Skip to content

Senior Product Security Engineer

157k – 184kUnited StatesRemote5+ YOE
Summary

Senior security engineer embedded in product development to build secure CI/CD pipelines, enforce supply chain controls, and harden Kubernetes workloads on GCP/AWS. Requires 5+ years experience, strong Go/Python skills, and deep Kubernetes and cloud security expertise.

About the role

What you’ll do

Build & Harden Secure Pipelines

  • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production.
  • Systematically, consistently and automatically capture the risk exposure of Chainguard's products.
  • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign).
  • Proactively identify emerging customer security needs, and build solutions to meet these.

Cloud-Native Product Hardening

  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack.
  • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management.
  • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.

What we're looking for

Required

  • 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
  • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
  • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers).
  • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub).
  • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
  • Fluency with container security: image scanning, distroless/minimal base images, runtime security.
  • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.

Nice to Have

  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
  • Experience with policy-as-code tools (OPA, Kyverno, Conftest).
  • Contributions to open source security projects.
  • Background in security research or offensive security (bug bounty, CTF, penetration testing).

Compensation & Benefits

  • Base Salary Range: $157,000—$184,000 USD
  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options.
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents.
  • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.
Skills
GoPythonKubernetesGCPAWSIAMCI/CDGitHub ActionsCloud BuildTektonContainer SecuritySigstoreSLSASBOMOWASP
Similar roles at this salary range
All Security Engineering jobs →
Shield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

160k – 240kSan Diego, CASecurity EngineeringOn-site7+ YOEGoOPA
Coinbase

Insider Threat Analyst

Insider Threat Analyst responsible for triaging alerts, conducting investigations, and mitigating insider risks using SIEM, UBA, and DLP tools. Requires 3+ years in security operations or investigations with strong cross-functional collaboration skills.

135k – 159kUnited StatesSecurity EngineeringRemote3+ YOEUBADLP
Chainguard

Senior Security Engineer

Own AI platform posture end-to-end: administer Claude/ChatGPT enterprise controls, build MCP servers and agentic tooling, harden security against prompt injection and data leakage, and create spend dashboards. Requires 5+ years security/IT/DevOps experience plus hands-on AI platform administration.

130k – 160kUnited StatesSecurity EngineeringRemote5+ YOEGCPGit
Chainguard

Senior Security Engineer

Senior Security Engineer on the Cyber Resiliency team designing detection controls, engineering SOAR/AI playbooks, leading incident response, and conducting threat hunts to strengthen Chainguard's security posture.

130k – 150kUnited StatesSecurity EngineeringRemote5+ YOEGoSOAR
Metropolis

Senior Security Engineer, Infrastructure & Network Security

Lead AWS and network security infrastructure, zero-trust initiatives, and cloud automation for enterprise environments. Requires strong AWS, networking, IAM, and scripting experience.

160k – 215kLos Angeles, CASecurity EngineeringOn-site5+ YOEAWSVPN