Senior Product Security Engineer

🔥 6 minutes ago

🇺🇸 United States – Remote

💵 $157k - $184k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 20%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Chainguard

Chainguard

51 - 200 employees

Founded 2021

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.

📋 Description

• Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production. • Systematically, consistently, and automatically capture the risk exposure of Chainguard's products. • Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation using SLSA, Sigstore, and Cosign. • Identify emerging customer security needs and build solutions to meet them. • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface. • Define and drive adoption of baseline security standards, including pod security standards, network policies, workload identity, and secrets management.

🎯 Requirements

• 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout. • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code. • Deep, hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers. • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services. • Proven track record designing and securing CI/CD pipelines, such as GitHub Actions, Cloud Build, or Tekton. • Fluency with container security, including image scanning, distroless/minimal base images, and runtime security. • Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation. • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically. • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems. • Experience with policy-as-code tools such as OPA, Kyverno, and Conftest. • Contributions to open source security projects. • Background in security research or offensive security, such as bug bounty, CTF, or penetration testing.

🏖️ Benefits

• Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. • Receive stock options upon hire and promotion. • Participate in secondary offerings and have 10 years to exercise your options. • 100% covered health, vision and dental insurance premiums for you and your dependents. • ∞ Flexible Time Off. • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout the child's first year.

Apply Now

Similar Jobs

🔥 1 hour ago

CNO Financial Group

1001 - 5000

🏥 Healthcare

💼 Consulting

📦 Logistics

Lead SailPoint security architect securing CNO’s insurance and financial services enterprise. Designing identity governance, access controls, and compliance architecture across U.S. operations.

🔥 3 hours ago

GuidePoint Security

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Architect designing and securing Active Directory and Entra ID environments. GuidePoint Security delivers cybersecurity expertise, solutions, and services to organizations and government agencies.

🔥 6 hours ago

Applied Research Solutions

501 - 1000

💼 Consulting

📦 Logistics

🏭 Manufacturing

Cybersecurity engineer securing ARS’s Azure-based DoD DevSecOps cloud environments. Supporting RMF, CMMC, ATO compliance, eMASS artifacts, and security governance.

🔥 6 hours ago

RTX

10,000+ employees

🏭 Manufacturing

💼 Consulting

📦 Logistics

Associate Director leading Workday HCM Core and security governance at RTX, the aerospace and defense company. Driving enterprise security architecture, data governance, releases, and functional team leadership.

🔥 7 hours ago

Axios

501 - 1000

💼 Consulting

📣 Marketing

📱 Media

IT Security Specialist protecting Axios’s AI-enabled media technology environment. Owning endpoint, identity, SaaS, security awareness, and AI security.

Jamf

MacOS