Principal Software Engineer (Libraries Platform) New United Kingdom - Remote

Principal Software Engineer (Libraries Platform) New United Kingdom - Remote

Full-Time 90498 - 110608 £ / year (est.) Working from home possible
Chainguard

At a Glance

  • Tasks: Lead the technical strategy for multi-ecosystem scaling and automation in software libraries.
  • Company: Join Chainguard, a leader in secure open-source software solutions.
  • Benefits: Enjoy remote work, flexible time off, and 100% covered health insurance.
  • Other info: Be part of a customer-obsessed team that values transparency and innovation.
  • Why this job: Shape the future of software libraries and make a real impact in tech.
  • Qualifications: 12+ years in infrastructure design and strong proficiency in Go required.

The predicted salary is between 90498 - 110608 £ per year.

Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.

Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake.

Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.

The role:

At Chainguard, we think the best platform work is invisible: the libraries just appear, the builds just work, and the CVEs quietly regret their life choices. Chainguard's Libraries organization runs the secure, reliable factory that continuously builds, verifies, and serves open-source libraries to customers and internal teams across multiple ecosystems. We're expanding that factory to new inbound ecosystems, while raising the bar on how much of the remediation and build lifecycle runs without a human in the loop.

As a Principal Software Engineer on the Libraries Platform team, you'll set technical direction for that expansion. This is a strategic, cross-organizational platform role: you're not just operating the existing factory, you're deciding how it generalizes to ecosystems it wasn't originally built for, and how much of the remediation pipeline - from CVE detection through patch, rebuild, verification, and release - can become fully automated rather than engineer-mediated. Your decisions will shape the platform's architecture for years and influence how every ecosystem team builds on top of it.

What you’ll do:

  • Own the technical strategy for multi-ecosystem scaling. Define the architecture that lets the Libraries Platform onboard new language ecosystems (.NET, Go, Rust) without re-deriving core services per ecosystem: generalizing package indexing, build orchestration, and metadata services so they're ecosystem-agnostic where possible and cleanly extensible where not.
  • Drive end-to-end remediation automation. Lead the redesign of CVE remediation workflows to close the loop from detection to verified, released fix with minimal manual intervention, rebuild triggering, SBOM and provenance regeneration, policy verification, and rollout, across all supported ecosystems.
  • Push the frontier on novel patch generation. Set the direction for agentic/AI-driven systems that synthesize security fixes when no upstream patch exists yet — not just selecting or backporting existing ones — and design the guardrails (automated validation, regression testing, provenance, and human checkpoints) that make machine-generated patches safe to ship across ecosystems.
  • Set platform-wide technical direction, spanning the package index, build/packaging pipelines, registry mirrors, and orchestration tooling that serve external customers and internal ecosystem teams at scale.
  • Make foundational build vs. buy and sequencing calls for bringing .NET, Go, and Rust online, identifying what's genuinely novel about each ecosystem's toolchain, packaging, and dependency model, and what can reuse or extend existing platform primitives.
  • Raise the technical bar across the org: mentor Staff and Senior Engineers, drive design reviews for the biggest architectural bets, and write the docs and RFCs that let other teams build correctly on the platform without you in the room.
  • Own reliability and scalability at the platform level: define SLOs for the expanded remediation pipeline, and lead incident response and postmortems for the platform's most consequential failures.
  • Get hands-on when it matters: dig into toolchain, compiler, and dependency-resolution problems specific to new ecosystems (e.g., NuGet, Go modules, Cargo) when they threaten the pipeline's reliability or timeline.

What we’re looking for:

  • 12+ years designing, building, and operating infrastructure for language ecosystems or developer platforms, (build systems, package registries, or CI/CD serving widely-used libraries or services) with demonstrated Principal-level scope: setting technical direction across multiple teams, not just owning a single system.
  • Direct experience standing up or significantly extending platform support for a language ecosystem- i.e. you've done the "onboard a new toolchain/packaging model into an existing platform" problem before, ideally including .NET (NuGet), Go (modules), or Rust (Cargo).
  • Strong proficiency in Go, with the judgment to know when a new ecosystem's idioms should bend the platform and when the platform should hold its ground.
  • A track record of automating away manual remediation steps. You can point to a workflow you took from "engineer does this by hand" to "system does this reliably", including the judgment calls about where automation is safe and where a human checkpoint still matters.
  • Deep background in CI/CD, agentic pipelines, cloud-native infrastructure, and IaC: containers (Docker/OCI, Kubernetes), Terraform, and pipeline tooling (GitHub Actions, Argo, Tekton, or equivalents) with experience running these at scale across heterogeneous ecosystems.
  • Demonstrated ability to diagnose and resolve deep toolchain, compiler, and packaging failures across multiple ecosystems, and to turn one-off fixes into systemic prevention.
  • Excellent written communication in a remote, distributed environment. Principal-level influence here happens mostly through docs, RFCs, and review, not just code.
  • A Principal ownership mindset: you set direction other engineers build against, you're comfortable being the person who has to make the ecosystem-generalization call with incomplete information, and you actively shape both the roadmap and engineering culture.

Nice to have:

  • Software supply chain security background: SLSA, SBOMs, sigstore, provenance, attestations, secure-by-default packaging.
  • Experience with Linux distributions, packaging, and reproducible build systems (Alpine, Wolfi, Debian, Bazel, CMake, Ninja).
  • Familiarity with AI/ML packaging and infra (PyTorch, TensorFlow) in cloud/Kubernetes environments.
  • Experience leading a platform through a step-change in automation maturity (e.g., an internal "remediation went from days to minutes" story).

About Us

We live and breathe our company values:

  • We are customer obsessed — We focus on delivering solutions to our customers that create value and make their lives better.
  • We have a bias for intentional action — We prioritize, plan, try things, and fail fast.
  • We don't take ourselves too seriously (but we do serious work) — We are solving an important problem which takes focus, but we also like to enjoy the journey.
  • We trust each other and assume good intentions — We're transparent with decisions to empower team members to make well informed decisions.

A few of the benefits we offer:

  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
  • Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Chainguard is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.

Principal Software Engineer (Libraries Platform) New United Kingdom - Remote employer: Chainguard

At Chainguard, we pride ourselves on being an exceptional employer, offering a dynamic work culture that prioritises employee well-being and growth. Our remote work flexibility allows you to balance your professional and personal life while enjoying comprehensive health coverage and opportunities for career advancement in the thriving tech landscape of Greater London. Join us to make a meaningful impact in customer success and be part of a team that values innovation and collaboration.

Chainguard

Contact Details:

Chainguard Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Software Engineer (Libraries Platform) New United Kingdom - Remote

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Chainguard or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Chainguard.

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Chainguard.

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Chainguard that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Principal Software Engineer (Libraries Platform) New United Kingdom - Remote

Technical Strategy Development
Architecture Design
CVE Remediation Automation
End-to-End Workflow Automation
Go Programming
CI/CD Expertise
Cloud-Native Infrastructure

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Chainguard.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Chainguard and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at Chainguard

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Chainguard uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.