Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Chainguard

Senior Product Security Engineer

Chainguard

. Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production.

Posted 10/8/2026full-timeRemote • United StatesSenior💰 $157,000 - $184,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing and securing CI/CD pipelines, implementing software supply chain security controls, and hardening Kubernetes-based workloads on GCP and AWS. Proficient in Go or Python programming, with a strong focus on container security and compliance with industry standards.

Highest-signal resume keywords
CI/CD Pipeline Design and SecurityKubernetes Hardening and ManagementGCP and AWS Security ExpertiseSoftware Supply Chain Security ToolsContainer Security Best Practices

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Go ProgrammingPython ProgrammingKubernetes ManagementCI/CD Pipeline SecurityCloud IAMContainer SecuritySLSA FrameworkSigstoreSBOM GenerationPolicy-as-Code Tools
Tools & Technologies
GitHub ActionsCloud BuildTektonOPAKyvernoConftest
Industry Keywords
OWASPNISTCloud Security FrameworksChainguard ImagesSecurity Architecture ReviewsThreat ModelingBug BountyCTFPenetration Testing

Tech Stack

Tools & technologies
AWSCloudGoogle Cloud PlatformKubernetesOpen SourcePythonGo

About the role

Key responsibilities & impact
  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production.
  • Systematically, consistently, and automatically capture the risk exposure of Chainguard's products.
  • Implement and enforce software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation using SLSA, Sigstore, and Cosign.
  • Identify emerging customer security needs and build solutions to meet them.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface.
  • Define and drive adoption of baseline security standards, including pod security standards, network policies, workload identity, and secrets management.

Requirements

What you’ll need
  • 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
  • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
  • Deep, hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers.
  • Practical expertise with GCP and/or AWS, including IAM, workload identity, secrets management, and security services.
  • Proven track record designing and securing CI/CD pipelines, such as GitHub Actions, Cloud Build, or Tekton.
  • Fluency with container security, including image scanning, distroless/minimal base images, and runtime security.
  • Experience with software supply chain security tooling and frameworks, including Sigstore, SLSA, and SBOM generation.
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
  • Experience with policy-as-code tools such as OPA, Kyverno, and Conftest.
  • Contributions to open source security projects.
  • Background in security research or offensive security, such as bug bounty, CTF, or penetration testing.

Benefits

Comp & perks
  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Receive stock options upon hire and promotion.
  • Participate in secondary offerings and have 10 years to exercise your options.
  • 100% covered health, vision and dental insurance premiums for you and your dependents.
  • ∞ Flexible Time Off.
  • 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout the child's first year.