About the Role
Join Chainguard as a Senior Product Security Engineer embedded directly in the product development process. You'll design and harden secure infrastructure across CI/CD pipelines, Kubernetes clusters, and cloud platforms—focusing on supply chain security, container hardening, and cloud-native defense.
Responsibilities
Build & Harden Secure Pipelines
- Design, build, and maintain secure CI/CD pipelines with security gates that prevent issues from reaching production.
- Systematically capture and track the risk exposure of Chainguard's products.
- Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign).
- Proactively identify emerging customer security needs and develop solutions.
Cloud-Native Product Hardening
- Lead security architecture reviews and threat modeling for Kubernetes-based workloads on GCP and AWS.
- Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface.
- Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, and secrets management.
- Evaluate and operationalize CNAPP / CSPM tooling for continuous visibility into cloud-native risk.
Requirements
Required
- 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility.
- Strong proficiency in Go or Python—able to write, review, and debug production-quality code.
- Deep, hands-on experience with Kubernetes in production: cluster hardening, RBAC, network policies, admission controllers.
- Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (GCP Security Command Center, AWS Security Hub).
- Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
- Fluency with container security: image scanning, distroless/minimal base images, runtime security.
- Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
- Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them practically.
Nice to Have
- Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
- Experience with policy-as-code tools (OPA, Kyverno, Conftest).
- Open source security project contributions.
- Background in security research or offensive security (bug bounty, CTF, penetration testing).
Benefits
- Flexible & Remote-First: Work remotely with bi-annual destination summits and monthly stipend for coworking, phone, and internet.
- Equity: Stock options upon hire and promotion, with 10-year exercise window. Opportunity to participate in secondary offerings.
- Health Coverage: 100% covered health, vision, and dental insurance for you and dependents.
- Time Off: Flexible unlimited PTO and 18 weeks paid parental leave (12 weeks for non-birthing parents).
Compensation: Base salary $157,000–$184,000 USD
Location: United States – Remote