Senior Public Sector Compliance Manager
Accountabilities Develop and maintain a comprehensive compliance roadmap covering federal security requirements, authorization activities, and risk mitigation initiatives.
Support FedRAMP Moderate and High authorization and reauthorization processes, including the preparation, review, and maintenance of SSPs, POA&Ms, SAPs, SARs, and related documentation.
Serve as a subject matter expert on FedRAMP High, NIST SP 800-53, and associated federal compliance requirements.
Support strategic federal initiatives, including security and compliance requirements associated with DoD Impact Level 6 environments.
Map, assess, and monitor security controls against FedRAMP Moderate/High baselines and NIST SP 800-53 requirements.
Coordinate with engineering, operations, and DevSecOps teams to ensure security and compliance requirements are incorporated into system design and ongoing operations.
Manage continuous monitoring activities, including periodic assessments, penetration testing, vulnerability scanning, and associated documentation.
Track POA&M items through remediation and closure while monitoring outstanding risks and compliance gaps.
Coordinate with Third Party Assessment Organizations (3PAOs), government customers, and internal stakeholders during audits, assessments, and authorization activities.
Support federal sales and business development teams by providing guidance on regulatory requirements, security frameworks, and compliance considerations.
Administer and maintain the FedRAMP compliance platform and manage recurring monthly, quarterly, and annual authorization requirements.
Produce compliance metrics, reporting, and risk analysis for leadership and maintain awareness of changes to FedRAMP, NIST, FISMA, CMMC, and related frameworks.
Requirements
2–3 years of experience in information security compliance, governance, risk management, or a related field, preferably within a FedRAMP- or FISMA-regulated environment.
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related discipline, or equivalent professional experience.
U.S. citizenship and eligibility to obtain a security clearance are required for work involving applicable government cloud environments.
Strong working knowledge of NIST SP 800-53, FedRAMP Moderate/High baselines, and the federal authorization process.
Hands-on experience creating, maintaining, or reviewing security documentation such as SSPs, POA&Ms, SARs, and SAPs.
Familiarity with governance, risk, and compliance tools, as well as vulnerability scanning technologies such as Nessus or Qualys and the ability to interpret security findings.
Experience implementing or assessing security controls in cloud environments such as AWS, Azure, or Google Cloud is highly valuable.
Experience working with a 3PAO or federal agency is preferred.
Relevant certifications such as CISSP, CISA, CAP, CompTIA Security+, or equivalent credentials are advantageous.
Strong analytical and problem-solving abilities, with a structured approach to identifying risks, resolving compliance gaps, and managing multiple priorities.
Excellent written and verbal communication skills, including the ability to translate technical compliance requirements for non-technical stakeholders.
Ability to work independently while collaborating effectively across security, engineering, operations, sales, and other functions in a fast-paced environment.
Benefits
Remote position within the United States.
Opportunity to contribute to federal security and compliance programs involving FedRAMP and other high-assurance environments.
Cross-functional exposure to cybersecurity, cloud infrastructure, engineering, DevSecOps, sales, and public sector initiatives.
Opportunity to work on compliance programs aligned with evolving federal security requirements.
Employment benefits and compensation are subject to the applicable terms and programs offered by the hiring organization.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1