Senior Security Analyst (Governance and Trust)

Chainguard
$110,000 - $130,000Remote

About The Position

Chainguard is seeking a Senior Security Analyst for its Governance and Trust team to build the public sector security program. This role will focus on translating federal and public-sector requirements into operational security capabilities, supporting CMMC compliance, and developing continuous monitoring and authorization processes. The ideal candidate will have hands-on federal or defense experience, a technical understanding of cloud-native systems, and a focus on risk reduction over mere compliance. The position involves designing and operating a portable continuous monitoring and authorization capability, translating requirements like CMMC 2.0 and FedRAMP 20x into practical controls, and partnering with Engineering and Product Security to align federal requirements with Chainguard's systems. The role will also support the pursuit of a Facility Clearance (FCL), build scalable systems for control management and evidence collection, and coordinate across various departments to advance federal program initiatives. The analyst will provide risk-based recommendations, create clear documentation, and contribute to making governance and trust a scalable function within Chainguard.

Requirements

  • Real technical depth: ability to engage directly with cloud-native architecture, SaaS product design, and software development practices.
  • Meaningful, firsthand experience operating inside a federal, defense, or intelligence environment in a technical or operational capacity (engineering, SOC, ISSM/ISSO with real decision authority).
  • Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53, applied practically.
  • Sharp, risk-based judgment: ability to differentiate between a control that's technically satisfied and one that actually reduces risk.
  • Demonstrated ability to build structure in ambiguity and drive cross-functional work to completion.
  • Clear written and verbal communication across technical, non-technical, and customer-facing audiences.
  • A collaborative, low-ego working style.

Nice To Haves

  • Exposure to federal personnel or facility clearance (FCL) processes.
  • Familiarity with FedRAMP 20x or other automated, continuous approaches to federal compliance.
  • Experience with policy-as-code, GitOps, continuous control monitoring, or automated evidence collection.
  • Exposure to non-US public-sector security regimes (IRAP, Germany's C5, or similar).
  • Familiarity with software supply chain security concepts: SBOMs, artifact signing, provenance, SLSA, or secure CI/CD.
  • Experience in a high-growth startup or security-first technology company.

Responsibilities

  • Design and operate a continuous monitoring and continuous authorization capability built to be portable across frameworks.
  • Translate CMMC 2.0, FedRAMP 20x, and other public-sector requirements into practical controls, evidence pipelines, and decision-ready recommendations.
  • Partner with Engineering and Product Security to connect federal requirements to how Chainguard's cloud-native systems and Athena actually work.
  • Support Chainguard's pursuit of a Facility Clearance (FCL), including the internal governance that comes with it.
  • Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting, favoring automation and policy-as-code over manual processes.
  • Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal to keep federal program work moving.
  • Provide risk-based, technically grounded recommendations on federal security questions and program tradeoffs.
  • Create documentation that helps technical and non-technical partners understand what's required, why it matters, and what to do next.
  • Help make governance and trust a scalable quantity as Chainguard grows.

Benefits

  • Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Receive stock options upon hire and promotion.
  • Participation in secondary offerings.
  • 10 years to exercise stock options.
  • 100% of health, vision and dental insurance premiums covered for employee and dependents.
  • Flexible Time Off.
  • 18 weeks paid parental leave for birthing parents.
  • 12 weeks paid parental leave for non-birthing parents.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service