
Staff Software Engineer, Malware Detection
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Canada.
• Lead the engineering efforts for Chainguard's shared malware scanning platform.
• Take ownership of the platform's architecture, scalability, and reliability.
• Develop measurement pipelines, metrics, and dashboards to assess detection coverage and accuracy.
• Create feedback mechanisms between Engineering and Product Security to ensure rapid evaluation and deployment of detection changes.
• Design systems for reviewing, escalating, and rectifying detections, including bulk corrections at an ecosystem scale.
• Manage scan orchestration, verdict storage, and APIs utilized by consuming products.
• Expand the scanner's capabilities from Libraries to Containers, Agent Skills, and future artifact types.
• Balance the aspects of detection quality, performance, extensibility, throughput, latency, and cost.
• Implement deterministic static analysis and AI-assisted reasoning for artifact content evaluation.
• Collaborate with Product Security to transition emerging threat detections from research prototypes into production.
• Develop APIs and services for investigating, enforcing, and appealing scanner results.
• Construct backend systems for policy management and operations at an enterprise scale.
• Operate the scanner as a critical component in customer installations, ensuring alerting, queue health, verdict-before-serve guarantees, and incident response.
• Work with Product to define customer experiences related to scanner verdicts.
• Several years of experience in building and managing production backend or infrastructure systems, demonstrating staff-level ownership and technical leadership.
• Proficient in Go, or possess extensive backend systems experience with the ability to quickly adapt to Go.
• Proven experience in owning highly technical platforms or backend infrastructure that supports multiple products or internal clients.
• Familiarity with high-throughput, event-driven pipelines where throughput, latency, and correctness are crucial.
• Strong knowledge of software supply chain security, malware detection, vulnerability management, or related security fields.
• Evidence of making engineering design and prioritization decisions in complex and ambiguous technical environments.
• Comfortable with owning and improving metrics such as false-positive rates.
• Experience in deploying and managing production services, with sound judgment regarding reliability, observability, and operational trade-offs.
• Background in mentoring engineers and elevating the standard for design and code reviews.
• Exceptional cross-functional collaboration skills with teams in Product, Security, Design, and GTM.
• Nice to have: experience in malware detection, static analysis, SCA, vulnerability scanning, package ecosystems, reusable platform capabilities, cloud infrastructure, software supply chain security, enterprise security platforms, AI-assisted security analysis, sandboxing, dynamic analysis, eBPF, gVisor, seccomp, container isolation, Terraform.
• Flexible & Remote-First Culture: Work remotely with opportunities for team meetups, bi-annual destination summits, and a monthly stipend for coworking spaces, phone, and internet expenses.
• Stock options granted upon hire and promotion.
• Opportunity to participate in secondary offerings.
• 10 years to exercise stock options.
• 100% coverage of health, vision, and dental insurance premiums for you and your dependents.
• ∞ Flexible Time Off.
• 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents, which can be taken all at once or throughout the child's first year.
• Opportunities for team meetups.
• Bi-annual destination summits.
• Monthly stipend for coworking, phone, and internet expenses.
Arista Networks
knowmad mood
Capital One
HealthEdge
Get handpicked remote jobs straight to your inbox weekly.