Skip to content
DockerDocker

Senior Supply Chain Security Engineer

Maintains security-hardened container images and adapts upstream Helm charts for Kubernetes environments, with a focus on supply-chain security, CVE triage, testing, and package-maintainer practices. Requires 6+ years of backend engineering experience and strong container, Kubernetes, YAML, and security expertise.

About the job

Responsibilities

  • Author and maintain image definition files that track upstream open-source project releases, define build steps, and keep the catalogue current across dozens of images.
  • Adapt upstream Helm charts, including cert-manager, Grafana, MongoDB, and Kyverno, to work with Docker Hardened Images, handling security constraints, non-root contexts, and Kubernetes compatibility concerns.
  • Track upstream version releases and semantic-versioning patterns across monorepos and standard repositories, including major-version breaks and dependency chains.
  • Write Go-based integration tests that validate images and charts in real Kubernetes environments.
  • Triage CVEs and contribute to security-hardening decisions across images.
  • Review peer definitions and chart pull requests against established conventions and identify issues before they reach customers.
  • Participate in an on-call rotation outside standard business hours, including evenings, weekends, and holidays, as needed.

Requirements

  • 6+ years of backend engineering experience with production-grade systems.
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Strong familiarity with containers and Kubernetes, including cert-manager, Kyverno, Grafana, and Istio; experience deploying these systems and reading upstream Helm chart source.
  • Comfort using YAML as a primary working medium.
  • Understanding of container security fundamentals, including non-root users, UID/GID, image layers, multi-architecture builds, and software supply-chain concepts.
  • Some Go experience sufficient to read and write test code.
  • A maintainer mindset focused on consistency, pattern adherence, and downstream impact.
  • Familiarity with GitHub-based open-source workflows, including pull requests, upstream tracking, and monorepo conventions.

Nice to have

  • Experience maintaining packages for a Linux distribution, Homebrew, or a similar ecosystem.
  • Helm chart authorship or contribution experience.
  • Familiarity with supply-chain tooling such as Sigstore, SBOMs, and SLSA.
  • Experience in a regulated or security-conscious environment.

Compensation and benefits

  • Canada: CA$210,627–CA$341,690 plus equity.
  • United States: $154,600–$250,800 plus equity.
  • EU: €83,900–€139,700 plus equity.
  • Flexible remote work.
  • Quarterly Whaleness Days and an end-of-year Whaleness break.
  • Home-office setup support.
  • 16 weeks of paid parental leave after 6 months of employment.
  • Technology stipend equivalent to $100 USD net per month.
  • PTO plan.
  • Training stipend for conferences, courses, and classes.
  • Equity participation.
  • Medical benefits, retirement benefits, and holidays vary by country.

Skills

Kubernetes, Helm, Yaml, Go, Docker, Container Security, Linux, GitHub, Sigstore, Sbom, Slsa, Grafana, Kyverno, Istio, Cert-Manager

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.