Staff Software Engineer (Malware Detection)

🏒 Chainguard · all 105 jobs
πŸ“ Canada
πŸ“… Posted Sep 18, 2026 Β· via Himalayas
🏷 Software Engineer, Backend Engineering, Platform Engineering, Malware Detection, Security Software Engineering, Staff Security Engineer +3 more
Apply on original site β†—

Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.

Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake.

Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.

The role, in a nutshell:

Chainguard is building the most trusted source for open source software. Every artifact Chainguard distributes is evaluated by our scanner before it reaches a customer. It determines whether a package, container, or AI agent skill is safe to use and sits between our customers and compromised software.

What began as a high-leverage internal system has become a core platform powering Chainguard Libraries, Containers, Agent Skills, and future products. We're hiring a Staff Software Engineer to lead the engineering of that platform.

You'll own its architecture, scale, and reliability. You'll partner closely with Product Security to turn threat research into detections that run accurately and fast on every artifact we distribute, and with Product to define how customers experience a verdict.

This is a backend and production-infrastructure role in a security domain, not a security research role. Product Security develops what the scanner looks for; you build and run the machinery that makes those detections fast, accurate, and dependable across every artifact we distribute. Deep detection-research experience is welcome, but it isn't what we're hiring for here.
What you'll own:
Detection Quality

- Build the measurement behind coverage and precision: the pipelines, metrics, and dashboards the product is steered by.

- Engineer the feedback loop between Engineering and Product Security so a detection change can be evaluated and shipped in hours, not days.

- Build the systems for reviewing, escalating, and correcting detections quickly, including bulk correction at ecosystem scale.

Scanner Platform

- Own the architecture of Chainguard 's shared malware scanning platform: scan orchestration, verdict storage, and the APIs every consuming product depends on.

- Scale the scanner beyond Libraries to Containers, Agent Skills, and future artifact types.

- Make the tradeoffs between detection quality, performance, and extensibility concrete in throughput, latency, and cost.

Threat Detection

- Build and scale the analysis itself: deterministic static analysis alongside AI-assisted reasoning over artifact contents.

- Partner with Product Security to take emerging-threat detections from research prototype to production, running on every new release across every ecosystem we cover.

Customer Experience

- Build the APIs and services behind how customers investigate, enforce, and appeal scanner findings.

- Build the backend for policy management and enterprise-scale operations.

Production Ownership
- Operate the scanner as a system in the critical path of every customer install: alerting, queue health, verdict-before-serve guarantees, and incident response.

What we're looking for:

- Multiple years building and operating production backend or infrastructure systems, with a clear track record of staff-level ownership and technical leadership.

- Strong Go experience, or deep backend systems experience with the ability to ramp quickly in Go.

- Experience owning highly technical platforms or backend infrastructure that supports multiple products or internal customers.

- Experience with high-throughput, event-driven pipelines where throughput, latency, and correctness all matter at once.

- Strong understanding of software supply chain security, malware detection, vulnerability management

Flights + hotels

This role requires you to be in Canada. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels β†’

← All remote jobs

Comparing Software Engineer pay and openings β€” the live median is $135k?All remote Software Engineer jobs β†’Software Engineer salary data β†’
Want more like this? Browse every live remote developer role.All remote developer jobs β†’
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you