CronJobs

security jobs

Senior Security Analyst (Governance and Trust)

Chainguard · United States - Remote

remotesenior$110,000–$110,000Posted Aug 25, 2026GoNIST 800-53FedRAMPRMFCMMC 2.0policy-as-codeGitOpsSBOM

Apply on the employer site

About this role

**Chainguard — Senior Security Analyst (Governance & Trust)** **Location:** US ONLY ## Role in a nutshell Build the public sector security program that helps Chainguard earn and maintain trust with government customers. You’ll turn federal and public-sector requirements into real, operating security capability—supporting CMMC compliance and building continuous monitoring / continuous authorization that can serve as the backbone for broader public-sector posture (e.g., FedRAMP 20x, Facility Clearance, IRAP, Germany’s C5). This is a strong fit if you have hands-on federal/defense exposure, are technically deep, and prefer reducing risk over compliance theater—treating NIST, RMF, and POA&M as starting points. ## What you’ll do - Design and operate a **continuous monitoring and continuous authorization** capability portable across frameworks (so it transfers cleanly across FedRAMP 20x, IRAP, C5, etc.). - Translate **CMMC 2.0, FedRAMP 20x, and other requirements** into practical controls, evidence pipelines, and decision-ready recommendations—prioritizing what reduces risk. - Partner with **Engineering and Product Security** to connect federal requirements to how Chainguard’s cloud-native systems and Athena work. - Support pursuit of a **Facility Clearance (FCL)**, including internal governance. - Build scalable systems for **control ownership, evidence collection, remediation tracking, exceptions, and reporting**, favoring automation and policy-as-code. - Coordinate across **Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal** to keep work moving and escalate interpretation questions appropriately. - Provide **risk-based, technically grounded recommendations**, including when a technically compliant answer doesn’t actually reduce risk. - Create documentation that helps technical and non-technical partners understand what’s required, why it matters, and what to do next. - Help make governance and trust a **scalable** capability as Chainguard grows. ## What you’ll bring - **Real technical depth** (comfortable engaging with cloud-native architecture, SaaS product design, and software development practices). - **Meaningful firsthand experience** operating in a federal/defense/intelligence environment in a technical or operational capacity (e.g., engineering, SOC, ISSM/ISSO with real decision authority). - Working knowledge of **CMMC Level 2** and at least one of **FedRAMP, RMF, or NIST 800-53**—applied practically. - **Sharp, risk-based judgment** to distinguish “satisfied on paper” from controls that truly reduce risk. - Ability to build structure in ambiguity and drive cross-functional work to completion. - Clear written and verbal communication across technical, non-technical, and customer-facing audiences. - Collaborative, low-ego style—joining as a peer specialist on an existing team. ## It would be great if you had - Exposure to **federal personnel** or **facility clearance (FCL)** processes. - Familiarity with **FedRAMP 20x** or other automated, continuous approaches. - Experience with **policy-as-code, GitOps, continuous control monitoring,** or automated evidence collection. - Exposure to non-US public-sector security regimes (e.g., **IRAP, Germany’s C5**). - Familiarity with software supply chain security concepts: **SBOMs, artifact signing, provenance, SLSA, secure CI/CD**. - Experience in a high-growth startup or security-first technology company. ## Compensation **Base Salary Range:** $110,000 — $130,0

Listing freshness

CronJobs last confirmed this listing 7h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord