Skip to main content
Chainguard

Senior Product Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
Company size
Startup
$157k–$184k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior product security engineer with 5+ years in software/security engineering. Must be strong in Go or Python, Kubernetes production hardening, GCP and/or AWS, CI/CD security, container security, and software supply chain security.

Core skills

KubernetesCI/CDSoftware supply chain security

Required skills

Go/PythonRBACNetwork policiesAdmission controllersGCP/AWSIAMWorkload identitySecrets managementGCP Security Command CenterAWS Security HubGitHub Actions/Cloud Build/TektonContainer securitySigstoreSLSASBOMOWASPNIST

Optional skills

Chainguard ImagesOPAKyvernoConftest

What you'll do

  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production.
  • Systematically, consistently and automatically capture the risk exposure of Chainguards products.
  • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign).
  • Proactively identify emerging customer security needs, and build solutions to meet these.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack.
  • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management.
  • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.

What they require

  • 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
  • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
  • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers).
  • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub).
  • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
  • Fluency with container security: image scanning, distroless/minimal base images, runtime security.
  • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
  • Preferred: Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
  • Preferred: Contributions to open source security projects.
  • Preferred: Background in security research or offensive security (bug bounty, CTF, penetration testing).

Benefits

  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion.
  • You can participate in secondary offerings and have 10 years to exercise your options.
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents.
  • ∞ Flexible Time Off: Take the time you need.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Software

TechnologyStartup
$157k–$184k/yr