Lead Security Engineer
TimescaleFull Time
Senior (5 to 8 years)
Candidates should possess 5+ years of experience in software development, security, or a related field. They must have experience and passion for identifying, developing, and integrating threat intelligence into meaningful detection engineering and preventative controls. Experience securing cloud-native environments, endpoint detection & response, and familiarity with macOS or Linux security controls are required. Experience with security frameworks such as SOC 2, ISO 27001, and NIST is also necessary. A strong independent work style and excellent communication skills are essential. Experience with open source software or red-teaming is considered a plus.
The Senior Security Engineer will be responsible for designing and deploying innovative technical controls to minimize security incidents. They will lead incident response efforts, including conducting tabletop exercises. This role involves integrating security best practices with product teams and performing security assessments and penetration tests. Additionally, they will automate detection and response workflows using Go, Python, or Shell, and stay ahead of emerging security threats. Rotational on-call responsibilities are also part of the role.
Supply chain risk management and audits
Chainguard specializes in managing risks in supply chains, particularly for businesses that rely on software. They conduct audits to identify risks and provide detailed reports with recommendations for improvement. Their unique offering includes a curated base container image distro, which helps businesses transition to secure software environments. Chainguard also provides supply chain observability services, allowing companies to track their software's origins and dependencies.