Get more replies from employers
Send a job-specific resume in minutes.
Chainguard is seeking a Principal Software Engineer to lead the Libraries Platform, shaping architecture for multi-ecosystem scaling across .NET, Go, and Rust. You will drive automation of remediation workflows from CVE detection to verified, released fixes, while expanding the scope of the platform beyond current ecosystems.
You will define the approach to automated patch generation, implementing guardrails for validation, regression testing, provenance, and human checkpoints to ensure safe
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.Principal Software Engineer, (Libraries Platform)
At Chainguard, we think the best platform work is invisible: the libraries just appear, the builds just work, and the CVEs quietly regret their life choices.
Chainguard's Libraries organization runs the secure, reliable factory that continuously builds, verifies, and serves open-source libraries to customers and internal teams across multiple ecosystems. We're expanding that factory to new inbound ecosystems, while raising the bar on how much of the remediation and build lifecycle runs without a human in the loop.
As a Principal Software Engineer on the Libraries Platform team, you'll set technical direction for that expansion. This is a strategic, cross-organizational platform role: you're not just operating the existing factory, you're deciding how it generalizes to ecosystems it wasn't originally built for, and how much of the remediation pipeline - from CVE detection through patch, rebuild, verification, and release - can become fully automated rather than engineer-mediated. Your decisions will shape the platform's architecture for years and influence how every ecosystem team builds on top of it.