Chainguard

Chainguard

Chainguard: Fortified Software Delivery Security for developers and CISOs, ensuring secure by default infrastructure and zero workflow friction.

Internet Software & Services
51-250
Founded 2021
$55M raised

Description

  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production.
  • Systematically capture and monitor the risk exposure of Chainguard products.
  • Implement and enforce software supply chain security controls such as signed artifacts, SBOMs, and provenance attestation.
  • Proactively identify emerging customer security needs and build solutions to address them.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to reduce attack surface.
  • Define and drive adoption of baseline security standards including pod security standards, network policies, workload identity, and secrets management.
  • Evaluate and operationalize CNAPP/CSPM tooling to maintain continuous visibility into cloud-native risk.
  • Provide technical leadership and cross-team influence as an individual contributor on hard security problems.

Requirements

  • 7+ years of experience in software engineering, security engineering, or a combined role with substantial hands-on security responsibility.
  • Strong proficiency in Go or Python, including the ability to write, review, and debug production-quality code.
  • Deep hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers.
  • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services such as GCP Security Command Center or AWS Security Hub.
  • Proven experience designing and securing CI/CD pipelines using tools such as GitHub Actions, Cloud Build, Tekton, or similar.
  • Fluency in container security, including image scanning, distroless or minimal base images, and runtime security.
  • Experience with software supply chain security tooling and frameworks such as Sigstore, SLSA, and SBOM generation.
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems is preferred.
  • Experience with policy-as-code tools such as OPA, Kyverno, or Conftest is a plus.
  • Contributions to open source security projects are preferred.
  • Background in security research or offensive security, such as bug bounty, CTFs, or penetration testing, is preferred.

Benefits

  • Flexible remote-first culture with team meetup opportunities and bi-annual destination summits.
  • Monthly stipend for coworking spaces, phone, and internet costs.
  • Stock options upon hire and promotion, plus participation in secondary offerings and a 10-year exercise window.
  • 100% company-covered health, vision, and dental insurance for employees and dependents.
  • Unlimited flexible time off.
  • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a Security Engineering professional to implement and operationalize application security tooling and practices across software development and CI/CD environments for a broad range of customer-facing security engagements.

Azure Burp Suite CI/CD CircleCI GitHub Actions Jenkins
3 hours, 35 minutes ago

Application Security Engineer (Remote in the U.S.)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring an Application Security professional to run and operationalize security testing tools across client development environments and help teams identify and remediate web application risks.

Azure Bamboo C# C++ CI/CD GitHub Java JavaScript Jenkins PHP Python
10 hours, 41 minutes ago

Product Security Engineer

ShopBack 1K-5K IT Services

ShopBack is hiring a Product Security Engineer to help secure its cloud-native, microservices, web, and mobile products across the software development lifecycle as the company scales its shopping, rewards, and payments platform.

Go LLM Microservices Node.js Python TypeScript
1 day, 2 hours ago

Senior Application Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior AI Application Security Engineer to lead hands-on application security for AI-native and agentic features in a fast-moving SaaS engineering environment.

AWS Burp Suite CI/CD Docker GitHub GitHub Actions Go Helm Java JavaScript Kotlin Kubernetes Penetration Testing Python Terraform TypeScript
1 day, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers