Lead Security Engineer
TimescaleFull Time
Senior (5 to 8 years)
The ideal candidate will have 5+ years of experience in software development or security, with a strong background in identifying, developing, and integrating threat intelligence into detection engineering and preventative controls. Experience securing cloud-native environments, endpoint detection & response, and familiarity with macOS or Linux security controls are essential. Knowledge of security frameworks like SOC 2, ISO 27001, and NIST is required. Experience with open source software or red-teaming is considered a plus. Strong communication skills and an independent work style are also necessary.
The Senior Information Security Analyst will engineer and deploy technical controls to minimize security incidents, lead incident response efforts including tabletop exercises, and integrate security best practices with product teams. This role involves conducting security assessments and penetration tests, automating detection and response workflows using Go, Python, or Shell, and staying ahead of emerging security threats. Rotational on-call responsibilities are also part of the role.
Supply chain risk management and audits
Chainguard specializes in managing risks in supply chains, particularly for businesses that rely on software. They conduct audits to identify risks and provide detailed reports with recommendations for improvement. Their unique offering includes a curated base container image distro, which helps businesses transition to secure software environments. Chainguard also provides supply chain observability services, allowing companies to track their software's origins and dependencies.