SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Chainguard is seeking a Staff Product Security Engineer to lead technical security initiatives across the company's software supply chain security platform. This is an individual-contributor Staff role focused on technical leadership, cross-team influence, and owning complex security problems.
You will design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production. You'll systematically capture risk exposure across Chainguard's products and implement software supply chain security controls including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign). You'll proactively identify emerging customer security needs and build solutions to address them.
On the cloud-native side, you'll lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. You'll harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface. You'll define and drive adoption of baseline security standards including pod security standards, network policies, workload identity, and secrets management. You'll also evaluate and operationalize CNAPP/CSPM tooling to maintain continuous visibility into cloud-native risk.
Required qualifications include 7+ years in software engineering or security engineering with meaningful hands-on security responsibility. You need strong proficiency in Go or Python, deep hands-on experience with Kubernetes in production, practical expertise with GCP and/or AWS, proven track record designing and securing CI/CD pipelines, fluency with container security, experience with software supply chain security tooling (Sigstore, SLSA, SBOM), and solid understanding of OWASP, NIST, and cloud security frameworks.
Nice-to-have skills include familiarity with Chainguard Images, policy-as-code tools (OPA, Kyverno, Conftest), open source security contributions, and background in security research or offensive security.
About Chainguard
AI / Data / Infrastructure; Legal / Compliance / Risk — software supply-chain security and trusted container images.