FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Product Security Engineer
Chainguard. Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in designing and securing CI/CD pipelines, implementing software supply chain security controls, and hardening Kubernetes-based workloads on GCP and AWS. Proficient in Go or Python programming, with a strong focus on container security and compliance with industry standards.
Highest-signal resume keywords
CI/CD Pipeline Design and SecurityKubernetes Hardening and ManagementGCP and AWS Security ExpertiseSoftware Supply Chain Security ToolsContainer Security Best Practices
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Go ProgrammingPython ProgrammingKubernetes ManagementCI/CD Pipeline SecurityCloud IAMContainer SecuritySLSA FrameworkSigstoreSBOM GenerationPolicy-as-Code Tools
Tools & Technologies
GitHub ActionsCloud BuildTektonOPAKyvernoConftest
Industry Keywords
OWASPNISTCloud Security FrameworksChainguard ImagesSecurity Architecture ReviewsThreat ModelingBug BountyCTFPenetration Testing
Tech Stack
Tools & technologiesAWSCloudGoogle Cloud PlatformKubernetesOpen SourcePythonGo
About the role
Key responsibilities & impact- Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production.
- Systematically, consistently, and automatically capture the risk exposure of Chainguard's products.
- Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation using SLSA, Sigstore, and Cosign.
- Identify emerging customer security needs and build solutions to meet them.
- Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
- Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface.
- Define and drive adoption of baseline security standards, including pod security standards, network policies, workload identity, and secrets management.
Requirements
What you’ll need- 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
- Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
- Deep, hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers.
- Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services.
- Proven track record designing and securing CI/CD pipelines, such as GitHub Actions, Cloud Build, or Tekton.
- Fluency with container security, including image scanning, distroless/minimal base images, and runtime security.
- Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation.
- Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
- Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
- Experience with policy-as-code tools such as OPA, Kyverno, and Conftest.
- Contributions to open source security projects.
- Background in security research or offensive security, such as bug bounty, CTF, or penetration testing.
Benefits
Comp & perks- Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
- Receive stock options upon hire and promotion.
- Participate in secondary offerings and have 10 years to exercise your options.
- 100% covered health, vision and dental insurance premiums for you and your dependents.
- ∞ Flexible Time Off.
- 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout the child's first year.