Senior Security Analyst (Governance and Trust)
Chainguard · United States - Remote
About this role
**Chainguard — Senior Security Analyst (Governance & Trust)** **Location:** US ONLY ## Role in a nutshell Build the public sector security program that helps Chainguard earn and maintain trust with government customers. You’ll turn federal and public-sector requirements into real, operating security capability—supporting CMMC compliance and building continuous monitoring / continuous authorization that can serve as the backbone for broader public-sector posture (e.g., FedRAMP 20x, Facility Clearance, IRAP, Germany’s C5). This is a strong fit if you have hands-on federal/defense exposure, are technically deep, and prefer reducing risk over compliance theater—treating NIST, RMF, and POA&M as starting points. ## What you’ll do - Design and operate a **continuous monitoring and continuous authorization** capability portable across frameworks (so it transfers cleanly across FedRAMP 20x, IRAP, C5, etc.). - Translate **CMMC 2.0, FedRAMP 20x, and other requirements** into practical controls, evidence pipelines, and decision-ready recommendations—prioritizing what reduces risk. - Partner with **Engineering and Product Security** to connect federal requirements to how Chainguard’s cloud-native systems and Athena work. - Support pursuit of a **Facility Clearance (FCL)**, including internal governance. - Build scalable systems for **control ownership, evidence collection, remediation tracking, exceptions, and reporting**, favoring automation and policy-as-code. - Coordinate across **Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal** to keep work moving and escalate interpretation questions appropriately. - Provide **risk-based, technically grounded recommendations**, including when a technically compliant answer doesn’t actually reduce risk. - Create documentation that helps technical and non-technical partners understand what’s required, why it matters, and what to do next. - Help make governance and trust a **scalable** capability as Chainguard grows. ## What you’ll bring - **Real technical depth** (comfortable engaging with cloud-native architecture, SaaS product design, and software development practices). - **Meaningful firsthand experience** operating in a federal/defense/intelligence environment in a technical or operational capacity (e.g., engineering, SOC, ISSM/ISSO with real decision authority). - Working knowledge of **CMMC Level 2** and at least one of **FedRAMP, RMF, or NIST 800-53**—applied practically. - **Sharp, risk-based judgment** to distinguish “satisfied on paper” from controls that truly reduce risk. - Ability to build structure in ambiguity and drive cross-functional work to completion. - Clear written and verbal communication across technical, non-technical, and customer-facing audiences. - Collaborative, low-ego style—joining as a peer specialist on an existing team. ## It would be great if you had - Exposure to **federal personnel** or **facility clearance (FCL)** processes. - Familiarity with **FedRAMP 20x** or other automated, continuous approaches. - Experience with **policy-as-code, GitOps, continuous control monitoring,** or automated evidence collection. - Exposure to non-US public-sector security regimes (e.g., **IRAP, Germany’s C5**). - Familiarity with software supply chain security concepts: **SBOMs, artifact signing, provenance, SLSA, secure CI/CD**. - Experience in a high-growth startup or security-first technology company. ## Compensation **Base Salary Range:** $110,000 — $130,0
Listing freshness
CronJobs last confirmed this listing 7h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.