Senior Security Engineer (Cloud)
Chainguard
| Company | Chainguard |
| Category | Uncategorised |
| Location | United States - Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital. United States - Remote
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake.
The role in a nutshell:
We're looking for a Sr Security Engineer to engineer and secure our multi-cloud environment — the same cloud infrastructure that powers our product. This is a cloud-native, AI-obsessed company, and our cloud isn't just internal plumbing: it's the platform our product runs on, so how we design, harden, and evolve it directly shapes what we can build and how fast we can build it safely. As open source software increasingly feeds AI agents as well as human engineers, securing that supply chain end-to-end is core to our mission — and this role sits right at that intersection. You'll report to the Director of Cyber Resiliency and partner closely with our Developer Platform and IAM teams to make sure every cloud environment we operate — primarily GCP, with AWS and Azure in the mix — is resilient, well-architected, and built to accelerate secure innovation rather than slow it down. Let us know if bonfires are your jam! We're a late-stage startup, which means priorities, tooling, and scope can shift quickly — you'll need to be energized by that pace rather than worn down by it. Like every Chainguardian, you'll take the work seriously without taking yourself too seriously, and default to good intentions in how you work with others.
What you'll do:
Architect and maintain cloud environments built to be secure, resilient, and optimized for performance
Partner hands-on with the Developer Platform team to embed security into the architecture and tooling developers use every day
Work closely with our IAM counterparts to design and enforce identity and access strategies across all cloud environments
Harden cloud platforms against emerging threats while keeping them resilient and highly available
Bring a DevOps mindset — building automation, pipelines, and guardrails using Terraform/IaC and Kubernetes
Help secure the infrastructure behind AI-driven pipelines and agentic workflows as they become a growing consumer of the software supply chain
Act as a trusted advisor and collaborator across engineering, translating security requirements into practical, adoptable designs that other teams actually want to use — sharing context generously and putting shared outcomes ahead of individual credit
Help set the long-term architectural vision for how our cloud environments scale securely
Adapt architecture and priorities as the company scales — reworking plans as needs, tooling, or team structure shift
Assist during relevant incident response investigations
What we're looking for:
Strong, hands-on GCP administrative experience — this is a must-have, not a nice-to-have
Experience with AWS and/or Azure is a plus
Solid DevOps background — comfort with Terraform/IaC, Kubernetes (GKE), and CI/CD pipelines
Familiarity with software supply chain security concepts particularly SLSA is a s