Senior Security Analyst – Governance, Trust

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $110k - $130k / year

⏰ Full Time

🟠 Senior

🔐 Security Analyst

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 20%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Chainguard

Chainguard

51 - 200 employees

Founded 2021

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Security • SaaS • Cybersecurity

Chainguard is a company that specializes in building secure container images to enhance software security and compliance. Their products include low-to-zero CVE container images, which are updated daily to maintain security and compliance standards such as FedRAMP, NIST 800-53, PCI-DSS, SOC2, and CIS benchmarks. Chainguard focuses on reducing vulnerabilities, automating compliance, and supporting development workflows without compromising on innovation and productivity. The company serves a wide range of industries, including highly regulated sectors, by providing hardened image solutions to mitigate software supply chain risks and enhance application security.

📋 Description

• Build the public sector security program to help Chainguard earn and maintain trust with government customers • Design and operate a portable continuous monitoring and continuous authorization capability • Translate CMMC 2.0, FedRAMP 20x, and other public-sector requirements into practical controls, evidence pipelines, and risk-based recommendations • Partner with Engineering and Product Security to connect federal requirements to Chainguard's cloud-native systems and Athena • Support Chainguard's pursuit of a Facility Clearance (FCL), including related internal governance • Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting • Favor automation and policy-as-code over manual processes • Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal • Provide technically grounded recommendations on federal security questions and program tradeoffs • Create documentation for technical and non-technical partners • Help make governance and trust scalable as Chainguard grows

🎯 Requirements

• Technical depth engaging directly with cloud-native architecture, SaaS product design, and software development practices • Meaningful firsthand experience operating inside a federal, defense, or intelligence environment in a technical or operational capacity • Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53 • Risk-based judgment distinguishing technically satisfied controls from controls that reduce risk • Ability to build structure in ambiguity and drive cross-functional work to completion • Clear written and verbal communication across technical, non-technical, and customer-facing audiences • Collaborative, low-ego working style • Exposure to federal personnel or facility clearance (FCL) processes • Familiarity with FedRAMP 20x or other automated, continuous approaches to federal compliance • Experience with policy-as-code, GitOps, continuous control monitoring, or automated evidence collection • Exposure to non-US public-sector security regimes such as IRAP or Germany's C5 • Familiarity with software supply chain security concepts including SBOMs, artifact signing, provenance, SLSA, or secure CI/CD • Experience in a high-growth startup or security-first technology company

🏖️ Benefits

• Work remotely with team meetup opportunities • Bi-annual destination summits • Monthly stipend for coworking spaces, phone and internet costs • Stock options upon hire and promotion • Participation in secondary offerings • 10 years to exercise stock options • 100% covered health, vision and dental insurance premiums for employee and dependents • Unlimited flexible time off • 18 weeks paid parental leave for birthing parents • 12 weeks paid parental leave for non-birthing parents • Flexible parental leave usage throughout the child's first year

Apply Now

Similar Jobs

🔥 51 minutes ago

BlueScope

10,000+ employees

🏭 Manufacturing

🏗️ Construction

Information Security Analyst securing BlueScope’s global building-solutions manufacturing systems, applications, and AI technologies. Managing controls, risk programs, continuity planning, and security awareness.

🔥 5 hours ago

Draper

1001 - 5000

🏥 Healthcare

🏭 Manufacturing

🧬 Biotechnology

Supply Chain Security Analyst assessing defense-industry suppliers and SCRM risks for Draper, a nonprofit R&D company. Developing compliance analyses, supplier validations, and mitigation strategies.

🔥 5 hours ago

Equity Resources, Inc

201 - 500

💸 Finance

🏠 Real Estate

👥 B2C

Senior IT Security Analyst leading Microsoft cybersecurity operations for mortgage lender Equity Resources. Protecting company and customer data through incident response, identity management, vulnerability remediation, and compliance.

🔥 12 hours ago

Windstream

10,000+ employees

📡 Telecommunications

👥 B2C

Information Security Analyst supporting IAM access provisioning, audits, and identity lifecycle management. Resolving access issues for corporate applications and systems across the United States.

🔥 23 hours ago

ChargePoint

1001 - 5000

💼 Consulting

📦 Logistics

🚘 Automotive

Senior security risk analyst strengthening GRC compliance for ChargePoint’s EV charging network. Automating IT controls and supporting SOX, FedRAMP, PCI, ISO 27001, SOC 2, and NIST compliance.