SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Software Engineer (Malware Detection)

Chainguard - Remote - Remote - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Chainguard is building the trusted source for open-source software. Every artifact distributed is evaluated by a malware scanner before reaching customers, determining whether packages, containers, and AI agent skills are safe to use. This scanner sits between customers and compromised software. You will lead the engineering of Chainguard's shared malware detection platform, owning its architecture, scale, and reliability. This is a backend and production-infrastructure role in a security domain, not a security research role. Product Security develops what the scanner looks for; you build and operate the machinery that makes those detections fast, accurate, and dependable across every artifact distributed. Key responsibilities include: **Detection Quality:** Build measurement systems behind coverage and precision—pipelines, metrics, and dashboards that steer the product. Engineer feedback loops between Engineering and Product Security so detection changes can be evaluated and shipped in hours, not days. Build systems for reviewing, escalating, and correcting detections quickly, including bulk correction at ecosystem scale. **Scanner Platform:** Own the architecture of the shared malware scanning platform: scan orchestration, verdict storage, and APIs that every consuming product depends on. Scale the scanner beyond Libraries to Containers, Agent Skills, and future artifact types. Make tradeoffs between detection quality, performance, and extensibility concrete in throughput, latency, and cost. **Threat Detection:** Build and scale the analysis itself—deterministic static analysis alongside AI-assisted reasoning over artifact contents. Partner with Product Security to take emerging-threat detections from research prototype to production, running on every new release across every ecosystem covered. **Customer Experience:** Build APIs and services behind how customers investigate, enforce, and appeal scanner findings. Build the backend for policy management and enterprise-scale operations. **Production Ownership:** Operate the scanner as a system in the critical path of every customer install—alerting, queue health, verdict-before-serve guarantees, and incident response. Chainguard's customers include Fortune 500 enterprises and global leaders like Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake. The company is venture-backed by Amplify, IVP, Kleiner Perkins, Lightspeed, Mantis VC, Redpoint, Sequoia Capital, and Spark Capital. **Requirements:** - Multiple years building and operating production backend or infrastructure systems, with a clear track record of staff-level ownership and technical leadership - Strong Go experience, or deep backend systems experience with the ability to ramp quickly in Go - Experience owning highly technical platforms or backend infrastructure that supports multiple products or internal customers - Experience with high-throughput, event-driven pipelines where throughput, latency, and correctness all matter simultaneously - Strong understanding of software supply chain security, malware detection, vulnerability management, or adjacent security domains - Demonstrated success making engineering design and prioritization decisions in technically complex and ambiguous environments - Comfort owning metrics like false-positive rate, instrumenting them honestly, and driving them down in a domain where both missed detections and false alarms carry real customer cost - Experience deploying and operating services in production, with strong judgment around reliability, observability, and operational tradeoffs - Experience mentoring engineers and raising the bar on design and code review - Excellent cross-functional collaboration skills with the ability to influence Product, Security, Design, and GTM partners **Nice to haves:** - Experience with malware detection, static analysis, software composition analysis (SCA), or vulnerability scanning - Familiarity with package ecosystems such as npm, PyPI, Maven, Go modules, or container registries - Experience building reusable platform capabilities that support multiple products - Background in cloud infrastructure, software supply chain security, or enterprise security platforms - Experience working with AI-assisted security analysis or automated threat detection systems, where output quality is measured and regression-tested - Experience with sandboxing and dynamic analysis: eBPF, gVisor, seccomp, or container isolation - Comfort working across application and infrastructure layers, including cloud infrastructure and infrastructure as code tools such as Terraform

About Chainguard

AI / Data / Infrastructure; Legal / Compliance / Risk — software supply-chain security and trusted container images.

Similar roles