Senior Product Security Engineer securing software delivery pipelines at Chainguard. Focus on cloud-native security in CI/CD processes and Kubernetes environments.
Responsibilities
Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production.
Systematically, consistently and automatically capture the risk exposure of Chainguard's products.
Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign).
Proactively identify emerging customer security needs, and build solutions to meet these.
Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack.
Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management.
Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.
Requirements
5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers).
Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
Fluency with container security: image scanning, distroless/minimal base images, runtime security.
Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
Benefits
Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.
Lead cyber security program development, risk management, and incident response for Supply Ontario. Requires 7 - 10 years experience and CISSP or equivalent.
Principal Cybersecurity Engineer leading complex engineering efforts and guiding strategic security decisions at a Canadian company. Combines technical expertise with mentorship and business acumen to drive cybersecurity initiatives.
Senior Security Engineer at Chainguard shaping how open source defends itself. Collaborate with teams to enhance security posture and compliance with industry standards.
Senior Security Engineer managing AI platform posture at Chainguard to enhance security and efficiency. Collaborating with teams for proactive governance, administration, and risk management.
Senior Manager managing IAM compliance and security controls for RBC's enterprise. Overseeing risks, audits, and regulatory inquiries in a global security setting.
Sr IAM Engineer managing implementation and support of Secret Management solutions at RBC. Collaborating across teams to deliver secure, scalable identity solutions.
Principal Developer specializing in cloud security for Nasdaq. Driving initiatives and influencing technical direction in security for scalable cloud systems.
Cybersecurity Architect at Canaccord Genuity designing proactive security solutions. Collaborating with Security team and implementing Microsoft Defender Suite across hybrid environments.
Operations and Business Intelligence Specialist at Mirego managing contracts and improving BI performance for commercial operations. Collaborating with sales and ensuring smooth execution of processes and billing.
Security Researcher simulating advanced adversaries against Bright Data's collection products. Engaging in R&D while influencing team direction in a fully remote role.