Staff Product Security Engineer

Chainguard
United States
Workplace: RemoteFull timeUSD 170,000 - 231,000 annuallyFunction: CybersecurityExperience: 7+ yearsSkills: ["Technical leadership","Cross-team influence","Proactive problem solving","Hands-on execution"]

Design and operate secure CI/CD pipelines with automated security gates that reduce risk before production. Capture and measure product security exposure, and enforce software supply chain controls including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign). Lead Kubernetes workload threat modeling and security architecture reviews across GCP and AWS, hardening IAM, containers, and clusters while evaluating CNAPP/CSPM tooling for continuous visibility.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Chainguard
Chainguard
21 hours ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Design and operate secure CI/CD pipelines with automated security gates that reduce risk before production. Capture and measure product security exposure, and enforce software supply chain controls including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign). Lead Kubernetes workload threat modeling and security architecture reviews across GCP and AWS, hardening IAM, containers, and clusters while evaluating CNAPP/CSPM tooling for continuous visibility.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, build, and maintain secure CI/CD pipelines with security gates to catch issues before production.
  • •Capture product risk exposure systematically and automatically.
  • •Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign).
  • •Lead security architecture reviews and threat models for Kubernetes workloads on GCP and AWS.
  • •Harden container images, Kubernetes configurations, and cloud IAM postures; define and drive baseline security standards and evaluate CNAPP/CSPM tooling for continuous visibility.

Pay and Benefits

Salary: USD 170,000 - 231,000 annually
Equity and Bonus:Equity
Perks:Remote WorkHealth InsuranceVisionDentalEquityPaid LeaveParental LeaveLearning Budget

Key Requirements

  • •7+ years in software engineering or security engineering with meaningful hands-on security responsibility.
  • •Strong proficiency in Go or Python for writing, reviewing, and debugging production-quality code.
  • •Deep hands-on Kubernetes production experience, including cluster hardening, RBAC, network policies, and admission controllers.
  • •Practical expertise with GCP and/or AWS (IAM, workload identity, secrets management, security services like Security Command Center and Security Hub).
  • •Proven experience designing and securing CI/CD pipelines (e.g., GitHub Actions, Cloud Build, Tekton) and applying software supply chain security tooling/frameworks (Sigstore, SLSA, SBOM).
Experience:7+ yearsOpen sourceCloud-nativeSecurity engineering
Skills:Technical leadershipCross-team influenceProactive problem solvingHands-on execution
Languages:English
Tech Stack:GoPythonCI/CDSecurity gatesGitHub ActionsCloud BuildTektonKubernetesRBACNetwork policiesAdmission controllersGCPAWSIAMWorkload identitySecrets managementGCP Security Command CenterAWS Security HubSigstoreCosign

Company Brief

Chainguard
Builds software supply chain security solutions for containerized and Kubernetes-native environments, offering tools for secure builds, attestations, vulnerability scanning, and policy enforcement to help organizations deploy trustworthy software at scale.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Seattle, United States
Founded: 2020
WebsiteLinkedIn