
51 - 200 employees
Founded 2021
🔐 Security
☁️ SaaS
🔒 Cybersecurity
Security • SaaS • Cybersecurity
Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.
🔥 0 minutes ago
🇺🇸 United States – Remote
💵 $110k - $130k / year
⏰ Full Time
🟠 Senior
🔐 Security Analyst
🦅 H1B Visa Sponsor
👻 Ghost score 20%
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
Founded 2021
🔐 Security
☁️ SaaS
🔒 Cybersecurity
Security • SaaS • Cybersecurity
Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.
• Build the public sector security program to help Chainguard earn and maintain trust with government customers • Design and operate a portable continuous monitoring and continuous authorization capability • Translate CMMC 2.0, FedRAMP 20x, and other public-sector requirements into practical controls, evidence pipelines, and risk-based recommendations • Partner with Engineering and Product Security to connect federal requirements to Chainguard's cloud-native systems and Athena • Support Chainguard's pursuit of a Facility Clearance (FCL), including related internal governance • Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting • Favor automation and policy-as-code over manual processes • Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal • Provide technically grounded recommendations on federal security questions and program tradeoffs • Create documentation for technical and non-technical partners • Help make governance and trust scalable as Chainguard grows
• Technical depth engaging directly with cloud-native architecture, SaaS product design, and software development practices • Meaningful firsthand experience operating inside a federal, defense, or intelligence environment in a technical or operational capacity • Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53 • Risk-based judgment distinguishing technically satisfied controls from controls that reduce risk • Ability to build structure in ambiguity and drive cross-functional work to completion • Clear written and verbal communication across technical, non-technical, and customer-facing audiences • Collaborative, low-ego working style • Exposure to federal personnel or facility clearance (FCL) processes • Familiarity with FedRAMP 20x or other automated, continuous approaches to federal compliance • Experience with policy-as-code, GitOps, continuous control monitoring, or automated evidence collection • Exposure to non-US public-sector security regimes such as IRAP or Germany's C5 • Familiarity with software supply chain security concepts including SBOMs, artifact signing, provenance, SLSA, or secure CI/CD • Experience in a high-growth startup or security-first technology company
• Work remotely with team meetup opportunities • Bi-annual destination summits • Monthly stipend for coworking spaces, phone and internet costs • Stock options upon hire and promotion • Participation in secondary offerings • 10 years to exercise stock options • 100% covered health, vision and dental insurance premiums for employee and dependents • Unlimited flexible time off • 18 weeks paid parental leave for birthing parents • 12 weeks paid parental leave for non-birthing parents • Flexible parental leave usage throughout the child's first year
Apply Now🔥 51 minutes ago
Information Security Analyst securing BlueScope’s global building-solutions manufacturing systems, applications, and AI technologies. Managing controls, risk programs, continuity planning, and security awareness.
🔥 5 hours ago
Supply Chain Security Analyst assessing defense-industry suppliers and SCRM risks for Draper, a nonprofit R&D company. Developing compliance analyses, supplier validations, and mitigation strategies.
🇺🇸 United States – Remote
💵 $82.3k - $220k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🔐 Security Analyst
🦅 H1B Visa Sponsor
🔥 5 hours ago
Senior IT Security Analyst leading Microsoft cybersecurity operations for mortgage lender Equity Resources. Protecting company and customer data through incident response, identity management, vulnerability remediation, and compliance.
🔥 12 hours ago
Information Security Analyst supporting IAM access provisioning, audits, and identity lifecycle management. Resolving access issues for corporate applications and systems across the United States.
🔥 23 hours ago
Senior security risk analyst strengthening GRC compliance for ChargePoint’s EV charging network. Automating IT controls and supporting SOX, FedRAMP, PCI, ISO 27001, SOC 2, and NIST compliance.
🇺🇸 United States – Remote
💰 $300M Post-IPO Debt on 2022-04
⏰ Full Time
🟠 Senior
🔐 Security Analyst
🦅 H1B Visa Sponsor