Staff Product Security Engineer
New
C
ChainguardSoftware Security
United States - RemoteFull-TimeStaff
Salary170,000 - 231,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years
- Required Skills
- AWSPythonGCPKubernetesGoCI/CD
Requirements
- 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility.
- Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
- Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers).
- Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, and security services.
- Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
- Fluency with container security (image scanning, distroless/minimal base images, runtime security).
- Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
- Solid understanding of OWASP, NIST, and cloud security frameworks and their pragmatic application.
Responsibilities
- Design, build, and maintain secure CI/CD pipelines with integrated security gates.
- Systematically capture and monitor risk exposure for Chainguard's products.
- Implement and enforce software supply chain security controls including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore / Cosign).
- Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS.
- Harden container images, Kubernetes cluster configurations, and cloud IAM postures.
- Define and drive adoption of baseline security standards for pod security, network policies, and workload identity.
- Evaluate and operationalize CNAPP and CSPM tooling to maintain visibility into cloud-native risk.
View Full Description & ApplyYou'll be redirected to the employer's site