
Chainguard is building the secure foundation for software development and deployment. Our Governance & Trust team needs someone who can turn federal and public-sector requirements into real, operating security capability rather than a paperwork trail. Youβll support CMMC compliance efforts and build the continuous monitoring and continuous authorization capability that becomes the backbone for our broader public-sector posture, whether that ends up meaning FedRAMP 20x, a Facility Clearance, or international regimes like IRAP or Germany's C5 as Chainguard's public-sector footprint grows.
This role is a strong fit for someone with real, hands-on federal or defense exposure who is technically deep, allergic to compliance theater, and energized by building something that doesn't exist yet.
What You'll Do
- Design and operate a continuous monitoring and continuous authorization capability built to be portable across frameworks (FedRAMP 20x, IRAP, C5, etc.), rather than being rebuilt from scratch each time.
- Translate CMMC 2.0, FedRAMP 20x, and other public-sector requirements into practical controls, evidence pipelines, and decision-ready recommendations.
- Partner with Engineering and Product Security to connect federal requirements to how Chainguard's cloud-native systems and Athena actually work.
- Support Chainguard's pursuit of a Facility Clearance (FCL), including the internal governance that comes with it.
- Build scalable systems for control ownership, evidence collection, remediation tracking, exceptions, and reporting, favoring automation and policy-as-code over manual processes.
- Coordinate across Security, Federal strategy, Go-to-Market, Product, Engineering, and Legal to keep federal program work moving.
- Provide risk-based, technically grounded recommendations on federal security questions and program tradeoffs.
- Create documentation that helps technical and non-technical partners understand what's required, why it matters, and what to do next.
- Help make governance and trust a scalable quantity as Chainguard grows.
What You'll Bring
- Real technical depth: Ability to engage directly with cloud-native architecture, SaaS product design, and software development practices.
- Federal/Defense experience: Meaningful, firsthand experience operating inside a federal, defense, or intelligence environment in a technical or operational capacity (engineering, SOC, ISSM/ISSO) rather than purely compliance or audit-of-record roles.
- Framework knowledge: Working knowledge of CMMC Level 2 and at least one of FedRAMP, RMF, or NIST 800-53, applied practically.
- Sharp, risk-based judgment: Ability to tell the difference between a control that's technically satisfied and one that actually reduces risk.
- Driving in ambiguity: Demonstrated ability to build structure in ambiguity and drive cross-functional work to completion.
- Communication: Clear written and verbal communication across technical, non-technical, and customer-facing audiences.
- Collaborative style: Low-ego working style joining as a peer specialist on an existing team.
Nice to Have
- Exposure to federal personnel or facility clearance (FCL) processes.
- Familiarity with FedRAMP 20x or other automated, continuous approaches to federal compliance.
- Experience with policy-as-code, GitOps, continuous control monitoring, or automated evidence collection.
- Exposure to non-US public-sector security regimes (IRAP, Germany's C5, or similar).
- Familiarity with software supply chain security concepts: SBOMs, artifact signing, provenance, SLSA, or secure CI/CD.
- Experience in a high-growth startup or security-first technology company.
Benefits & Perks
- Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone, and internet.
- Equity: Receive stock options upon hire and promotion with a 10-year exercise window.
- 100% Covered Health Insurance: 100% coverage for health, vision, and dental insurance premiums for you and your dependents.
- Unlimited Flexible Time Off: Take the time you need to recharge.
- Paid Parental Leave: 18 weeks for birthing parents and 12 weeks for non-birthing parents.
Timezone overlap
UTC-8β-4
Benefits
Equity, Health, Dental, Vision, Unlimited PTO, Parental leave, Internet, Coworking
Open to
US
Sign in to track applications and earn points.