Staff Product Security Engineer

🕒 il y a 1 mois

🇺🇸 États-Unis – Télétravail

💵 $17 000 - $231 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Chainguard

Chainguard

51 - 200 employés

Fondée en 2021

🔐 Sécurité

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard est une entreprise spécialisée dans la création d’images de conteneur sécurisées afin de renforcer la sécurité logicielle et la conformité. Ses produits incluent des images de conteneur à faible, voire zéro, CVE, mises à jour quotidiennement pour respecter des référentiels de sécurité et de conformité tels que FedRAMP, NIST 800-53, PCI-DSS, SOC 2 et les CIS Benchmarks. Chainguard se concentre sur la réduction des vulnérabilités, l’automatisation de la conformité et le support des workflows de développement, sans compromettre l’innovation ni la productivité. L’entreprise sert un large éventail d’industries, y compris des secteurs fortement réglementés, en fournissant des images durcies qui atténuent les risques de la chaîne d’approvisionnement logicielle et renforcent la sécurité des applications.

Description

• Build & Harden Secure Pipelines • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production. • Systematically, consistently and automatically capture the risk exposure of Chainguards products. • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign). • Proactively identify emerging customer security needs, and build solutions to meet these. • Cloud-Native Product Hardening • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack. • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management. • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.

🎯 Exigences

• 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout. • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code. • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers). • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub). • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar). • Fluency with container security: image scanning, distroless/minimal base images, runtime security. • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation). • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.

🏖️ Avantages

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!). • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck. • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset. • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Veeam Software

1001 - 5000

☁️ SaaS

🔒 Cybersecurity

🏢 Entreprise

Sales Specialist focused on Securiti AI solutions at Veeam. Driving growth in data security through complex enterprise deal closures and account expansion strategies.

🇺🇸 États-Unis – Télétravail

💵 $231 500 - $429 800 / an

💰 €500 000 000 Private Equity Round en 2019-01

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Gartner

10 000+ employés

🏢 Entreprise

Director Analyst providing insights on infrastructure cybersecurity technologies for Gartner's clients. Analyzing market trends, collaborating with senior executives, and publishing research findings.

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

IDEXX

10 000+ employés

⚕️ Assurance santé

🧬 Biotechnologie

Manager of Data Security leading data protection strategies and compliance at IDEXX, overseeing DSPM operations and partnering across engineering and business teams.

🇺🇸 États-Unis – Télétravail

💵 $160 000 - $180 000 / an

💰 Seed Round en 1984-01

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Achieve

1001 - 5000

💸 Finance

💳 Fintech

Principal Security Engineer at Achieve responsible for security solutions across various platforms. Evaluating and implementing robust security measures while collaborating with engineering teams.

🇺🇸 États-Unis – Télétravail

💵 $68 - $75 / heure

💰 €50 000 000 Debt Financing en 2023-06

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

ASSA ABLOY Opening Solutions

10 000+ employés

🔐 Sécurité

🔧 Matériel

🤝 B2B

Director of Supply Chain Security at HID leading corporate-wide Supply Chain Security program. Ensuring software integrity, security, and trustworthiness through policies and standards across diverse products and environments.

🇺🇸 États-Unis – Télétravail

💵 $230 000 - $250 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis