Staff Software Engineer (Malware Detection)
Job Description
<div class="content-intro"><p>Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. <br><br>Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake. <br><br>Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.</p></div><p><span style="font-size: 10pt;"><strong>The role, in a nutshell:</strong></span></p> <p><span style="font-size: 10pt;">Chainguard is building the most trusted source for open source software. Every artifact Chainguard distributes is evaluated by our scanner before it reaches a customer. It determines whether a package, container, or AI agent skill is safe to use and sits between our customers and compromised software.</span></p> <p><span style="font-size: 10pt;">What began as a high-leverage internal system has become a core platform powering Chainguard Libraries, Containers, Agent Skills, and future products. We're hiring a Staff Software Engineer to lead the engineering of that platform.</span></p> <p><span style="font-size: 10pt;">You'll own its architecture, scale, and reliability. You'll partner closely with Product Security to turn threat research into detections that run accurately and fast on every artifact we distribute, and with Product to define how customers experience a verdict.</span></p> <p><span style="font-size: 10pt;"><strong>This is a backend and production-infrastructure role in a security domain, not a security research role.</strong> Product Security develops what the scanner looks for; you build and run the machinery that makes those detections fast, accurate, and dependable across every artifact we distribute. Deep detection-research experience is welcome, but it isn't what we're hiring for here.</span></p> <h2><span style="font-size: 10pt;"><strong>What you'll own:</strong></span></h2> <p><span style="font-size: 10pt;"><strong>Detection Quality</strong></span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Build the measurement behind coverage and precision: the pipelines, metrics, and dashboards the product is steered by.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Engineer the feedback loop between Engineering and Product Security so a detection change can be evaluated and shipped in hours, not days.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Build the systems for reviewing, escalating, and correcting detections quickly, including bulk correction at ecosystem scale.</span></li> </ul> <p><span style="font-size: 10pt;"><strong>Scanner Platform</strong></span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Own the architecture of Chainguard's shared malware scanning platform: scan orchestration, verdict storage, and the APIs every consuming product depends on.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Scale the scanner beyond Libraries to Containers, Agent Skills, and future artifact types.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Make the tradeoffs between detection quality, performance, and extensibility concrete in throughput, latency,