Staff Vulnerability Management Engineer

Chainguard
United States
Workplace: RemoteFull timeUSD 170,000 - 231,000 annuallyFunction: Data Analytics & Business IntelligenceExperience: 7+ yearsSkills: []

Own Chainguard’s vulnerability management pipeline for thousands of novel vulnerabilities identified by frontier models and other sources. You’ll drive measurement, responsible disclosure, and weekly reporting, calibrate response processes as trends emerge, and manage upstream communication, CNA assignment, and internal/external embargo coordination. You’ll also coordinate across the industry with groups like the Linux Foundation and CISA, and represent Chainguard’s security efforts while working with AI model vendors to shape future software supply chain security.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Chainguard
Chainguard
9 hours ago

Staff Vulnerability Management Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Own Chainguard’s vulnerability management pipeline for thousands of novel vulnerabilities identified by frontier models and other sources. You’ll drive measurement, responsible disclosure, and weekly reporting, calibrate response processes as trends emerge, and manage upstream communication, CNA assignment, and internal/external embargo coordination. You’ll also coordinate across the industry with groups like the Linux Foundation and CISA, and represent Chainguard’s security efforts while working with AI model vendors to shape future software supply chain security.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Data Analytics & Business Intelligence
Seniority: Sr. Manager level

Key Responsibilities

  • •Manage the vulnerability pipeline for thousands of novel vulnerabilities identified weekly by frontier models and other sources.
  • •Own measurement, disclosure, and reporting of the pipeline and calibrate response processes based on emerging trends.
  • •Coordinate disclosure and reporting of newly discovered vulnerabilities with upstream projects and maintainers.
  • •Run a CNA program to assign new CVEs where necessary and coordinate internal/external embargoes.
  • •Represent Chainguard externally, coordinate with industry/public bodies (e.g., Linux Foundation, CISA), and work with AI model vendors to shape future software supply chain security.

Pay and Benefits

Salary: USD 170,000 - 231,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceVisionDentalEquityRemote WorkPaid LeaveParental Leave

Key Requirements

  • •7+ years in software security, open source maintenance, or vulnerability disclosure management.
  • •Strong understanding of responsible disclosure.
  • •Experience automating vulnerability pipelines and processes at large scale to reduce human-in-the-loop.
  • •Deep experience with open source communities.
  • •Experience coordinating with public sector or industry standards bodies and working groups.
Experience:7+ yearsOpen sourceSoftware securityVulnerability disclosure managementResponsible disclosure
Tech Stack:PythonJavaJavascriptGoCNACVEsLinux FoundationCISA

Company Brief

Chainguard
Builds software supply chain security solutions for containerized and Kubernetes-native environments, offering tools for secure builds, attestations, vulnerability scanning, and policy enforcement to help organizations deploy trustworthy software at scale.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Seattle, United States
Founded: 2020
WebsiteLinkedIn