SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Chainguard is building the secure foundation for software development and deployment, delivering hardened, secure, production-ready builds of open source software. The company serves Fortune 500 enterprises and global leaders including OpenAI, Snap, and Snowflake, and is backed by top-tier VCs including Sequoia, Kleiner Perkins, and Lightspeed.
As Senior Security Analyst for Governance & Trust, you will build Chainguard's public-sector security program to earn and maintain trust with government customers. This is a hands-on role for someone with real federal or defense experience who is technically deep and allergic to compliance theater.
Key responsibilities include:
- Design and operate continuous monitoring and continuous authorization capabilities portable across frameworks (FedRAMP 20x, IRAP, C5, CMMC 2.0)
- Translate federal requirements into practical controls, evidence pipelines, and risk-prioritized recommendations
- Partner with Engineering and Product Security to connect federal requirements to cloud-native systems
- Support pursuit of Facility Clearance (FCL) and associated internal governance
- Build scalable systems for control ownership, evidence collection, remediation tracking, and reporting using automation and policy-as-code
- Coordinate across Security, Federal Strategy, Go-to-Market, Product, Engineering, and Legal
- Provide risk-based, technically grounded recommendations on federal security questions
- Create documentation for technical and non-technical stakeholders
- Help scale governance and trust as Chainguard grows
You bring real technical depth in cloud-native architecture, SaaS product design, and software development practices. You have meaningful firsthand experience operating inside federal, defense, or intelligence environments in technical or operational capacity (engineering, SOC, ISSM/ISSO with decision authority). You have working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53 applied practically. You demonstrate sharp risk-based judgment, can build structure in ambiguity, and communicate clearly across audiences. You work collaboratively as a peer specialist.
About Chainguard
AI / Data / Infrastructure; Legal / Compliance / Risk — software supply-chain security and trusted container images.