Senior Security Analyst (Governance and Trust)
Chainguard
- Location
- United States - Remote
- Work model
- Remote
- Level
- Senior
- Salary
- $110k/yr
- H-1B history
- 1 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.
Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake.
Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.
Senior Security Analyst, Governance & Trust
Location: US ONLY
The role in a nutshell
Build the public sector security program that will help Chainguard earn and maintain trust with government customers.
Chainguard is building the secure foundation for software development and deployment. Our Governance & Trust team needs someone who can turn federal and public-sector requirements into real, operating security capability rather than a paperwork trail. You’ll support CMMC compliance efforts and build the continuous monitoring and continuous authorization capability that becomes the backbone for our broader public-sector posture, whether that ends up meaning FedRAMP 20x, a Facility Clearance, or international regimes like IRAP or Germany's C5 as Chainguard's public-sector footprint grows.
This role is a strong fit for someone with real, hands-on federal or defense exposure who is technically deep, allergic to compliance theater, and energized by building something that doesn't exist yet. We're not looking for someone who treats NIST, RMF, or a POA&M as the end of the conversation. We're looking for someone who treats them as a starting point for figuring out what actually reduces risk.
What you'll do
• Design and operate a continuous monitoring and continuous authorization capability built to be portable across frameworks, so it transfers cleanly if FedRAMP 20x, IRAP, C5, or other regimes come into scope, rather than being rebuilt from scratch each time.
• Translate CMMC 2.0, FedRAMP 20x, and other public-sector requirements into practical controls, evidence pipelines, and decision-ready recommendations, prioritized by what actually reduces risk over what merely satisfies an assessor.
• Partner with Engineering and Product Security to connect federal requirements to how Chainguard's cloud-native systems and Athena actually work.
• Support Chainguard's pursuit of a Facility Clearance (FCL), including the internal governance that comes with it.
• Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting, favoring automation and policy-as-code over manual processes.
• Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal to keep federal program work moving, escalating legal or regulatory interpretation questions rather than freelancing them.
• Provide risk-based, technically grounded recommendations on federal security questions and program tradeoffs, and be willing to say when a technically-compliant answer doesn't actually reduce risk.
• Create documentation that helps technical and non-technical partners understand what's required, why it matters, and what to do next.
• Help make governance and trust a scalable quantity as Chainguard grows.
What you'll bring
• Real technical depth: you can engage directly with cloud-native architecture, SaaS product design, and software development practices, not just describe controls at a policy level. You