Staff Product Security Engineer

Chainguard
United Kingdom
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Technical leadership","Cross-team influence","Hands-on ownership","Threat modeling","Proactive problem solving"]

Design, build, and maintain secure CI/CD pipelines with automated security gates, and systematically capture product risk exposure across Chainguard’s offerings. Implement software supply chain security controls such as signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign). Lead security architecture reviews and threat modeling for Kubernetes workloads on GCP and AWS, hardening clusters, container images, and cloud IAM while evaluating CNAPP/CSPM tooling for continuous visibility.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Chainguard
Chainguard
20 hours ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Design, build, and maintain secure CI/CD pipelines with automated security gates, and systematically capture product risk exposure across Chainguard’s offerings. Implement software supply chain security controls such as signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign). Lead security architecture reviews and threat modeling for Kubernetes workloads on GCP and AWS, hardening clusters, container images, and cloud IAM while evaluating CNAPP/CSPM tooling for continuous visibility.
Location: United Kingdom
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, build, and maintain secure CI/CD pipelines with security gates to catch issues before production.
  • •Capture and quantify product risk exposure consistently and automatically.
  • •Implement and enforce software supply chain security controls (signed artifacts, SBOMs, provenance attestation).
  • •Lead security architecture reviews and threat models for Kubernetes workloads on GCP and AWS.
  • •Harden container images, Kubernetes configurations, and cloud IAM postures; drive adoption of baseline security standards and evaluate CNAPP/CSPM tooling.

Pay and Benefits

Perks:Remote WorkHealth InsuranceVisionDentalEquityParental LeaveFlexible Time

Key Requirements

  • •7+ years in software engineering/security engineering with meaningful hands-on security responsibility.
  • •Strong proficiency in Go or Python to write, review, and debug production-quality code.
  • •Deep hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers.
  • •Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services (e.g., GCP Security Command Center, AWS Security Hub).
  • •Proven experience designing and securing CI/CD pipelines and using software supply chain security frameworks (e.g., Sigstore, SLSA, SBOM generation).
Experience:Security engineeringSoftware engineeringOpen sourceCloud-native
Skills:Technical leadershipCross-team influenceHands-on ownershipThreat modelingProactive problem solving
Languages:English
Tech Stack:GoPythonKubernetesGCPAWSGitHub ActionsCloud BuildTektonSBOMSLSASigstoreCosignOWASPNISTGCP Security Command CenterAWS Security HubCNAPPCSPMOPAKyverno

Company Brief

Chainguard
Builds software supply chain security solutions for containerized and Kubernetes-native environments, offering tools for secure builds, attestations, vulnerability scanning, and policy enforcement to help organizations deploy trustworthy software at scale.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Seattle, United States
Founded: 2020
WebsiteLinkedIn