Enable job alerts via email!

Senior GRC Analyst

Chainguard

United States

Remote

USD 120,000 - 135,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Chainguard is hiring a Senior GRC Analyst to lead and scale its governance, risk, and compliance function. This role offers a unique greenfield opportunity, allowing the successful candidate to shape compliance policies in a dynamic and secure environment. Strong experience with SOC 2 and ISO 27001 audits is essential, along with a proactive approach to risk management.

Benefits

Flexible & Remote-First Culture
100% Covered Health Insurance
∞ Flexible Time Off
18 Weeks Paid Parental Leave

Qualifications

  • Led multiple SOC 2 Type II audits and ISO 27001 efforts.
  • Managed competing priorities and kept projects on track.
  • Explained audit findings to both execs and engineers.

Responsibilities

  • Own the upcoming SOC 2 Type II and ISO 27001 audits.
  • Shape security policies, standards, and procedures.
  • Identify, assess, and mitigate compliance and security risks.

Skills

Risk assessments
Compliance management
Control design
Remote collaboration

Education

Experience with SOC 2 Type II and ISO 27001
Technical background or engineering experience

Tools

GRC platforms like Vanta

Job description

Join to apply for the Senior GRC Analyst role at Chainguard

Join to apply for the Senior GRC Analyst role at Chainguard

Get AI-powered advice on this job and more exclusive features.

The Role

You’ve led audits. You’ve wrangled evidence. You’ve lived through spreadsheets that nearly broke your soul. Now it’s time to take all that experience and build a GRC function that works smarter, scales cleanly, and earns real trust.

The Role

You’ve led audits. You’ve wrangled evidence. You’ve lived through spreadsheets that nearly broke your soul. Now it’s time to take all that experience and build a GRC function that works smarter, scales cleanly, and earns real trust.

Here’s the fun part: Chainguard has already done the hard work of building a solid, secure foundation and now we’re looking for someone to own and scale it.

As our first GRC-focused Security Engineer, you’ll take over a mature but growing compliance program, expand it, and shape the future of governance, risk, and compliance at a company that cares about getting this right. This is a build-it, own-it, make-it-better kind of gig.

You’ll be building something foundational for Chainguard and for how software supply chain security is defined industry-wide. And you’ll do it in a company that values intentional action, collective success, and the kind of thoughtful, opinionated approach that keeps us ahead of the curve and out of compliance purgatory.

What You’ll Do

  • Create immediate impact: You’ll immediately own the upcoming SOC 2 Type II and ISO 27001 audits.
  • Greenfield opportunity: You’re the first in this seat. You’ll have room to shape security policies, standards, and procedures while building the function and processes.
  • Cross-functional exposure: You’ll work daily with security engineers, legal, HR, and product teams.
  • Be the calm in the audit storm: Serve as the point of contact between auditors and Chainguardians, translating “audit-speak” into plain English.
  • Spot the risk:. Help identify, assess, and mitigate compliance and security risks before they become “surprise incidents.”
  • Level us up: Recommend ways to streamline our compliance engine ideally with the help of automation and modern GRC platforms.

What We're Looking For

  • You’ve run multiple SOC 2 Type II audits and ISO 27001 efforts. Bonus points if you’ve survived a FedRAMP audit and lived to tell the tale.
  • Experience with risk assessments, control design and testing, and remediation management.
  • Familiarity with GRC platforms like Vanta and risk assessment methodologies, and a solid sense for how to automate the boring parts.
  • You can manage competing priorities and keep projects on track.
  • You can explain audit findings to both execs and engineers without causing confusion (or panic).
  • Bonus points if you’ve got a technical background or engineering experience.

Why You’ll Love It Here

We’re not a place that patches problems. We rethink the system.

At Chainguard, You’ll

  • Challenge the status quo. We love people who stir the pot, rethink assumptions, and invent better ways forward.
  • Win together. We believe in collective success. No lone heroes here (but hey, bring your cape if you want).
  • Work with trust and humor. We take the mission seriously, but we laugh often because good work happens when people enjoy showing up.
  • Supportive, tight-knit team: Happy hours and activities (such as playing Oregon Trail) are part of the deal!

Base Salary Range

$120,000—$135,000 USD

About Us

Chainguard is the secure foundation for software development and deployment. By providing guarded open source software, built from source and updated continuously, Chainguard helps organizations eliminate threats in their software supply chains.

Founded by the industry's leading experts on open source software, security and cloud native development, Chainguard has built the largest library of open source software that is secure by default.

Chainguard’s mission is to be the safe source for open source.

We Live And Breathe Our Company Values

We are customer obsessed - We focus on delivering solutions to our customers that create value and make their lives better.

We have a bias for intentional action - We prioritize, plan, try things, and fail fast.

We don’t take ourselves too seriously (but we do serious work) - We are solving an important problem which takes focus, but we also like to enjoy the journey.

We trust each other and assume good intentions - We’re transparent with decisions to empower team members to make well informed decisions.

A Few Of The Benefits We Offer

  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a $400 monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
  • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.
  • For a full list of our benefits and rewards, click here.

If your experience is close but doesn’t fulfill all requirements, please apply. We’re building the best team in technology and are focused on hiring “Chainguardians'' with unique backgrounds, perspectives, and experiences.

Chainguard is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.

By submitting your application, you acknowledge that Chainguard will process your personal data in accordance with Chainguard’s Privacy Policy.

2025 Chainguard. All Rights Reserved.

Referrals increase your chances of interviewing at Chainguard by 2x

Get notified about new Senior Analyst jobs in United States.

United States $93,000.00-$150,000.00 1 week ago

Senior Sales Operations and Strategy Analyst

United States $90,000.00-$100,000.00 2 weeks ago

United States $85,850.00-$101,000.00 6 days ago

United States $129,000.00-$152,000.00 1 week ago

Senior Analyst I , Growth & Retention Insights
Senior Workforce Management Data Analyst

United States $136,400.00-$178,300.00 5 days ago

Chicago, IL $88,350.00-$123,700.00 1 week ago

Rhode Island, United States $86,300.00-$118,700.00 1 week ago

New Jersey, United States $86,300.00-$118,700.00 2 weeks ago

New York, United States $86,300.00-$118,700.00 2 weeks ago

Delaware, United States $86,300.00-$118,700.00 2 weeks ago

Georgia, United States $86,300.00-$118,700.00 1 week ago

Senior Analyst, Revenue Operations (Partner Ops Focus)

United States $90,000.00-$100,000.00 2 weeks ago

United States $69,000.00-$100,000.00 6 days ago

Pennsylvania, United States $86,300.00-$118,700.00 2 weeks ago

Sr Associate, Senior Business Analyst & Special Projects

United States $75,000.00-$95,000.00 5 days ago

North Carolina, United States $86,300.00-$118,700.00 2 weeks ago

Maryland, United States $86,300.00-$118,700.00 2 weeks ago

Florida, United States $86,300.00-$118,700.00 2 weeks ago

Indiana, United States $86,300.00-$118,700.00 2 weeks ago

Kentucky, United States $86,300.00-$118,700.00 2 weeks ago

New Hampshire, United States $86,300.00-$118,700.00 2 weeks ago

Ohio, United States $86,300.00-$118,700.00 2 weeks ago

South Carolina, United States $86,300.00-$118,700.00 2 weeks ago

Massachusetts, United States $86,300.00-$118,700.00 2 weeks ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior GRC Analyst

TherapyNotes, LLC

On-site

USD 95,000 - 135,000

3 days ago
Be an early applicant

Senior GRC Analyst

Freddie Mac

Remote

USD 95,000 - 135,000

4 days ago
Be an early applicant

Senior GRC Analyst

Skillable

Remote

USD 130,000 - 160,000

30+ days ago