Chainguard

Chainguard

Chainguard: Fortified Software Delivery Security for developers and CISOs, ensuring secure by default infrastructure and zero workflow friction.

Internet Software & Services
51-250
Founded 2021
$55M raised

Description

  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production.
  • Systematically capture and track the risk exposure of Chainguard’s products.
  • Implement and enforce software supply chain security controls such as signed artifacts, SBOMs, and provenance attestation.
  • Identify emerging customer security needs and build solutions to address them.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to reduce attack surface.
  • Define and drive adoption of baseline security standards for pod security, network policies, workload identity, and secrets management.
  • Evaluate and operationalize CNAPP/CSPM tooling to maintain continuous visibility into cloud-native risk.

Requirements

  • 7+ years of experience in software engineering, security engineering, or a combined role with significant hands-on security responsibility.
  • Strong proficiency in Go or Python and ability to write, review, and debug production-quality code.
  • Deep hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers.
  • Practical experience with GCP and/or AWS, including IAM, workload identity, secrets management, and security services such as GCP Security Command Center or AWS Security Hub.
  • Proven experience designing and securing CI/CD pipelines using GitHub Actions, Cloud Build, Tekton, or similar tools.
  • Experience with container security, including image scanning, distroless or minimal base images, and runtime security.
  • Experience with software supply chain security tooling and frameworks such as Sigstore, SLSA, and SBOM generation.
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
  • Familiarity with Chainguard Images or other minimal and hardened container base image ecosystems, preferred.
  • Experience with policy-as-code tools such as OPA, Kyverno, or Conftest, preferred.
  • Contributions to open source security projects, preferred.
  • Background in security research or offensive security such as bug bounty, CTFs, or penetration testing, preferred.

Benefits

  • Flexible remote-first culture with team meetup opportunities and bi-annual destination summits.
  • Monthly stipend for coworking spaces, phone, and internet costs.
  • Stock options upon hire and promotion, with participation in secondary offerings and 10 years to exercise options.
  • 100% company-covered health, vision, and dental insurance for employees and dependents.
  • Unlimited flexible time off.
  • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Platform Engineer - Navy (FedD174/FedD175)

DefenseUnicorns 51-250 Internet Software & Services

Defense Unicorns is hiring a Platform Engineer for its Navy Delivery team to support secure platform, DevOps, and application security work for U.S. government missions.

Agile AWS CI/CD GitOps Go Helm Kubernetes Linux Pulumi Unix YAML
18 hours, 3 minutes ago

DevOps Engineer

Launchpad Technologies 51-250 Internet Software & Services

Launchpad Technologies Inc. is building a talent pool for remote DevOps opportunities focused on cloud infrastructure, CI/CD, and reliable, secure environments for clients across North America and beyond.

Agile Ansible AWS Azure Bash CloudFormation Datadog DevSecOps Docker GCP Git GitHub GitLab Grafana Kubernetes Microservices PowerShell Prometheus Python Serverless Terraform
18 hours, 3 minutes ago

DevOps Engineer Bucharest

Amdaris 251-1K Internet Software & Services

DevOps Engineer at a growing engineering team within Insight, focused on improving cloud infrastructure, delivery automation, and platform reliability across development, QA, and IT environments.

Ansible AWS Azure Bash CI/CD CloudFormation Cybersecurity DevSecOps Docker GCP Git Grafana Jenkins Kubernetes Microservices PowerShell Prometheus Python Terraform
18 hours, 48 minutes ago

Senior Software Engineer - VDR

SRS Acquiom 51-250 Capital Markets

SRS Acquiom is hiring a senior full stack engineer to lead complex software design, development, and technical strategy for its M&A and loan agency transaction platform.

CI/CD Docker Kubernetes Ruby on Rails
18 hours, 48 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers