via Remote Rocketship
$85K - 130K a year
Lead and manage compliance programs across federal and commercial contracts ensuring audit readiness and certification success.
Requires 6+ years program management with 3-5 years in compliance/security programs, hands-on FedRAMP experience, and knowledge of ISO 27001, SOC 2, HITRUST, and federal contracting regulations.
Job Description: • Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness. • Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle. • Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans. • Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market's requirements. • Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks. • Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans). • Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business. • Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed. • Track and report program status, risks, and KPIs to executive leadership and agency stakeholders. • Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups. • Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs. Requirements: • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered). • 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs. • Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) is required. • Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks). • Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53). • Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines. • Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders. • Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements. • Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC, or similar). • Must be a U.S. Citizen or U.S. Person residing in the U.S. (FedRAMP Moderate/High requirement). Benefits: • Health insurance • Flexible working hours • Professional development opportunities
This job posting was last updated on 7/29/2026