
Senior Security Analyst – Governance, Trust
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
• Develop the public sector security program to enable Chainguard to gain and uphold trust with government clients.
• Create and manage a portable continuous monitoring and continuous authorization system.
• Convert CMMC 2.0, FedRAMP 20x, and other public sector mandates into actionable controls, evidence pipelines, and risk-informed recommendations.
• Collaborate with Engineering and Product Security to align federal requirements with Chainguard's cloud-native systems and Athena.
• Assist Chainguard in obtaining a Facility Clearance (FCL), including related internal governance processes.
• Develop scalable systems for control ownership, evidence gathering, remediation tracking, exceptions, and reporting.
• Prioritize automation and policy-as-code over manual workflows.
• Facilitate coordination among Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal teams.
• Offer technically sound recommendations on federal security issues and program trade-offs.
• Produce documentation for both technical and non-technical stakeholders.
• Contribute to creating scalable governance and trust mechanisms as Chainguard expands.
• Technical expertise in cloud-native architecture, SaaS product design, and software development methodologies.
• Significant hands-on experience working within a federal, defense, or intelligence environment in a technical or operational role.
• Proficient understanding of CMMC Level 2 and familiarity with at least one of FedRAMP, RMF, or NIST 800-53.
• Risk-based judgment ability to differentiate between technically compliant controls and those that effectively mitigate risk.
• Skill in creating structure amidst uncertainty and driving cross-functional initiatives to completion.
• Strong written and verbal communication skills for a range of audiences, including technical, non-technical, and client-facing.
• Team-oriented, low-ego approach to collaboration.
• Familiarity with federal personnel or facility clearance (FCL) procedures.
• Knowledge of FedRAMP 20x or similar automated, continuous compliance methods.
• Experience with policy-as-code, GitOps, continuous control monitoring, or automated evidence collection.
• Awareness of non-US public sector security frameworks like IRAP or Germany's C5.
• Understanding of software supply chain security concepts, including SBOMs, artifact signing, provenance, SLSA, or secure CI/CD practices.
• Background in a high-growth startup or security-focused technology firm.
• Opportunity to work remotely with occasional team meet-ups.
• Bi-annual destination summits.
• Monthly stipend for coworking spaces, phone, and internet expenses.
• Stock options provided upon hiring and promotions.
• Eligibility to participate in secondary offerings.
• 10 years to exercise stock options.
• Full coverage of health, vision, and dental insurance premiums for employees and their dependents.
• Unlimited flexible time off.
• 18 weeks of paid parental leave for birthing parents.
• 12 weeks of paid parental leave for non-birthing parents.
• Flexible usage of parental leave throughout the child's first year.
Harness
Veracity Insurance Solutions, LLC
Positivo S+
ShorePoint Inc
Get handpicked remote jobs straight to your inbox weekly.