Staff Software Engineer (Malware Detection)
Chainguard · United States - Remote
About this role
## Chainguard — Staff Software Engineer (Malware Detection) ### The role, in a nutshell Chainguard is building the most trusted source for open source software. Every artifact Chainguard distributes is evaluated by a scanner before it reaches a customer—helping determine whether a package, container, or AI agent skill is safe to use. This is a **backend and production-infrastructure role in a security domain**, not a security research role. Product Security develops what the scanner looks for; you build and run the machinery that makes those detections **fast, accurate, and dependable** across every artifact we distribute. ### What you’ll own **Detection Quality** - Build the measurement behind coverage and precision (pipelines, metrics, dashboards). - Engineer the feedback loop between Engineering and Product Security so detection changes can be evaluated and shipped in hours, not days. - Build systems for reviewing, escalating, and correcting detections quickly, including bulk correction at ecosystem scale. **Scanner Platform** - Own the architecture of Chainguard’s shared malware scanning platform (scan orchestration, verdict storage, and the APIs consuming products depend on). - Scale the scanner beyond Libraries to Containers, Agent Skills, and future artifact types. - Make tradeoffs between detection quality, performance, and extensibility concrete in throughput, latency, and cost. **Threat Detection** - Build and scale the analysis itself (deterministic static analysis alongside AI-assisted reasoning over artifact contents). - Partner with Product Security to take emerging-threat detections from research prototype to production. **Customer Experience** - Build the APIs and services behind how customers investigate, enforce, and appeal scanner findings. - Build the backend for policy management and enterprise-scale operations. **Production Ownership** - Operate the scanner as a system in the critical path of every customer install (alerting, queue health, verdict-before-serve guarantees, and incident response). ### What we’re looking for - Multiple years building and operating production backend/infrastructure systems, with clear staff-level ownership and technical leadership. - Strong Go experience (or deep backend systems experience with the ability to ramp quickly in Go). - Experience owning highly technical platforms or backend infrastructure supporting multiple products or internal customers. - Experience with high-throughput, event-driven pipelines where throughput, latency, and correctness all matter. - Strong understanding of software supply chain security, malware detection, vulnerability management, or adjacent security domains. - Demonstrated success making design/prioritization decisions in technically complex and ambiguous environments. - Comfort owning metrics like false-positive rate—instrumenting honestly and driving it down. - Experience deploying and operating services in production with strong judgment around reliability and observability. - Experience mentoring engineers and raising the bar on design and code review. - Excellent cross-functional collaboration skills. ### Nice to haves - Experience with malware detection, static analysis, SCA, or vulnerability scanning. - Familiarity with package ecosystems (npm, PyPI, Maven, Go modules, container registries). - Experience building reusable platform capabilities supporting multiple products. - Background in cloud infrastructure, software supply chain se
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.