Staff Product Security Engineer

🕒 5 days ago

🇺🇸 United States – Remote

💵 $170k - $231k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Chainguard

Chainguard

51 - 200 employees

Founded 2021

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.

📋 Description

• Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production. • Systematically and automatically capture the risk exposure of Chainguard's products. • Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation. • Identify emerging customer security needs and build solutions to meet them. • Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures. • Define and drive adoption of baseline security standards, including pod security standards, network policies, workload identity, and secrets management. • Evaluate and operationalise CNAPP/CSPM tooling for continuous visibility into cloud-native risk. • Provide technical leadership, cross-team influence, and ownership of complex security problems as an individual contributor.

🎯 Requirements

• 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility. • Strong proficiency in Go or Python; ability to write, review, and debug production-quality code. • Deep hands-on production Kubernetes experience, including cluster hardening, RBAC, network policies, and admission controllers. • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services. • Proven experience designing and securing CI/CD pipelines, such as GitHub Actions, Cloud Build, or Tekton. • Fluency with container security, including image scanning, distroless/minimal base images, and runtime security. • Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation. • Solid understanding of OWASP, NIST, and cloud security frameworks and their pragmatic application. • Nice to have: familiarity with Chainguard Images or other minimal/hardened container base image ecosystems. • Nice to have: experience with policy-as-code tools such as OPA, Kyverno, or Conftest. • Nice to have: contributions to open source security projects. • Nice to have: security research or offensive security background, such as bug bounty, CTF, or penetration testing.

🏖️ Benefits

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. • Receive stock options upon hire and promotion. • Participation in secondary offerings. • 10 years to exercise stock options. • 100% covered health, vision and dental insurance premiums for you and your dependents. • Flexible time off. • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents. • Equal opportunity employer.

Apply Now

Similar Jobs

🕒 5 days ago

Optiv

1001 - 5000

Regional cybersecurity sales director leading Optiv’s complex security solutions revenue across the South Atlantic. Recruiting, coaching, forecasting, and expanding executive client and partner relationships.

🕒 5 days ago

GE HealthCare

10,000+ employees

🏥 Healthcare

💊 Pharmaceuticals

Staff Cyber Security Engineer securing GE HealthCare’s cloud, on-premises, and medical technology environments. Leading architecture, vulnerability management, risk analysis, and compliance initiatives.

🕒 5 days ago

Snowflake

5001 - 10000

💼 Consulting

📣 Marketing

Staff Security Engineer protecting Snowflake’s enterprise cloud data platform through endpoint security, threat detection, and AI-powered automation. Owning security tooling strategy across a complex multi-cloud, multi-SaaS environment.

🕒 5 days ago

Huron

5001 - 10000

🏥 Healthcare

📦 Logistics

📣 Marketing

Cloud Security Architect securing Huron’s consulting operations across Azure and hybrid environments. Designing assessments, automation, IaC baselines, and remediation roadmaps for enterprise security.

🇺🇸 United States – Remote

💵 $140k - $190k / year

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info

🕒 5 days ago

Aledade, Inc.

501 - 1000

🏥 Healthcare

⚕️ Healthcare Insurance

🏢 Enterprise

Staff Security Engineer designing IAM and cloud security services for Aledade, which supports independent primary-care practices. Automating identity governance, protecting workloads, and advancing healthcare security.

🇺🇸 United States – Remote

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer