SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Product Security Engineer

Chainguard - Remote - Remote - posted 2026-08-06

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Chainguard is seeking a Staff Product Security Engineer to lead technical security initiatives across the organization. This is an individual-contributor role focused on designing and hardening secure CI/CD pipelines, implementing software supply chain security controls (SLSA, Sigstore, SBOMs, provenance attestation), and securing cloud-native infrastructure. Key responsibilities include: **Secure Pipeline Architecture**: Design and maintain CI/CD pipelines with security gates that prevent issues from reaching production. Systematically capture risk exposure across Chainguard's products. Implement signed artifacts, SBOMs, and provenance attestation frameworks. Proactively identify emerging customer security needs and build solutions. **Cloud-Native Hardening**: Lead security architecture reviews and threat modeling for Kubernetes workloads on GCP and AWS. Harden container images, Kubernetes configurations, and cloud IAM postures. Define and drive adoption of baseline security standards including pod security standards, network policies, workload identity, and secrets management. Evaluate and operationalize CNAPP/CSPM tooling for continuous cloud-native risk visibility. **Required Qualifications**: 7+ years in software engineering or security engineering with hands-on security responsibility. Strong proficiency in Go or Python. Deep production Kubernetes experience (cluster hardening, RBAC, network policies, admission controllers). Practical expertise with GCP and/or AWS (IAM, workload identity, secrets management, security services). Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton). Fluency with container security (image scanning, distroless images, runtime security). Experience with software supply chain security tooling (Sigstore, SLSA, SBOM generation). Solid understanding of OWASP, NIST, and cloud security frameworks. **Nice to Have**: Familiarity with Chainguard Images or hardened container ecosystems, policy-as-code tools (OPA, Kyverno), open source security contributions, or security research/offensive security background. This role offers technical leadership, cross-team influence, and ownership of hard problems in a venture-backed company serving Fortune 500 enterprises and industry leaders.

About Chainguard

AI / Data / Infrastructure; Legal / Compliance / Risk — software supply-chain security and trusted container images.

Similar roles