Staff Product Security Engineer

🔥 21 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Chainguard

Chainguard

51 - 200 employees

Founded 2021

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.

📋 Description

• Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production. • Systematically, consistently, and automatically capture the risk exposure of Chainguard’s products. • Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation using SLSA, Sigstore, and Cosign. • Proactively identify emerging customer security needs and build solutions to meet them. • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface. • Define and drive adoption of baseline security standards, including pod security standards, network policies, workload identity, and secrets management. • Evaluate and operationalize CNAPP/CSPM tooling for continuous visibility into cloud-native risk. • Provide technical leadership, cross-team influence, and ownership of complex security problems as an individual contributor.

🎯 Requirements

• 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout. • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code. • Deep, hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers. • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services such as GCP Security Command Center and AWS Security Hub. • Proven track record designing and securing CI/CD pipelines using GitHub Actions, Cloud Build, Tekton, or similar. • Fluency with container security, including image scanning, distroless/minimal base images, and runtime security. • Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation. • Solid understanding of OWASP, NIST, and cloud security frameworks and their pragmatic application. • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems is nice to have. • Experience with policy-as-code tools such as OPA, Kyverno, and Conftest is nice to have. • Contributions to open source security projects are nice to have. • Background in security research or offensive security, such as bug bounty, CTF, or penetration testing, is nice to have.

🏖️ Benefits

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. • Receive stock options upon hire and promotion. • Participation in secondary offerings. • 10 years to exercise stock options. • 100% covered health, vision and dental insurance premiums for you and your dependents. • ∞ Flexible Time Off. • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout the child's first year.

Apply Now

Similar Jobs

🕒 3 days ago

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform, products, CI/CD, and production infrastructure. Leading threat modeling, cloud security automation, vulnerability management, and detection and response operations.

🕒 July 27

LastPass

501 - 1000

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Principal Cloud Security Engineer at LastPass ensuring security best practices across cloud infrastructure. Partnering with engineering teams to drive secure practices and solutions.

🕒 June 29

Zscaler

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Principal AI Security Specialist driving AI technical strategy and ensuring enterprise security. Collaborate with executives and deliver compelling demonstrations of Zscaler's AI security capabilities.

🕒 May 20

Chainalysis Inc.

501 - 1000

🔌 API

💳 Fintech

🔒 Cybersecurity

Staff Security Engineer overseeing product security for Chainalysis' SaaS solutions and leading risk management frameworks. Engaging directly with AI tools and security automation.

🕒 May 19

Kraken Digital Asset Exchange

1001 - 5000

₿ Crypto

💸 Finance

💳 Fintech

Staff Security Architect at Kraken Security Labs managing security architecture and assessments for crypto products. Collaborating across teams to secure infrastructure and applications.