
Senior Product Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Design, construct, and sustain secure CI/CD pipelines equipped with security gates that detect issues prior to production.
• Methodically, consistently, and automatically assess the risk exposure of Chainguard's products.
• Implement and uphold software supply chain security measures, including signed artifacts, SBOMs, and provenance attestation utilizing SLSA, Sigstore, and Cosign.
• Recognize emerging security requirements from customers and develop solutions to address them.
• Conduct security architecture evaluations and threat modeling for Kubernetes-based workloads operating on GCP and AWS.
• Strengthen container images, Kubernetes cluster configurations, and cloud IAM settings to reduce the attack surface.
• Establish and promote the adoption of fundamental security standards, including pod security standards, network policies, workload identity, and secrets management.
• Over 5 years of experience in software engineering, security engineering, or a combined role with substantial hands-on security responsibilities.
• Strong expertise in Go or Python, capable of writing, reviewing, and debugging production-quality code.
• Extensive, hands-on experience with Kubernetes in production, encompassing cluster hardening, RBAC, network policies, and admission controllers.
• Practical knowledge of GCP and/or AWS, including IAM, workload identity, secrets management, and security services.
• Demonstrated success in designing and securing CI/CD pipelines, such as GitHub Actions, Cloud Build, or Tekton.
• Proficiency in container security, including image scanning, distroless/minimal base images, and runtime security.
• Experience with software supply chain security tools and frameworks, including Sigstore, SLSA, and SBOM generation.
• Strong understanding of OWASP, NIST, and cloud security frameworks and their practical applications.
• Familiarity with Chainguard Images or similar minimal/hardened container base image ecosystems.
• Experience with policy-as-code tools like OPA, Kyverno, and Conftest.
• Contributions to open source security projects.
• Background in security research or offensive security, such as bug bounty, CTF, or penetration testing.
• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, as well as phone and internet expenses.
• Receive stock options upon hire and promotion.
• Participate in secondary offerings and have 10 years to exercise your options.
• 100% covered health, vision, and dental insurance premiums for you and your dependents.
• ∞ Flexible Time Off.
• 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to take it all at once or spread it throughout the child's first year.
Cloudiax
BLUVIT GmbH
Eli Lilly and Company
S + S Regeltechnik GmbH
Get handpicked remote jobs straight to your inbox weekly.