SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Chainguard is seeking a Staff Vulnerability Management Engineer to lead the company's novel vulnerabilities pipeline and coordinate industry-wide security efforts. This is an individual-contributor Staff role focused on technical leadership, cross-team influence, and owning hard problems at the intersection of AI supply chain security and open source software.
Key responsibilities include:
**Manage the Vulnerabilities Pipeline**: Own measurement, disclosure, and reporting of thousands of novel vulnerabilities identified weekly by frontier AI models and other sources. Calibrate response processes in response to emerging trends. Manage reporting of newly discovered vulnerabilities to upstream projects and maintainers. Run Chainguard's CNA (CVE Numbering Authority) program to assign new CVEs where necessary. Coordinate internal and external embargoes with customers, internal engineering teams, and external maintainers.
**Industry Coordination**: Work with the Linux Foundation, CISA, and other standards bodies to coordinate actions and responses. Guide and lead industry direction to ensure Chainguard customer needs are met by emerging standards. Represent Chainguard externally as the face of industry-leading efforts. Work with AI model vendors to guide future evolution of the software supply chain.
Required qualifications: 7+ years in software security, open source maintenance, or vulnerability disclosure management. Strong understanding of responsible disclosure. Practical expertise automating pipelines and processes at large scale. Deep experience with open source communities. Experience coordinating with public sector or industry standards bodies and working groups.
Nice-to-have qualifications include established thought leadership in vulnerability disclosure, familiarity with hardened container base images, CNA operation experience, software engineering background in Python/Java/JavaScript/Go, and security research or bug bounty experience.
The role offers a remote-first culture with flexible work arrangements, team meetups, and bi-annual destination summits. Chainguard is venture-backed by leading investors including Sequoia Capital, Kleiner Perkins, and Spark Capital, serving Fortune 500 enterprises and industry leaders.
About Chainguard
AI / Data / Infrastructure; Legal / Compliance / Risk — software supply-chain security and trusted container images.