Chainguard

Staff Vulnerability Management Engineer

Chainguard · Canada - Remote

Posted about a month ago

or apply directly on Chainguard's site. We never take the application ourselves.

Is this posting real?

This role has been open
33 days
Chainguard's roles stay open a median of 40 days
Reposted
No
Salary listed
No
5% of Chainguard's roles list one
Ghost-job risk at Chainguard
high
35 stale, 1 reposted of 83 open
Hiring momentum
137 roles opened in the last 90 days
↑ up vs. the prior 90 days
Last confirmed on the employer's board
2026-09-17

Measured from postings appearing on and disappearing from Chainguard's own greenhouse board since 2026-08-03. Full hiring picture for Chainguard.

About this role

As a Staff Vulnerability Management Engineer at Chainguard, you will manage a pipeline of novel vulnerabilities, ensuring their measurement, disclosure, and reporting. You will coordinate with various stakeholders, including public sector bodies and industry standards organizations, to guide the direction of vulnerability management and represent Chainguard's efforts in the industry.

Our read on this posting2.8out of 5
benefits
3/5
freshness
3/5
career value
4/5
role clarity
4/5
pay transparency
0/5

Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Chainguard as an employer.

What you need

  • 7+ years in software security, open source maintenance, or vulnerability disclosure management
  • A strong understanding of responsible disclosure
  • Practical expertise with automating pipelines and processes
  • Deep experience with open source communities
  • Experience in coordinating with public sector or industry standards bodies and working groups

Nice to have

  • Established thought leadership in the industry relating to vulnerability disclosure management and embargoes
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems
  • Experience operating a CNA
  • Software engineering background in Python, Java, Javascript, Go, or similar languages
  • Background in security research, pen testing or bug bounties

What you get

  • Flexible & Remote-First Culture
  • Our Approach to Equity
  • 100% Covered Health Insurance
  • ∞ Flexible Time Off
  • 18 Weeks Paid Parental Leave

Worth weighing

  • No salary listed
  • The role involves significant coordination with external bodies, which may require strong interpersonal skills
  • The requirement to use specific phrases in applications and interviews may be unusual for some candidates

Summarised from Chainguard's posting. Read the full original.

Listed by Chainguard on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.

More roles at Chainguard

All 83 open roles at Chainguard

Apply to a Staff Vulnerability Management Engineer position at Chainguard - Jobs near me at Canada - Remote