Senior Security Analyst (Governance and Trust)

1 day, 9 hours ago
Full-time
Senior
Cybersecurity
Chainguard

Chainguard

Chainguard: Fortified Software Delivery Security for developers and CISOs, ensuring secure by default infrastructure and zero workflow friction.

Internet Software & Services
51-250
Founded 2021
$55M raised

Description

  • Design and operate portable continuous monitoring and continuous authorization capabilities across public-sector frameworks.
  • Translate CMMC 2.0, FedRAMP 20x, and related requirements into practical controls, evidence pipelines, and risk-based recommendations.
  • Partner with Engineering and Product Security to align federal requirements with Chainguard’s cloud-native systems and Athena.
  • Support the pursuit of a Facility Clearance, including related internal governance.
  • Build scalable systems for control ownership, evidence collection, remediation, exceptions, and reporting using automation and policy-as-code.
  • Coordinate federal program work across Security, Federal Strategy, Go-to-Market, Product, Engineering, and Legal.
  • Provide technically grounded, risk-based guidance on federal security questions and program tradeoffs.
  • Create documentation for technical, non-technical, and customer-facing stakeholders.
  • Help scale governance and trust processes as the company grows.

Requirements

  • Hands-on technical depth in cloud-native architecture, SaaS products, and software development practices.
  • Firsthand technical or operational experience in a federal, defense, or intelligence environment, such as engineering, SOC, ISSM, or ISSO work with decision authority.
  • Practical knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53.
  • Strong risk-based judgment and the ability to distinguish compliance from actual risk reduction.
  • Ability to create structure in ambiguous environments and drive cross-functional work to completion.
  • Clear written and verbal communication with technical, non-technical, and customer-facing audiences.
  • Collaborative, low-ego working style.
  • Exposure to federal personnel or facility clearance processes preferred.
  • Experience with FedRAMP 20x, policy-as-code, GitOps, continuous control monitoring, or automated evidence collection preferred.
  • Familiarity with IRAP, Germany’s C5, software supply chain security, or high-growth security technology companies preferred.

Benefits

  • Base salary of $110,000–$130,000 USD.
  • Flexible remote-first work with team meetups, biannual destination summits, and monthly coworking, phone, and internet stipends.
  • Stock options upon hire and promotion, secondary offering participation, and a 10-year exercise window.
  • 100% company-paid health, vision, and dental insurance for employees and dependents.
  • Flexible time off.
  • Paid parental leave: 18 weeks for birthing parents and 12 weeks for non-birthing parents.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Vulnerability Mgmt / Scan Operator

Pingwind 51-250 Internet Software & Services

PingWind is seeking a remote Vulnerability Management / Scan Operator to support vulnerability identification, remediation, and federal cybersecurity compliance for a mission-critical Department of Education Federal Student Aid IAM program.

Encryption TLS
1 day, 10 hours ago

Open Source Intelligence Specialist

Binance 5K-10K Capital Markets

Binance is hiring an investigations professional to research corporate entities and individuals, identify financial and compliance risks, and strengthen the blockchain company’s risk framework.

Blockchain Cybersecurity
1 day, 10 hours ago

RMF / CSAM Analyst

Pingwind 51-250 Internet Software & Services

PingWind is seeking a remote RMF/CSAM Analyst to maintain continuous security authorization and compliance for a cloud-based federal IAM solution supporting FSA identity services.

Cybersecurity TLS
2 days, 9 hours ago

Threat Researcher

GreyNoise 51-250 Internet Software & Services

GreyNoise Intelligence is hiring a Threat Researcher to investigate emerging cyber threats and produce actionable intelligence that helps security practitioners detect, disrupt, and impose costs on adversaries.

Embedded Systems SQL
4 days, 9 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers