Source Job

US Unlimited PTO 18w maternity 12w paternity

  • Design and operate a continuous monitoring and authorization capability portable across frameworks.
  • Translate CMMC 2.0 and FedRAMP requirements into practical controls and evidence pipelines.
  • Partner with engineering and product security to connect federal requirements to cloud-native systems.

CMMC FedRAMP Cloud Security Risk Management

20 jobs similar to Senior Security Analyst (Governance and Trust)

Jobs ranked by similarity.

US

  • Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
  • Build and manage the control environment, including policies, procedures, and evidence collection systems.
  • Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.

US Unlimited PTO 16w maternity 10w paternity

  • Own compliance operations for FedRAMP, DoD Impact Levels, and CMMC programs.
  • Manage federal obligation registers, POA&Ms, and continuous monitoring.
  • Produce artifacts including NIST 800-171 self-assessments and certification packages.

Kaizen builds modern, AI-native software for government services to restore public trust. Founded in 2022 and based in NYC, the company has raised $35 million from top venture firms and reaches 55 million Americans across 50+ agencies.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

US

  • You will serve as a trusted technical advisor guiding federal customers through Wiz deployment, configuration, and operationalization using cloud-security best practices.
  • You will act as the primary technical liaison for complex architectural and operational challenges in federal cloud environments.
  • You will help customers develop success plans with measurable goals aligned to their organizational security, compliance, and mission objectives.

Wiz is a cloud security platform that redefines security for the AI era, enabling teams to secure cloud and AI applications. They are one of the fastest-growing startups, trusted by over 65% of the Fortune 100, scanning over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

US

  • Execute NIST SP 800-53 control mappings and implement security baselines.
  • Develop and maintain SSPs, POA&Ms, and authorization documentation.
  • Support continuous monitoring and gap assessments for ATO and FedRAMP.

This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.

Unlimited PTO

  • Lead end-to-end CMMC implementations for customers, owning the customer experience from kickoff through handoff and readiness milestones.
  • Translate customer requirements into clear implementation plans, including scope, timeline, milestones, owners, risks, dependencies, and success criteria.
  • Build repeatable implementation assets, including kickoff templates, project plans, RACI models, discovery questionnaires, evidence checklists, status reports, readiness criteria, risk registers, and handoff runbooks.

Secureframe is a cybersecurity compliance platform that helps companies achieve and maintain compliance standards. It is a fast-growing startup backed by top venture capital firms, fostering a culture of creativity and continuous learning.

$105,000–$123,000/yr
US Unlimited PTO 18w maternity 12w paternity

  • Operate and sustain Chainguard’s technology platforms (cloud, IAM, and AI) and help implement access controls and identity policies.
  • Support the hardening and monitoring of cloud infrastructure, assist in securing AI/ML pipelines, and troubleshoot systems.
  • Document processes, contribute to runbooks, and adapt to shifting priorities while learning security best practices.

Chainguard delivers hardened, secure, and production-ready builds of open source software. It is a venture-backed late-stage startup with Fortune 500 customers including Anduril, Canva, and OpenAI.

US

  • Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
  • Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
  • Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.

Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.

$93,000–$128,000/yr
US

  • Build, deploy, and maintain cloud-based IAM systems using DevSecOps practices and cloud-native architecture.
  • Ensure rapid and reliable delivery of code changes through CI/CD, automated testing, and deployment into production.
  • Lead evergreening activities, environment support, and compliance with federal requirements.

PingWind delivers services to the federal government in cybersecurity, development, IT infrastructure, and supply chain management. They are an SBA certified Service-Disabled Veteran-Owned Small Business with offices in Northern Virginia and Huntsville AL.

US

  • Maintain traceability from Federal Zero Trust guidance and VA objectives to assessment criteria, architecture patterns, and implementation priorities.
  • Support preparation and documentation for Architecture Review Boards, technical reviews, and executive governance forums.
  • Coordinate documentation needed to transition implementation outcomes into sustainable governance and RMF processes.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. It has been recognized as a Best Places to Work in 2023 and 2025, and made the Inc. 5000 list in 2022, 2023, and 2025, reflecting a people-first culture and sustained growth.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

$137,000–$160,000/yr
US Unlimited PTO 18w maternity 12w paternity

  • Architect and maintain secure, resilient, and optimized cloud environments primarily in GCP, with AWS and Azure.
  • Partner with Developer Platform and IAM teams to embed security into architecture and identity strategies.
  • Harden cloud platforms against emerging threats, bring a DevOps mindset with Terraform/IaC and Kubernetes, and help secure AI-driven pipelines.

Chainguard is the trusted source for open source software, delivering hardened and secure builds. They are a venture-backed late-stage startup serving Fortune 500 enterprises and global industry leaders.

US

  • Maintain traceability between federal Zero Trust guidance and organizational objectives.
  • Support governance forums and documentation for architecture decisions.
  • Coordinate with technical and program stakeholders to ensure alignment.

The company supports federal Zero Trust cybersecurity initiatives. It is a collaborative, people-focused environment emphasizing professional development and innovation.

US Unlimited PTO

  • Define cross-domain product strategy and multi-quarter roadmap for the U.S. public sector cloud portfolio, balancing parity, compliance, and scalability.
  • Shape the market point of view for regulated public sector, anticipating parity blockers and validating federal, DoD, and SLED nuances.
  • Lead multi-team and multi-VP programs, influencing engineering, security, legal, and go-to-market teams to align on strategy and unblock delivery.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter, faster, and better. They are building an AI-native culture where technology and talent are unstoppable together.

US

  • Build and maintain CI/CD pipelines and automated deployment workflows for federal environments.
  • Support software releases, deployment execution, cutovers, and post-release monitoring across IL5, IL6, and classified networks.
  • Automate infrastructure provisioning using Terraform, Ansible, and similar infrastructure-as-code tools.

Keeper Security is a leading cybersecurity software company that protects thousands of organizations and millions of people in more than 150 countries. Recognized in the Gartner Magic Quadrant for Privileged Access Management, it combines robust compliance with unmatched visibility and control.

US

  • Design and maintain enterprise security architecture for assigned ICAM applications and services.
  • Translate security requirements into implementable architecture and technical controls.
  • Integrate security controls into application, infrastructure, cloud, and DevSecOps environments.

Makpar is a comprehensive professional and technical solutions provider for the Federal government. They have a connected and engaged workforce dedicated to delivering success for clients and the American people.

US 4w maternity 4w paternity

  • You will lead the development and management of client Governance, Risk, and Compliance programs.
  • You will assess cybersecurity compliance against frameworks like CMMC, NIST SP 800-171, and DFARS.
  • You will provide advisory services and manage client expectations to ensure successful engagements.

This company provides cybersecurity compliance consulting services to organizations in the U.S. Defense Industrial Base. They foster a collaborative, security-first culture with a focus on advocacy and resilience.

$104,000–$166,000/yr
US

  • Serve as Tier 3 escalation point for complex incidents and outages in the AWS GovCloud environment.
  • Lead proactive identification and mitigation of infrastructure risks using monitoring tools like CloudWatch and Dynatrace.
  • Manage AWS GovCloud infrastructure across 70+ tenant environments ensuring FedRAMP compliance and optimization.

Peraton is a next-generation national security company that drives missions of consequence globally. As a leading mission capability integrator and IT provider, they deliver trusted solutions to protect the nation and allies, with a large workforce supporting government agencies.