← Zurück zur Liste
Stelle · Senior

Senior Product Security Engineer

Security Engineer • Senior • Remote • Vollzeit Kanada Canada - Remote, Kanada

Senior Product Security Engineer embedded in Chainguard's engineering process, hardening CI/CD pipelines, Kubernetes workloads, and the software supply chain with signed artifacts, SBOMs, and provenance attestation.

Responsibilities

  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production
  • Systematically, consistently, and automatically capture the risk exposure of Chainguard's products
  • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore/Cosign)
  • Proactively identify emerging customer security needs and build solutions to meet them
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface
  • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management
  • Evaluate and operationalize CNAPP/CSPM tooling for continuous visibility into cloud-native risk

Requirements

  • 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility
  • Strong proficiency in Go or Python, able to write, review, and debug production-quality code
  • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers)
  • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub)
  • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar)
  • Fluency with container security: image scanning, distroless/minimal base images, runtime security
  • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation)
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically

Nice to have

  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems
  • Experience with policy-as-code tools (OPA, Kyverno, Conftest)
  • Contributions to open source security projects
  • Background in security research or offensive security (bug bounty, CTF, penetration testing)

Soft skills

Embedded, process-integrated mindset rather than being a gate at the endProactive in spotting customer security needsPrecise, technically deep approach

What we offer

  • Flexible & remote-first culture with team meetups, bi-annual destination summits, and a monthly coworking/phone/internet stipend
  • Stock options upon hire and promotion, with 10 years to exercise
  • 100% covered health, vision, and dental insurance for you and your dependents
  • Unlimited flexible time off
  • 18 weeks paid parental leave (12 weeks for non-birthing parents)

About the company

Chainguard is the trusted source for open source, delivering hardened, secure, production-ready builds relied on by engineers and AI agents. Its customers include Fortune 500 enterprises such as Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap, and Snowflake, and it is backed by leading investors including Amplify, IVP, Kleiner Perkins, Sequoia Capital, and Redpoint Ventures.

Ähnliche Stellen