Staff Vulnerability Management Engineer

Chainguard
Canada
Workplace: RemoteFull timeFunction: Data Analytics & Business IntelligenceExperience: 7+ yearsSkills: ["Responsible disclosure","Pipeline automation","Cross-team coordination","Industry coordination","Technical leadership"]

Own Chainguard’s novel vulnerabilities pipeline, including measurement, disclosure, and weekly reporting for thousands of vulnerabilities identified by frontier models and other sources. Calibrate response processes as trends emerge, coordinate upstream disclosures and CNA operations, and manage internal/external embargoes. Work across customers, engineering teams, maintainers, and industry bodies (e.g., Linux Foundation, CISA) while representing Chainguard externally and guiding standards direction.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Chainguard
Chainguard
9 hours ago

Staff Vulnerability Management Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Own Chainguard’s novel vulnerabilities pipeline, including measurement, disclosure, and weekly reporting for thousands of vulnerabilities identified by frontier models and other sources. Calibrate response processes as trends emerge, coordinate upstream disclosures and CNA operations, and manage internal/external embargoes. Work across customers, engineering teams, maintainers, and industry bodies (e.g., Linux Foundation, CISA) while representing Chainguard externally and guiding standards direction.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Data Analytics & Business Intelligence
Seniority: Sr. Director level

Key Responsibilities

  • •Manage the novel vulnerabilities pipeline and its measurement, disclosure, and reporting at weekly cadence.
  • •Calibrate the response process as emerging trends change vulnerability discovery and handling.
  • •Coordinate reporting of newly discovered vulnerabilities to upstream projects and maintainers.
  • •Run the CNA program to assign new CVEs where necessary.
  • •Coordinate internal and external embargoes and represent Chainguard in industry actions and standards efforts.

Pay and Benefits

Perks:Health InsuranceVisionDentalEquityRemote WorkPaid LeaveParental Leave

Key Requirements

  • •7+ years in software security, open source maintenance, or vulnerability disclosure management.
  • •Strong understanding of responsible disclosure and coordinating vulnerability disclosure and embargoes.
  • •Practical expertise automating pipelines and processes to operate at large scale with minimal human involvement.
  • •Deep experience with open source communities.
  • •Experience coordinating with public-sector or industry standards bodies and working groups.
Experience:7+ yearsSoftware securityOpen sourceVulnerability disclosure
Skills:Responsible disclosurePipeline automationCross-team coordinationIndustry coordinationTechnical leadership
Languages:English
Tech Stack:PythonJavaJavascriptGo

Company Brief

Chainguard
Builds software supply chain security solutions for containerized and Kubernetes-native environments, offering tools for secure builds, attestations, vulnerability scanning, and policy enforcement to help organizations deploy trustworthy software at scale.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Seattle, United States
Founded: 2020
WebsiteLinkedIn