Principal Product Security Researcher

1 hour, 51 minutes ago
Full-time
Lead
Cybersecurity
Chainguard

Chainguard

Chainguard: Fortified Software Delivery Security for developers and CISOs, ensuring secure by default infrastructure and zero workflow friction.

Internet Software & Services
51-250
Founded 2021
$55M raised

Description

  • Own the product security research agenda by scanning the broader ecosystem for emerging attack patterns and translating them into risks and opportunities.
  • Research emerging threats and trends in software supply chain and product security and assess their impact on Chainguard’s products and customers.
  • Design pragmatic mitigations across people, process, and technology that can be adopted in practice.
  • Lead large-scale, multi-quarter initiatives that reduce risk and improve security maturity across multiple product lines and platforms.
  • Partner with Product, Engineering, Security, and executive leadership to shape security strategy, influence roadmaps, and drive major decisions.
  • Identify systematic weaknesses and develop root-cause fixes that persist over time.
  • Mentor and upskill Product Security and Engineering teams to think more strategically about threats, risk, and security posture.
  • Represent Chainguard externally through talks, conferences, and thought leadership.

Requirements

  • Deep experience in product security or application security with a track record of leading research or threat-focused work that delivered company-level outcomes.
  • Expert knowledge across secure architecture, application/product security, software supply chain, and org-level risk management.
  • Ability to own ambiguous, cross-functional problems and turn them into structured, prioritized initiatives.
  • Proven ability to present complex ideas to executive stakeholders and drive alignment.
  • Strong awareness of industry trends, tooling, and research methods, with the ability to apply them pragmatically.
  • Ability to work independently with high ownership while collaborating effectively with others.
  • Comfort operating in fast-evolving, uncertain contexts and building structure.
  • Experience balancing security, velocity, and reliability.
  • Experience leading large, complex security initiatives is preferred.
  • Experience in public speaking, conferences, or thought leadership is preferred.

Benefits

  • Base salary range of $201,000 to $226,000 USD.
  • Flexible remote-first culture with team meetup opportunities and bi-annual destination summits.
  • Monthly stipend for coworking spaces, phone, and internet costs.
  • Stock options upon hire and promotion, with participation in secondary offerings and a 10-year exercise window.
  • 100% covered health, vision, and dental insurance for employees and dependents.
  • Unlimited flexible time off.
  • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Engineer, AI Security

Twilio 5K-10K Diversified Telecommunication Services

Twilio is hiring a remote-based Staff Engineer, AI Security in Ireland to lead security for AI and machine learning systems across the app security team and help shape a secure-by-default AI lifecycle.

CI/CD Go LLM Machine Learning Python Twilio
6 minutes ago

Application Security Engineer

BrainRocket 251-1K Internet Software & Services

BrainRocket is hiring a Senior Application Security Engineer to shape secure architecture and product security across cloud infrastructure, applications, and delivery pipelines for its global tech products.

Agile AWS CI/CD CloudFormation Docker GitLab Helm JavaScript Kubernetes Python Shell Scripting Terraform TypeScript
2 hours, 36 minutes ago

Staff Application Security Engineer

Thumbtack 1K-5K Construction & Engineering

Thumbtack is hiring a Security Engineer to shape application security for its cloud-based, AI-enabled home services platform as the company scales.

AWS CI/CD GCP Secrets Management
4 hours, 21 minutes ago

Staff Product Security

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Staff Product Security Engineer in the USA to design and secure AI, data, and cloud-native products across the product lifecycle.

AWS Azure CI/CD DevSecOps GCP Java JavaScript Kubernetes Microservices Python Secrets Management
5 hours, 36 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers