Staff Product Security Engineer

🕒 May 6

🇺🇸 United States – Remote

💵 $17k - $231k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Chainguard

Chainguard

51 - 200 employees

Founded 2021

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.

📋 Description

• Build & Harden Secure Pipelines • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production. • Systematically, consistently and automatically capture the risk exposure of Chainguards products. • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign). • Proactively identify emerging customer security needs, and build solutions to meet these. • Cloud-Native Product Hardening • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack. • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management. • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.

🎯 Requirements

• 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout. • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code. • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers). • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub). • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar). • Fluency with container security: image scanning, distroless/minimal base images, runtime security. • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation). • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.

🏖️ Benefits

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!). • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck. • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset. • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Apply Now

Similar Jobs

🕒 May 6

Veeam Software

1001 - 5000

☁️ SaaS

🔒 Cybersecurity

🏢 Enterprise

Sales Specialist focused on Securiti AI solutions at Veeam. Driving growth in data security through complex enterprise deal closures and account expansion strategies.

🇺🇸 United States – Remote

💵 $231.5k - $429.8k / year

💰 $500M Private Equity Round on 2019-01

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info

🕒 May 6

Gartner

10,000+ employees

🏢 Enterprise

Director Analyst providing insights on infrastructure cybersecurity technologies for Gartner's clients. Analyzing market trends, collaborating with senior executives, and publishing research findings.

🕒 May 6

Achieve

1001 - 5000

💸 Finance

💳 Fintech

Principal Security Engineer at Achieve responsible for security solutions across various platforms. Evaluating and implementing robust security measures while collaborating with engineering teams.

🇺🇸 United States – Remote

💵 $68 - $75 / hour

💰 $50M Debt Financing on 2023-06

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info

🕒 May 6

ASSA ABLOY Opening Solutions

10,000+ employees

🔐 Security

🔧 Hardware

🤝 B2B

Director of Supply Chain Security at HID leading corporate-wide Supply Chain Security program. Ensuring software integrity, security, and trustworthiness through policies and standards across diverse products and environments.

🇺🇸 United States – Remote

💵 $230k - $250k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🕒 May 5

Hotel Engine

201 - 500

🛍️ eCommerce

🚗 Transport

Staff Cloud Security Engineer at Engine focusing on securing AWS and GCP cloud environments. Collaborating with cross-functional teams to enhance cloud security operations and strategies.

🇺🇸 United States – Remote

💵 $137.3k - $190k / year

💰 $65M Series B on 2021-12

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer