Senior Security Analyst
Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.
About the job
Responsibilities
- Design and operate continuous monitoring and continuous authorization capabilities that can transfer across public-sector frameworks.
- Translate CMMC 2.0, FedRAMP 20x, and other requirements into practical controls, evidence pipelines, and risk-based recommendations.
- Partner with Engineering and Product Security to connect federal requirements to cloud-native systems and Athena.
- Support pursuit of a Facility Clearance (FCL) and related internal governance.
- Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting, emphasizing automation and policy-as-code.
- Coordinate Security, Federal Strategy, Go-to-Market, Product, Engineering, and Legal stakeholders.
- Provide technically grounded recommendations on federal security risks and program tradeoffs.
- Create documentation for technical, non-technical, and customer-facing audiences.
Requirements
- Technical depth in cloud-native architecture, SaaS product design, and software development practices.
- Hands-on technical or operational experience in federal, defense, or intelligence environments.
- Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53.
- Strong risk-based judgment and ability to distinguish compliance from actual risk reduction.
- Ability to build structure in ambiguity and drive cross-functional work to completion.
- Clear written and verbal communication.
- Collaborative, low-ego working style.
Nice-to-haves
- Exposure to federal personnel or facility clearance processes.
- Familiarity with FedRAMP 20x or automated continuous compliance approaches.
- Experience with policy-as-code, GitOps, continuous control monitoring, or automated evidence collection.
- Exposure to IRAP, Germany's C5, or similar non-US public-sector security regimes.
- Familiarity with SBOMs, artifact signing, provenance, SLSA, or secure CI/CD.
- Experience at a high-growth startup or security-first technology company.
Compensation & Benefits
- Base salary: $110,000–$130,000 USD.
- Remote-first culture with meetup opportunities, destination summits, and coworking, phone, and internet stipends.
- Stock options, participation in secondary offerings, and a 10-year exercise window.
- 100% covered health, vision, and dental insurance premiums for employees and dependents.
- Flexible time off.
- Paid parental leave: 18 weeks for birthing parents and 12 weeks for non-birthing parents.
Skills
Cmmc 2.0, FedRAMP, Nist 800-53, Rmf, Cloud-Native Architecture, SaaS, Policy-As-Code, GitOps, Continuous Monitoring, Automated Evidence Collection, Sboms, Slsa, Secure Ci/Cd, Artifact Signing, Provenance
Similar jobs
Security Engineering jobsThe Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.
Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.
The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.