Chainguard

Senior Product Security Engineer

Chainguard
Apply
3 months ago
Remote, CanadaSenior

Responsibilities

  • Design, build, and maintain secure CI/CD pipelines with security gates that identify issues before production.
  • Automatically capture and assess risk exposure across Chainguard products.
  • Implement software supply chain controls including signed artifacts, SBOMs, and provenance attestation using SLSA and Sigstore/Cosign.
  • Identify emerging customer security needs and build solutions to address them.
  • Lead security architecture reviews and threat models for Kubernetes workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures.
  • Define and drive adoption of pod security standards, network policies, workload identity, and secrets management standards.
  • Evaluate and operationalize CNAPP and CSPM tooling for continuous visibility into cloud-native risk.

Requirements

  • At least 5 years of software engineering, security engineering, or combined experience with meaningful hands-on security responsibility.
  • Strong proficiency in Go or Python and ability to write, review, and debug production-quality code.
  • Deep production experience with Kubernetes, including cluster hardening, RBAC, network policies, and admission controllers.
  • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services such as GCP Security Command Center and AWS Security Hub.
  • Experience designing and securing CI/CD pipelines using GitHub Actions, Cloud Build, Tekton, or similar tools.
  • Fluency with container security, including image scanning, distroless or minimal base images, and runtime security.
  • Experience with software supply chain security tools and frameworks including Sigstore, SLSA, and SBOM generation.
  • Understanding of OWASP, NIST, and cloud security frameworks and their pragmatic application.
  • Familiarity with Chainguard Images or other minimal or hardened container base image ecosystems is preferred.
  • Experience with policy-as-code tools such as OPA, Kyverno, or Conftest is preferred.
  • Contributions to open source security projects are preferred.
  • Security research or offensive security experience, such as bug bounty, CTF, or penetration testing, is preferred.

Benefits

  • Flexible, remote-first work with team meetup opportunities and bi-annual destination summits.
  • Monthly stipend for coworking spaces, phone, and internet costs.
  • Stock options upon hire and promotion, with participation in secondary offerings and a 10-year exercise period.
  • 100% company-paid health, vision, and dental insurance for employees and dependents.
  • Flexible time off.
  • Paid parental leave of 18 weeks for birthing parents and 12 weeks for non-birthing parents.

Tech Stack

Categories

Chainguard

About Chainguard

501-1,000 employees

Chainguard provides secure, hardened container images and production-ready builds of open source software for enterprises and developers, typically sold via subscriptions and support. Its offerings include Chainguard Images and tools for software supply chain security; the company also maintains Wolfi, a container-focused Linux distribution. Founded in 2021 and headquartered in Kirkland, WA, Chainguard’s customers include organizations such as OpenAI, Snowflake, and Hewlett Packard Enterprise.

Contact me