Chainguard
Senior Software Engineer (Sustaining)
Job Summary
The role involves owning the triage and automation of CVEs, working hands-on with container and Linux packaging technologies, and collaborating with global teams. Candidates should have 4+ years in DevOps or software development, with experience in Linux packaging, container images, Kubernetes, and Terraform. A strong programming ability, effective communication skills, and a focus on automation and security are essential. The position emphasizes building secure container images, automating vulnerability management, and contributing to open-source security efforts.
Required Skills
Benefits
Job Description
Ready to build the future instead of patching the past? Join the Chainguard Sustaining Team and shake up the world of open source with us!
Why Chainguard?
We're the Safe Source for Open Source™—your backstage pass to where security, speed, and innovation come together. Every day, our team takes on the challenge of delivering minimal, zero-CVE container images and software artifacts that are always fresh, always resilient, and genuinely fun to work on.
Picture this: your code becomes part of the backbone for global enterprises, powering the cloud-native era and freeing developers everywhere to swap “urgent patch needed” for “let’s deploy and chill.” Sound good? Keep reading.
The Mission: Make Containers Boringly Secure (And Gloriously Efficient!)
We don’t just patch vulnerabilities. We build software that makes them extinct. As a key player on our sustaining engineering team, you will:
- Own the queue: Triage, chase down, and smash CVE’s, then dial up automation so those issues don’t come back.
- Play in our tech sandbox: Get hands-on with melange, apko, Wolfi OS, and the Chainguard Images catalog—our open-source foundation that strips out bloat (and bugs) from containers.
- Code, create, and launch: Build new Linux packages (APKs) and container images, and watch your handiwork shine in real-world cloud applications.
- Collaborate and celebrate: Sync early and often with project managers and teammates around the world. Shout out wins. Beat blockers. Keep momentum high.
- Spread the knowledge: Mentor engineers globally, leave your mark on the community, and become someone’s “you should talk to them.”
- Level up quality: Bring your passion for testing and automation so we can ship with confidence—and maybe brag a little, too.
What Makes You Chainguardian Material?
- Veteran skills: 4+ years writing code in DevOps or software development—bonus points for serious Linux packaging experience (APK, DEB, RPM), debugging mastery, and the stamina to run solo when it counts.
- Containers are your jam: You don’t just build and debug images—you think in them.
- Kubernetes flair: Deploy with plain manifests, Helm, or Kustomize. You’re the one people call when everything “just stopped working.”
- Terraform whiz: You create modules like LEGO—reusable, logical, and awesome.
- Real programming chops: Fluent in at least one language (your Go, Python, C, or C++ memes always impress).
- Crystal-clear communicator: English is no barrier. You know when to ask, when to inform, and when to celebrate.
- Not another cloud admin: We’re all about DevOps tools for build and test, not wrangling infrastructure.
Bonus Moves That Wow Us
- You're a familiar face in the open-source crowd or a rising community leader.
- You have hands-on experience with vulnerability management and remediation.
- You geek out over distroless containers and supply chain security.
Dig Deeper Into Our World
Curious about the real work? Explore Chainguard Academy for hands-on tutorials, debug strategies, and deep dives into supply chain security—plus stories from dev teams who discovered they can spend less time patching and more time building.
Hungry for Impact? Let’s Chat!
If “secure by default” excites you (instead of putting you to sleep) and you want to swap daily patches for daily progress… we’re ready for you. Step up, apply, and help us build the software supply chain everyone else wishes they had.
Chainguard: Because your talent shouldn’t be wasted fighting yesterday’s bugs—let’s build a safer, shinier tomorrow.
About Us
Chainguard is the secure foundation for software development and deployment. By providing guarded open source software, built from source and updated continuously, Chainguard helps organizations eliminate threats in their software supply chains.
Founded by the industry's leading experts on open source software, security and cloud native development, Chainguard has built the largest library of open source software that is secure by default.
Chainguard’s mission is to be the safe source for open source.
We live and breathe our company values:
We are customer obsessed - We focus on delivering solutions to our customers that create value and make their lives better.
We have a bias for intentional action - We prioritize, plan, try things, and fail fast.
We don’t take ourselves too seriously (but we do serious work) - We are solving an important problem which takes focus, but we also like to enjoy the journey.
We trust each other and assume good intentions - We’re transparent with decisions to empower team members to make well informed decisions.
A few of the benefits we offer:
- Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a $400 monthly stipend for coworking spaces, phone and internet costs.
- Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
- 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
- ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
- 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.
- For a full list of our benefits and rewards, click here.
If your experience is close but doesn’t fulfill all requirements, please apply. We’re building the best team in technology and are focused on hiring “Chainguardians'' with unique backgrounds, perspectives, and experiences.
Chainguard is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.
By submitting your application, you acknowledge that Chainguard will process your personal data in accordance with Chainguard’s Privacy Policy.
©2025 Chainguard. All Rights Reserved.
Chainguard
Discover Chainguard's hardened, vulnerability-free container images designed to keep your infrastructure secure and efficient.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.