Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
Anaplan

Anaplan

via Ladders

All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Sr. Security Program Manager, Commercial & Federal Compliance

Anywhere
Full-time
Posted 7/25/2026
Verified Source
Key Skills:
FedRAMP
ISO 27001
SOC 2
HITRUST
Program Management
Compliance Management
Risk Assessment

Compensation

Salary Range

$120K - 160K a year

Responsibilities

Lead and coordinate compliance initiatives across commercial and federal contracts ensuring audit readiness and certification compliance.

Requirements

6+ years program management with 3-5 years leading compliance/security programs, hands-on FedRAMP experience, knowledge of ISO 27001, SOC 2, HITRUST, federal contracting requirements, and strong communication skills.

Full Description

We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams - driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701, Cyber Essentials, TISAX). The ideal candidate is a skilled program leader who can translate complex, multi-jurisdictional regulatory requirements into actionable roadmaps, manage cross-functional execution, and communicate risk and progress clearly to senior leadership. Your Impact • Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness. • Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle. • Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans. • Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market's requirements. • Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks. • Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans). • Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business. • Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed. • Track and report program status, risks, and KPIs to executive leadership and agency stakeholders. • Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups. • Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs. Your Qualifications • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered). • 6+ years of program or project management experience, including at least 3-5 years directly leading compliance, security, or risk programs. • Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) is required. • Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks). • Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53). • Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines. • Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders. • Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements. • Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC, or similar). • Must be a U.S. Citizen or U.S. Person residing in the U.S. (FedRAMP Moderate/High requirement). Nice to Haves • PMP, PgMP, or equivalent program management certification. • ISO 27001 Lead Auditor or Lead Implementer certification. • HITRUST Certified CSF Practitioner (CCSFP). • CISSP, CISA, or CISM. • Experience supporting a FedRAMP JAB or Agency authorization from initiation through ATO, including familiarity with OSCAL and continuous monitoring deliverables. • Experience operating in multiple international markets and navigating varying regional compliance/certification requirements. #LI-Remote

This job posting was last updated on 7/28/2026

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt