Chainguard

Chainguard

Chainguard: Fortified Software Delivery Security for developers and CISOs, ensuring secure by default infrastructure and zero workflow friction.

Internet Software & Services
51-250
Founded 2021
$55M raised

Description

  • Design, build, and maintain secure CI/CD pipelines with security gates that prevent issues from reaching production.
  • Systematically capture and track the risk exposure of Chainguard's products.
  • Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation.
  • Identify emerging customer security needs and build solutions to address them.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to reduce attack surface.
  • Define baseline security standards for pod security, network policies, workload identity, and secrets management.
  • Evaluate and operationalize CNAPP/CSPM tooling to maintain continuous visibility into cloud-native risk.
  • Provide technical leadership and cross-team influence as an individual-contributor Staff engineer.

Requirements

  • 7+ years of experience in software engineering, security engineering, or a combined role with significant hands-on security responsibility.
  • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
  • Deep hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers.
  • Practical experience with GCP and/or AWS, including IAM, workload identity, secrets management, and security services such as GCP Security Command Center or AWS Security Hub.
  • Proven experience designing and securing CI/CD pipelines using GitHub Actions, Cloud Build, Tekton, or similar tools.
  • Fluency with container security, including image scanning, distroless or minimal base images, and runtime security.
  • Experience with software supply chain security tooling and frameworks such as Sigstore, SLSA, and SBOM generation.
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems is preferred.
  • Experience with policy-as-code tools such as OPA, Kyverno, or Conftest is preferred.
  • Contributions to open source security projects are preferred.
  • Background in security research or offensive security, such as bug bounty, CTFs, or penetration testing, is preferred.

Benefits

  • Flexible, remote-first work environment with team meetup opportunities and bi-annual destination summits.
  • Monthly stipend for coworking spaces, phone, and internet costs.
  • Stock options upon hire and promotion, with participation in secondary offerings and 10 years to exercise options.
  • 100% company-paid health, vision, and dental insurance for employees and dependents.
  • Unlimited flexible time off.
  • 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a Security Engineer to partner with engineering and product teams remotely, building secure-by-default systems and driving measurable application security outcomes.

AWS Docker GCP Go Java Kubernetes Python Ruby Terraform
4 days, 19 hours ago

Staff Application & Product Security Engineer

Cleo 251-1K Internet Software & Services

Cleo is hiring a Staff Application Security Engineer to own secure product development and the security posture of its SaaS and customer-hosted products, partnering with engineering and security teams from design through release.

AWS Burp Suite CI/CD GitHub Go Java Jenkins Kubernetes Penetration Testing Python SAML Terraform TypeScript
4 days, 20 hours ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is seeking an Application Security Engineer to triage and validate vulnerability submissions across client bug bounty programs, communicate with researchers and customers, and escalate critical security incidents.

Burp Suite Nmap
1 week, 5 days ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices throughout product development.

CI/CD DevSecOps Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
1 week, 5 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers