Senior Security Analyst (Governance and Trust)

chainguard

United States

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Chainguard is building the secure foundation for software development and deployment. The Senior Security Analyst will design and operate a portable continuous monitoring and authorization framework across FedRAMP, CMMC, RMF, and other regimes, helping Chainguard win and sustain government trust.

You will translate requirements into practical controls and evidence pipelines, partner with Engineering and Product Security, pursue a Facility Clearance, and drive risk-based decisions while

Qualifications

  • Real technical depth in cloud-native architecture and security practice applied to federal environments.
  • Hands-on experience operating inside a federal, defense, or intelligence setting with real decision authority.
  • Ability to distinguish between technically satisfied controls and ones that genuinely reduce risk.

Responsibilities

  • Design and operate a portable continuous monitoring and authorization framework across FedRAMP 20x, IRAP, C5, or other regimes.
  • Translate federal requirements into practical controls, evidence pipelines, and risk-based recommendations.
  • Partner with Engineering and Product Security to align Chainguard's cloud-native systems with federal needs.
  • Support pursuit of a Facility Clearance (FCL) and related governance.
  • Build scalable systems for control ownership, evidence collection, remediation tracking, and reporting.
  • Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal.
  • Provide risk-based, technically grounded recommendations and speak up when a technically compliant answer does not reduce risk.
  • Create documentation to explain requirements, why they matter, and next steps.
  • Help scale governance and trust as Chainguard grows.

Skills

Technical depth
Federal/defense experience
Clear communication

Tools

CMMC 2.0 knowledge

Job description

Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.

Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake.

Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.

Senior Security Analyst, Governance & Trust

Location: US ONLY

The role in a nutshell

Build the public sector security program that will help Chainguard earn and maintain trust with government customers.

Chainguard is building the secure foundation for software development and deployment. Our Governance & Trust team needs someone who can turn federal and public-sector requirements into real, operating security capability rather than a paperwork trail. You'll support CMMC compliance efforts and build the continuous monitoring and continuous authorization capability that becomes the backbone for our broader public-sector posture, whether that ends up meaning FedRAMP 20x, a Facility Clearance, or international regimes like IRAP or Germany's C5 as Chainguard's public-sector footprint grows.

This role is a strong fit for someone with real, hands-on federal or defense exposure who is technically deep, allergic to compliance theater, and energized by building something that doesn't exist yet. We're not looking for someone who treats NIST, RMF, or a POA&M as the end of the conversation. We're looking for someone who treats them as a starting point for figuring out what actually reduces risk.

What you'll do

Design and operate a continuous monitoring and continuous authorization capability built to be portable across frameworks, so it transfers cleanly if FedRAMP 20x, IRAP, C5, or other regimes come into scope, rather than being rebuilt from scratch each time.

Translate CMMC 2.0, FedRAMP 20x, and other public-sector requirements into practical controls, evidence pipelines, and decision-ready recommendations, prioritized by what actually reduces risk over what merely satisfies an assessor.

Partner with Engineering and Product Security to connect federal requirements to how Chainguard's cloud-native systems and Athena actually work.

Support Chainguard's pursuit of a Facility Clearance (FCL), including the internal governance that comes with it.

Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting, favoring automation and policy-as-code over manual processes.

Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal to keep federal program work moving, escalating legal or regulatory interpretation questions rather than freelancing them.

Provide risk-based, technically grounded recommendations on federal security questions and program tradeoffs, and be willing to say when a technically-compliant answer doesn't actually reduce risk.

Create documentation that helps technical and non-technical partners understand what's required, why it matters, and what to do next.

Help make governance and trust a scalable quantity as Chainguard grows.

What you’ll bring

Real technical depth: you can engage directly with cloud-native architecture, SaaS product design, and software development practices, not just describe controls at a policy level. You don't need to be a software engineer, but you need to be able to hold your own with one.

Meaningful, firsthand experience operating inside a federal, defense, or intelligence environment in a technical or operational capacity (engineering, SOC, ISSM/ISSO with real decision authority) rather than a purely compliance or audit-of-record role. We want someone who picked up the culture and vocabulary because they had to operate inside it, not someone whose career has been the paperwork.

Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53, applied practically rather than academically.

Sharp, risk-based judgment: you can tell the difference between a control that's technically satisfied and one that actually reduces risk, and you say so even when it's the less convenient answer.

Demonstrated ability to build structure in ambiguity and drive cross-functional work to completion without waiting for a perfect template or a predecessor's playbook.

Clear written and verbal communication across technical, non-technical, and customer-facing audiences.

A collaborative, low-ego working style. You're joining as a peer specialist on an existing team, not building your own fiefdom, and you should find that appealing rather than limiting.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst (Governance and Trust) New United States - Remote
Senior Security Analyst (Governance and Trust) New United States - Remote

Chainguard • Northern (KY)

Remote
USD 110,000 - 130,000
Remote-friendly culture
Stock options
100% Covered Health Insurance
+2
Senior Technical Program Manager
Senior Technical Program Manager

Chainguard • Northern (KY)

Remote
USD 153,000 - 180,000
Remote-friendly culture
Stock options on hire and promotion
100% health insurance for you and your
+2
Senior Solutions Architect - PubSec (Professional Services) New United States - Remote
Senior Solutions Architect - PubSec (Professional Services) New United States - Remote

Chainguard • Northern (KY)

Remote
USD 165,000 - 210,000
Remote-first culture
Equity stock options
Health insurance
+2
Public Sector Security & Compliance Architect
Public Sector Security & Compliance Architect

chainguard • United States

On-site
USD 120,000 - 150,000
Senior Customer Success Manager, Enterprise - East United States - Remote
Senior Customer Success Manager, Enterprise - East United States - Remote

Chainguard • New York (NY)

Hybrid
USD 96,000 - 160,000
Remote-First Culture
Stock options
Health insurance
+1
Remote Senior Security Analyst, Governance & Trust
Remote Senior Security Analyst, Governance & Trust

Chainguard • Northern (KY)

Hybrid
USD 110,000 - 130,000
Remote-friendly culture
Stock options
100% Covered Health Insurance
+2
Customer Success Manager, Enterprise – East
Customer Success Manager, Enterprise – East

Chainguard • United States

On-site
USD 100,000 - 130,000
Flexible & Remote‑First Culture
Stock options and equity opportunities
100% Covered Health Insurance (family)
+2
Public Sector Account Executive - Civilian
Public Sector Account Executive - Civilian

Chainguard • Richmond (VA)

On-site
USD 320,000 - 380,000
Remote-first culture
Stock options
100% health insurance
+2
Public Sector Account Executive - Civilian New Virginia - Remote
Public Sector Account Executive - Civilian New Virginia - Remote

Chainguard • Virginia (IL), Northern (KY)

Remote
USD 300,000 - 400,000
Flexible & Remote-First Culture
Stock options
100% Covered Health Insurance
+2
Senior Software Engineer, Developer Platform
Senior Software Engineer, Developer Platform

Chainguard • United States

On-site
USD 157,000 - 184,000
Remote-friendly
Equity options (stock) with 10-year+%u
Health insurance (100% coverage)
+2