Назад
Company hidden
1 день назад

Senior Security Analyst (Governance and Trust)

110 000 - 130 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Analyst (Governance and Trust) (CMMC/FedRAMP): Building Chainguard’s public-sector security program, including continuous monitoring, authorization, practical controls, and evidence pipelines with an accent on federal and defense security requirements. Focus on translating CMMC and FedRAMP requirements into risk-reducing capabilities, automating governance through policy-as-code, and connecting compliance controls to cloud-native systems.

Location: United States only — remote

Base salary: $110,000–$130,000 USD per year

Company

hirify.global provides hardened, secure, production-ready builds of open source software for organizations and AI agents.

What you will do

  • Design and operate continuous monitoring and continuous authorization capabilities that can support multiple public-sector security frameworks.
  • Translate CMMC 2.0, FedRAMP 20x, and related requirements into practical controls, evidence pipelines, and risk-based recommendations.
  • Partner with Engineering and Product Security to connect federal requirements with cloud-native systems and Athena.
  • Support the pursuit of a Facility Clearance and establish the related internal governance.
  • Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting using automation and policy-as-code.
  • Coordinate with Security, Federal Strategy, Go-to-Market, Product, Engineering, and Legal teams while documenting requirements and decisions.

Requirements

  • Must be based in the United States.
  • Technical depth across cloud-native architecture, SaaS product design, and software development practices.
  • Hands-on experience in a federal, defense, or intelligence environment in a technical or operational capacity.
  • Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53.
  • Strong risk-based judgment, ability to work through ambiguity, and experience driving cross-functional initiatives.
  • Clear written and verbal communication across technical, non-technical, and customer-facing audiences.

Nice to have

  • Experience with federal personnel or facility clearance processes.
  • Familiarity with FedRAMP 20x, policy-as-code, GitOps, continuous control monitoring, or automated evidence collection.
  • Exposure to IRAP, Germany’s C5, or other non-US public-sector security regimes.
  • Knowledge of SBOMs, artifact signing, provenance, SLSA, or secure CI/CD.
  • Experience in a high-growth startup or security-first technology company.

Culture & Benefits

  • Remote-first culture with team meetups, twice-yearly destination summits, and a monthly coworking, phone, and internet stipend.
  • Stock options upon hire and promotion, participation in secondary offerings, and a 10-year exercise period.
  • Health, vision, and dental insurance premiums fully covered for employees and dependents.
  • Flexible time off.
  • Paid parental leave of up to 18 weeks for birthing parents and 12 weeks for non-birthing parents.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →