See all roles

[Remote] Staff Product Security Engineer

Work from home Full-time role Hiring

Note: The job is a remote job and is open to candidates in USA. Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The Staff Product Security Engineer will design and maintain secure CI/CD pipelines, lead security architecture reviews, and define security standards to minimize risk across Chainguard's product stack.

Responsibilities

  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production
  • Systematically, consistently and automatically capture the risk exposure of Chainguards products
  • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign)
  • Proactively identify emerging customer security needs, and build solutions to meet these
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack
  • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management
  • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk

Skills

  • 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout
  • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code
  • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers)
  • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub)
  • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar)
  • Fluency with container security: image scanning, distroless/minimal base images, runtime security
  • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation)
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems
  • Experience with policy-as-code tools (OPA, Kyverno, Conftest)
  • Contributions to open source security projects
  • Background in security research or offensive security (bug bounty, CTF, penetration testing)

Benefits

  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
  • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Company Overview

  • Chainguard is a cloud-native development platform that provides low-to-zero CVE container images for building and running applications. It was founded in 2021, and is headquartered in Kirkland, Washington, USA, with a workforce of 201-500 employees. Its website is https://www.chainguard.dev.
  • Company H1B Sponsorship

  • Chainguard has a track record of offering H1B sponsorships, with 1 in 2026, 1 in 2024, 2 in 2023. Please note that this does not guarantee sponsorship for this specific role.
  • Apply To This Job

    You might like

    [Remote] Data Scientist

    Work from home Full-time role

    [Remote] Senior Accountant II

    Work from home Full-time role

    [Remote] Senior Salesforce Administrator

    Work from home Full-time role

    [Remote] Business Development Director- Northrop Grumman

    Work from home Full-time role

    [Remote] Senior Business Systems Analyst - SAP (S4 Hana)

    Work from home Full-time role

    [Remote] SAP Auto Industry Consultant

    Work from home Full-time role

    [Remote] In House Marketing Executive - $2000 Incentive *Potential

    Work from home Full-time role

    [Remote] Senior Key Account Manager, OEM IT Cooling

    Work from home Full-time role

    [Remote] Associate Director - OneStream Architect, Account Reconciliation & Transaction Matching

    Work from home Full-time role

    [Remote] Business Analyst

    Work from home Full-time role

    Family Law Litigation Attorney ( WFH ) #ESF1490

    Work from home Full-time role

    Remote Administrative Assistant (Logistics-Shipping)

    Work from home Full-time role

    Managing Editor, Creative Writing Strategy - EMEA Content Expertise

    Work from home Full-time role

    Junior Data Analyst - Data Operated Bus

    Work from home Full-time role

    Youth Outreach Coordinator

    Work from home Full-time role

    Experienced Full Stack Product Manager – Web & Cloud Application Development

    Work from home Full-time role

    Rewritten Job Title:

    Work from home Full-time role

    Experienced Live Chat Support Representative – Remote Customer Service Opportunity for Entertainment Enthusiasts at blithequark

    Work from home Full-time role

    Experienced Remote Pharmacy Customer Service Representative – Patient Benefits Support

    Work from home Full-time role

    Experienced Retail Customer Experience Associate – Delivering Exceptional Service and Support in a Fast-Paced Environment at blithequark

    Work from home Full-time role