Staff Product Security Engineer

Job not on LinkedIn

🔥 51 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Chainguard

Chainguard

51 - 200 employees

Founded 2021

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.

📋 Description

• Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production. • Systematically, consistently, and automatically capture the risk exposure of Chainguard’s products. • Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation. • Identify emerging customer security needs and build solutions to meet them. • Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures. • Define and drive adoption of baseline security standards, including pod security standards, network policies, workload identity, and secrets management. • Evaluate and operationalize CNAPP/CSPM tooling for continuous visibility into cloud-native risk. • Provide technical leadership, cross-team influence, and ownership of complex security problems as an individual contributor.

🎯 Requirements

• 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout. • Strong proficiency in Go or Python, with ability to write, review, and debug production-quality code. • Deep hands-on production Kubernetes experience, including cluster hardening, RBAC, network policies, and admission controllers. • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services. • Proven track record designing and securing CI/CD pipelines using GitHub Actions, Cloud Build, Tekton, or similar. • Fluency with container security, including image scanning, distroless/minimal base images, and runtime security. • Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation. • Solid understanding of OWASP, NIST, and cloud security frameworks, and ability to apply them pragmatically.

🏖️ Benefits

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. • Receive stock options upon hire and promotion. • Participate in secondary offerings. • 10 years to exercise stock options. • 100% covered health, vision and dental insurance premiums for you and your dependents. • ∞ Flexible Time Off. • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout the child's first year.

Apply Now

Similar Jobs

🔥 2 hours ago

Atos

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Cybersecurity advisory director leading secure digital transformation consulting for Atos clients in Canada and North America. Shaping strategy, managing executive engagements, developing consultants, and driving profitable practice growth.

🗣️🇫🇷 French Required

🕒 2 days ago

Kyndryl

10,000+ employees

💼 Consulting

📦 Logistics

🏥 Healthcare

Mainframe Security Architect designing IBM Z and z/OS security for Kyndryl’s managed-services clients. Leading architecture, integration, operational readiness, and resilient security delivery.

🕒 3 days ago

LiveKit

11 - 50

🔌 API

🤖 Artificial Intelligence

📡 Telecommunications

🇨🇦 Canada – Remote

💵 $200k - $300k / year

💰 Venture Round on 2022-09

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🕒 July 29

High Tech Genesis

51 - 200

📦 Logistics

📣 Marketing

🏭 Manufacturing

Experienced Workday Reporting, Security & HRIS Analyst supporting HR, Payroll, IT, Finance teams with Workday solutions. Involves configuration, reporting, and collaboration with various business units.

🕒 July 28

Forward Financing

201 - 500

💸 Finance

💳 Fintech

🤝 B2B

Staff Security Engineer owning the security technology stack for a fintech company. Leading technical direction and mentoring engineers across security functions.

🇨🇦 Canada – Remote

💵 $160k - $200k / year

💰 $250M Debt Financing on 2021-05

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer