Join Chainguard as a Staff Product Security Engineer focusing on secure software and pipeline integrity. Lead efforts in product hardening and cloud-native security.
Responsibilities
Build & Harden Secure Pipelines
Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production.
Systematically, consistently and automatically capture the risk exposure of Chainguards products.
Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign).
Proactively identify emerging customer security needs, and build solutions to meet these.
Cloud-Native Product Hardening
Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack.
Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management.
Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.
Requirements
7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers).
Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
Fluency with container security: image scanning, distroless/minimal base images, runtime security.
Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
Benefits
Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.
Senior security advisor simulating and mitigating cyberthreats for Desjardins, North America's largest cooperative financial group. Leading offensive security methodologies, tools and strategic initiatives.
Staff Product Security Engineer building customer identity and authentication services for Affirm’s buy - now - pay - later platform. Designing secure, scalable CIAM backend systems and integrations.
Senior Security Engineer securing AWS infrastructure, production systems, and AI - driven workflows. Building guardrails, vulnerability remediation, monitoring, and incident response for a rapidly scaling platform.