Senior Product Security Engineer
Core
Design, build, and maintain secure CI/CD pipelines and harden cloud-native container workloads for open source software builds.
Role type
Senior Product Security Engineer (Cloud-Native & Supply Chain)
Builds
Hardened container images, secure CI/CD pipelines, and cloud-native product stacks for Fortune 500 enterprises.
Domain
Cloud Security / Software Supply Chain Security
Deliverable
production ML models | product features | infrastructure
Required skills
Go or Python, Kubernetes production hardening, GCP/AWS security services, CI/CD pipeline security, container security, software supply chain security frameworks (SLSA, Sigstore, SBOM), cloud security frameworks (OWASP, NIST)
Preferred skills
Chainguard Images ecosystem, policy-as-code (OPA, Kyverno), open source security contributions, offensive security background
Technologies
Kubernetes, GCP, AWS, GitHub Actions, Cloud Build, Tekton, Sigstore, SLSA, SBOM, OPA, Kyverno, Conftest
Responsibilities
Design and maintain secure CI/CD pipelines with automated security gates; implement software supply chain security controls (signed artifacts, provenance attestation); lead security architecture reviews and threat models for Kubernetes workloads; harden container images and cloud IAM postures; evaluate and operationalize CNAPP/CSPM tooling.
Seniority
Senior, hands-on IC