Senior Product Security Engineer

Posted 3 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Design, construct, and sustain secure CI/CD pipelines equipped with security gates that detect issues prior to production.

• Methodically, consistently, and automatically assess the risk exposure of Chainguard's products.

• Implement and uphold software supply chain security measures, including signed artifacts, SBOMs, and provenance attestation utilizing SLSA, Sigstore, and Cosign.

• Recognize emerging security requirements from customers and develop solutions to address them.

• Conduct security architecture evaluations and threat modeling for Kubernetes-based workloads operating on GCP and AWS.

• Strengthen container images, Kubernetes cluster configurations, and cloud IAM settings to reduce the attack surface.

• Establish and promote the adoption of fundamental security standards, including pod security standards, network policies, workload identity, and secrets management.


⛳️ Requirements

• Over 5 years of experience in software engineering, security engineering, or a combined role with substantial hands-on security responsibilities.

• Strong expertise in Go or Python, capable of writing, reviewing, and debugging production-quality code.

• Extensive, hands-on experience with Kubernetes in production, encompassing cluster hardening, RBAC, network policies, and admission controllers.

• Practical knowledge of GCP and/or AWS, including IAM, workload identity, secrets management, and security services.

• Demonstrated success in designing and securing CI/CD pipelines, such as GitHub Actions, Cloud Build, or Tekton.

• Proficiency in container security, including image scanning, distroless/minimal base images, and runtime security.

• Experience with software supply chain security tools and frameworks, including Sigstore, SLSA, and SBOM generation.

• Strong understanding of OWASP, NIST, and cloud security frameworks and their practical applications.

• Familiarity with Chainguard Images or similar minimal/hardened container base image ecosystems.

• Experience with policy-as-code tools like OPA, Kyverno, and Conftest.

• Contributions to open source security projects.

• Background in security research or offensive security, such as bug bounty, CTF, or penetration testing.


🏝️ Benefits

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, as well as phone and internet expenses.

• Receive stock options upon hire and promotion.

• Participate in secondary offerings and have 10 years to exercise your options.

• 100% covered health, vision, and dental insurance premiums for you and your dependents.

• ∞ Flexible Time Off.

• 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to take it all at once or spread it throughout the child's first year.

People also viewed

Cloudiax21 hours ago

Information Security, Compliance & Internal Controls Manager – ISO 27001

Anywhere in the WorldFull-timeCybersecurity / Security Engineer
ApplyView job
BLUVIT GmbH1 day ago

Information Security Consultant – M/F/D

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer€40k – €70k/year
ApplyView job
Eli Lilly and Company1 day ago

Enterprise AI Security Advisor

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $253k/year
ApplyView job
S + S Regeltechnik GmbH1 day ago

Senior IT Security Expert (m/f/d)

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
IntellectEU1 day ago

Senior Security Engineer

LU flagLuxembourg OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
BCD Travel1 day ago

Senior Information Security Auditor

CO flagColombia, +2 more countriesFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers