Senior Product Security Engineer
Chainguard3 months ago
Base Salary
$157k - $184k/yr
Responsibilities
- Design, build, and maintain secure CI/CD pipelines with security gates that identify issues before production.
- Automatically capture and assess risk exposure across Chainguard products.
- Implement software supply chain controls including signed artifacts, SBOMs, and SLSA or Sigstore/Cosign provenance attestations.
- Identify emerging customer security needs and build solutions to address them.
- Lead security architecture reviews and threat models for Kubernetes workloads on GCP and AWS.
- Harden container images, Kubernetes configurations, and cloud IAM postures to reduce attack surface.
- Define and drive adoption of pod security standards, network policies, workload identity, and secrets management baselines.
- Evaluate and operationalize CNAPP/CSPM tooling for continuous visibility into cloud-native risk.
Requirements
- 5+ years of software engineering, security engineering, or combined experience with meaningful hands-on security responsibility.
- Strong proficiency in Go or Python and ability to write, review, and debug production-quality code.
- Deep production Kubernetes experience, including cluster hardening, RBAC, network policies, and admission controllers.
- Practical GCP and/or AWS expertise covering IAM, workload identity, secrets management, and security services.
- Experience designing and securing CI/CD pipelines using tools such as GitHub Actions, Cloud Build, or Tekton.
- Fluency with container security, including image scanning, minimal or distroless base images, and runtime security.
- Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation.
- Understanding of OWASP, NIST, and cloud security frameworks and their practical application.
- Familiarity with Chainguard Images or other minimal and hardened container image ecosystems is preferred.
- Experience with policy-as-code tools such as OPA, Kyverno, or Conftest is preferred.
- Open source security contributions or a background in security research, bug bounty, CTF, or penetration testing is preferred.
Benefits
- Remote-first work arrangement with team meetups, bi-annual destination summits, and a monthly coworking, phone, and internet stipend.
- Stock options upon hire and promotion, with participation in secondary offerings and a 10-year exercise period.
- 100% company-paid health, vision, and dental insurance premiums for employees and dependents.
- Flexible time off.
- Paid parental leave of 18 weeks for birthing parents and 12 weeks for non-birthing parents.
Tech Stack
Categories
About Chainguard
Chainguard provides secure, hardened container images and production-ready builds of open source software for enterprises and developers, typically sold via subscriptions and support. Its offerings include Chainguard Images and tools for software supply chain security; the company also maintains Wolfi, a container-focused Linux distribution. Founded in 2021 and headquartered in Kirkland, WA, Chainguard’s customers include organizations such as OpenAI, Snowflake, and Hewlett Packard Enterprise.