SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 170,000 - 231,000 / annual
Chainguard is seeking a Staff Product Security Engineer to lead technical security initiatives across the organization. This is an individual-contributor role focused on designing and hardening secure CI/CD pipelines, implementing software supply chain security controls, and securing cloud-native infrastructure.
Key responsibilities include:
**Secure Pipeline Development**: Design and build CI/CD pipelines with security gates that catch issues before production. Implement software supply chain security controls including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign). Systematically capture and monitor risk exposure across Chainguard's products. Proactively identify emerging customer security needs and build solutions.
**Cloud-Native Hardening**: Lead security architecture reviews and threat modeling for Kubernetes workloads on GCP and AWS. Harden container images, Kubernetes configurations, and cloud IAM postures to minimize attack surface. Define and drive adoption of baseline security standards including pod security standards, network policies, workload identity, and secrets management. Evaluate and operationalize CNAPP/CSPM tooling for continuous visibility into cloud-native risk.
**Required Qualifications**: 7+ years in software engineering or security engineering with meaningful hands-on security responsibility. Strong proficiency in Go or Python with production-quality code experience. Deep hands-on Kubernetes experience in production environments. Practical expertise with GCP and/or AWS (IAM, workload identity, secrets management, security services). Proven track record designing and securing CI/CD pipelines. Fluency with container security practices. Experience with software supply chain security tooling (Sigstore, SLSA, SBOM). Solid understanding of OWASP, NIST, and cloud security frameworks.
**Nice to Have**: Familiarity with Chainguard Images or hardened container ecosystems, policy-as-code tools (OPA, Kyverno), open source security contributions, or security research/offensive security background.
Chainguard is a venture-backed company delivering hardened, secure, production-ready builds of open source software. Customers include Fortune 500 enterprises and industry leaders like OpenAI, Snap, and Snowflake.
About Chainguard
AI / Data / Infrastructure; Legal / Compliance / Risk — software supply-chain security and trusted container images.