include Chainguard Images and tools for software supply chain security; the company also maintains Wolfi, a container-focused Linux distribution. Founded in 2021 and headquartered in Kirkland, WA, Chainguard’s customers include organizations such as OpenAI, Snowflake, and Hewlett Packard Enterprise.