Senior Security Engineer
Senior Security Engineer responsible for architecting and securing Chainguard's multi-cloud infrastructure (primarily GCP), embedding security into developer platforms, and hardening environments for AI/agentic workflows using IaC and Kubernetes. Requires strong GCP expertise, DevOps background, and staff-level cloud security experience.
About the job
What you'll do
- Architect and maintain cloud environments built to be secure, resilient, and optimized for performance
- Partner hands-on with the Developer Platform team to embed security into the architecture and tooling developers use every day
- Work closely with our IAM counterparts to design and enforce identity and access strategies across all cloud environments
- Harden cloud platforms against emerging threats while keeping them resilient and highly available
- Bring a DevOps mindset — building automation, pipelines, and guardrails using Terraform/IaC and Kubernetes
- Help secure the infrastructure behind AI-driven pipelines and agentic workflows as they become a growing consumer of the software supply chain
- Act as a trusted advisor and collaborator across engineering, translating security requirements into practical, adoptable designs that other teams actually want to use — sharing context generously and putting shared outcomes ahead of individual credit
- Help set the long-term architectural vision for how our cloud environments scale securely
- Adapt architecture and priorities as the company scales — reworking plans as needs, tooling, or team structure shift
- Assist during relevant incident response investigations
What we're looking for
- Strong, hands-on GCP administrative experience — this is a must-have, not a nice-to-have
- Experience with AWS and/or Azure is a plus
- Solid DevOps background — comfort with Terraform/IaC, Kubernetes (GKE), and CI/CD pipelines
- Familiarity with software supply chain security concepts particularly SLSA is a strong plus
- Experience securing or architecting AI/ML infrastructure or agentic workflows
- Outstanding interpersonal and communication skills — you'll plan, coordinate, and build consensus with the Developer Platform team, IAM stakeholders, and other partners across the org
- Staff-level experience architecting and securing complex, multi-cloud environments
- Comfort with ambiguity and rapid change — prior experience at a fast-moving or late-stage startup is a strong plus
- A track record of designing systems that are secure, resilient, and built to accelerate — not slow down — engineering velocity
Skills
GCP, AWS, Azure, Terraform, Kubernetes, GKE, CI/CD, Slsa, Iac, DevOps
Similar jobs
Security Engineering jobsSenior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.
Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.