Chainguard logo
Chainguard

Making the software supply chain secure by default.

Senior Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2021H1B SponsorCompany SiteLinkedIn

Location

United Kingdom

Posted

4 days ago

Salary

0

Seniority

Senior

Job Description

Senior Product Security Engineer

Chainguard

• Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production. • Systematically, consistently and automatically capture the risk exposure of Chainguards products. • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign). • Proactively identify emerging customer security needs, and build solutions to meet these. • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimise attack surface across our product stack. • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management. • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.

Job Requirements

  • 7+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility throughout.
  • Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code.
  • Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers).
  • Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub).
  • Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar).
  • Fluency with container security: image scanning, distroless/minimal base images, runtime security.
  • Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation).
  • Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.

Benefits

  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
  • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Related Categories

Related Job Pages

More Security Engineer Jobs

ZBeta, Inc. logo

Physical Security Project Manager

ZBeta, Inc.

Security that protects. Solutions that empower.

Full TimeRemoteTeam 51-200H1B No Sponsor

• Support security design and installation projects throughout North America • Manage all aspects of the project from initial engagement through project completion, including multiple projects and scopes of work • Identify project schedule, scope parameters, and oversee security design and implementation per client design requirements and standards • Manage early project initiation activities and develop project security scope, schedule, critical deliverables, and requirements • Manage scheduling, status, and tracking of critical project tasks, issues, and deliverables • Prepare, issue, and manage Request for Proposal (RFP) documents for security systems installation scope • Evaluate RFP responses and prepare evaluation reports, to include evaluation criteria, scoring, and recommendation details • Perform security site evaluations of potential client properties and review proposed design concepts • Collaborate with client owner and user group stakeholders to define use cases and verify functional requirements, and produce a security functional specification for the project

Colorado
$100K - $115K / year
Full TimeRemoteTeam 51-200H1B No Sponsor

• Conduct security control assessments for commercial and government customers to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within a system boundary. • Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). • Conduct kick-off meetings, develop associated schedules and resource plans to complete the assessments. • Responsible for quality control on the assessment and associated deliverables. • Develop practical and risk-based approaches for security control implementation and vulnerability remediation. • Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization. • Review cyber/system/network security body of evidence and documentation for accuracy and completeness. • Lead Post Assessment Meetings with the customer. • Provide Plan of Action and Milestones (POA&M) support to ensure mitigations are completed or the teams are working to mitigate all vulnerabilities in a timely fashion and within customer policy timelines. • Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system. • Perform other duties as assigned.

United States
$90K - $115K / year
Aqua Finance, Inc. logo

Information Security Manager

Aqua Finance, Inc.

Aqua provides flexible financing programs to dealers, contractors, and retailers so families can realize their dreams.

Full TimeRemoteTeam 201-500Since 1985H1B No Sponsor

• Lead and manage Security Analysts responsible for security operations center (SOC) activities and security administration • Oversee daily security monitoring, event triage, escalation handling, and incident response coordination • Establish team priorities, assign work, and ensure timely completion of operational security tasks and remediation activities • Develop and report on security operations metrics, trends, and performance indicators • Oversee administration of security tools, including monitoring platforms, endpoint protection, vulnerability management, and access controls • Manage user access administration, privileged access review support, and periodic access validation processes • Ensure security controls are functioning effectively and that issues are tracked, escalated, and remediated • Maintain team procedures, runbooks, and documentation for security operations and incident response • Support the implementation, tuning, and effectiveness of security tools and monitoring capabilities • Lead incident detection and response activities, including escalation to leadership when appropriate • Coordinate with IT and system owners on containment, remediation, recovery, and lessons learned • Monitor emerging threats and vulnerabilities and direct team focus accordingly • Support audit readiness, assessments, and operational response exercises • Manage, coach, and develop Security Analysts, including performance management and career development • Promote consistency in investigation, documentation, escalation, and communication practices • Partner with the CISO on staffing, workload planning, and operational maturity initiatives • Collaborate with Audit, Risk, Compliance, and IT teams on control validation and issue remediation • Support third-party reviews and audit follow-up activities • Escalate material risks, control gaps, and resource concerns to the CISO • Ensure alignment with organizational policies, standards, and regulatory requirements

Illinois + 2 moreAll locations: Illinois | North Carolina | Minnesota
Booz Allen Hamilton logo

Information Systems Security Engineer

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Title: Information Systems Security Engineer (ISSE) locations Fort Meade, MD time type Full time job requisition id R0241836 Job Description: Information Systems Security Engineer (ISSE) The Opportunity: Are you looking for an opportunity to apply your expertise in cybersecurity, risk management, and secure system design to strengthen national defense and protect mission-critical AI-enabled capabilities? As an Information Systems Security Engineer (ISSE), you will identify the security controls, assessment tools, and authorization strategies needed to ensure emerging technologies are securely integrated into operational, research, and enterprise environments. Your experience will help drive the development, testing, and deployment of secure systems that safeguard missions, protect sensitive data, and reinforce our nation’s security posture. On our team, you’ll guide and mentor professionals as they analyze complex cybersecurity challenges, conduct security assessments, and remediate vulnerabilities across varied systems and architectures. You’ll lead the creation and maintenance of RMF authorization packages, manage ATO processes, and oversee the development of key cybersecurity artifacts, from system security plans to POA&Ms. Leveraging your expertise with tools such as ACAS, SCAP, and eMASS, you’ll evaluate system risks, ensure compliance with STIGs and IAVM directives, and coordinate vulnerability remediation efforts across project teams. In this role, you’ll make a direct impact on critical mission areas by embedding cybersecurity best practices into AI development pipelines and integrating security throughout the system lifecycle. Your work will help ensure secure deployment of advanced capabilities that support national operations, enhance readiness, and defend vital infrastructure. With hands-on problem solving, opportunities to collaborate with DevOps, Cloud Architects, AI/ML Engineers, and continuous learning across evolving technologies, you’ll help shape resilient, innovative security solutions for our customers. Join us as we strengthen, secure, and protect mission-critical systems that support our nation today and into the future. You Have:   - Experience with the Risk Management Framework (RMF), including creation and maintenance of authorization packages, ATOs, and re-authorizations - Experience conducting security assessments, vulnerability remediation, and continuous monitoring in alignment with RMF - Experience with compliance scanning and VM tools, especially ACAS and SCAP - Experience implementing cybersecurity directives such as IAVM directives, CPUs, and STIGs - Experience updating and maintaining eMASS, including scan results, documentation, and evidence packages - Knowledge of system lifecycle management and procurement cybersecurity requirements - Ability to prepare and maintain cybersecurity documentation, including SSPs, SARs, and POA&Ms - Ability to analyze system architectures, hardware, and software designs to identify and mitigate security risks - TS/SCI clearance with a polygraph - HS diploma or GED Nice If You Have:   - Experience securing AI-enabled or ML-driven systems, given the mission context of supporting AI capabilities across operational, research, and enterprise environments - Experience with cloud and hybrid architectures, especially when securing AI workloads across varied computer environments - Experience with DevSecOps tooling, CI/CD security integration, and automated compliance workflows - Experience working with cross-functional AI/ML development teams, enabling secure model training, deployment pipelines, and monitoring frameworks - Experience in secure software development or secure architecture design reviews - Experience with cybersecurity automation scripting such as Python, PowerShell, or Ansible to support STIG automation, scanning pipelines, or IaC security controls - Knowledge of DoD-specific cybersecurity governance frameworks, mission workflows, and operational environments including USCYBERCOM or DoW environments - Bachelor’s degree Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance with polygraph is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Maryland
$99K - $225K / year