Staff Product Security Engineer

Chainguard
Canada, United States
Workplace: RemoteFull timeFunction: CybersecurityExperience: 7+ yearsSkills: ["Technical leadership","Cross-team collaboration","Systematic problem-solving","Proactive thinking"]

Design and maintain secure CI/CD pipelines with automated security gates and software supply chain protections, including signed artifacts, SBOMs, and provenance attestations. Lead security architecture reviews and threat modeling for Kubernetes workloads on GCP and AWS, hardening clusters, container images, and IAM postures. Evaluate CNAPP/CSPM tooling for continuous cloud-native risk visibility, proactively addressing emerging customer security needs.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Chainguard
Chainguard
20 hours ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Design and maintain secure CI/CD pipelines with automated security gates and software supply chain protections, including signed artifacts, SBOMs, and provenance attestations. Lead security architecture reviews and threat modeling for Kubernetes workloads on GCP and AWS, hardening clusters, container images, and IAM postures. Evaluate CNAPP/CSPM tooling for continuous cloud-native risk visibility, proactively addressing emerging customer security needs.
Location: Canada, United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, build, and maintain secure CI/CD pipelines with security gates to catch issues before production.
  • •Automatically capture product risk exposure and implement software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign).
  • •Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • •Harden container images and Kubernetes cluster configurations, including cloud IAM postures, pod security standards, network policies, workload identity, and secrets management.
  • •Evaluate and operationalize CNAPP/CSPM tooling to maintain continuous visibility into cloud-native risk.

Pay and Benefits

Equity and Bonus:Equity
Perks:Remote WorkHealth InsuranceVisionDentalEquityPaid LeaveParental Leave

Key Requirements

  • •7+ years of software engineering and/or security engineering with meaningful hands-on security responsibility.
  • •Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
  • •Deep hands-on Kubernetes experience in production, including cluster hardening, RBAC, network policies, and admission controllers.
  • •Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services (e.g., Security Command Center, Security Hub).
  • •Proven experience designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar) with container and supply chain security expertise.
Experience:7+ years
Skills:Technical leadershipCross-team collaborationSystematic problem-solvingProactive thinking
Tech Stack:GoPythonCI/CDSecurity gatesSecure pipelinesGitHub ActionsCloud BuildTektonKubernetesRBACNetwork policiesAdmission controllersGCPAWSIAMWorkload identitySecrets managementGCP Security Command CenterAWS Security HubCNAPP

Company Brief

Chainguard
Builds software supply chain security solutions for containerized and Kubernetes-native environments, offering tools for secure builds, attestations, vulnerability scanning, and policy enforcement to help organizations deploy trustworthy software at scale.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Seattle, United States
Founded: 2020
WebsiteLinkedIn