
Senior FedRamp Program Manager
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Oversee the daily implementation of the company's responsibilities within a partner-managed FedRAMP environment.
• Convert FedRAMP, NIST SP 800-53, assessment, and partner requirements into actionable internal tasks.
• Manage milestones, dependencies, risks, deadlines, internal follow-ups, and shared-responsibility dependencies.
• Facilitate control implementation, gather evidence, provide remediation information, and prepare necessary program documentation.
• Assess evidence for completeness, accuracy, relevance, currency, traceability, and consistency.
• Serve as the quality gate for evidence and remediation responses on behalf of the company.
• Monitor findings from assignment through remediation, evidence submission, and closure.
• Act as the main operational liaison with the external FedRAMP infrastructure and compliance partner.
• Organize continuous monitoring meetings and manage subsequent actions, findings, requests, and decisions.
• Collaborate with Software Engineering and Cloud Engineering on technical compliance requirements without directly performing technical remediation.
• Work in conjunction with Security, IT, Support, Operations, Product, Legal, and leadership on FedRAMP obligations.
• Maintain a comprehensive understanding of FedRAMP scope, systems, workflows, integrations, control inheritance, and shared-responsibility boundaries.
• Coordinate the review of product, infrastructure, operational, and process changes impacting FedRAMP scope or controls.
• Persistently enhance FedRAMP processes, documentation, evidence practices, ownership models, and operational routines.
• Provide ready-to-present reports to the Director of Security and Compliance.
• Escalate significant risks, disputed requirements, unmet commitments, and issues necessitating management or specialized technical intervention.
• A minimum of 7 years of relevant professional experience in security, compliance, technical program management, risk management, cloud security, or related fields.
• At least 3 years of direct experience in FedRAMP program execution or ownership.
• Proven experience managing a significant portion of at least one FedRAMP authorization lifecycle.
• Experience in operating a FedRAMP program post-authorization, including continuous monitoring, recurring evidence collection, remediation deadlines, scope or significant-change considerations, and assessment preparation.
• Strong working knowledge of NIST SP 800-53 and the FedRAMP Moderate baseline.
• Familiarity with cloud or compliance shared-responsibility models.
• Capability to translate FedRAMP requirements into actionable expectations, designated owners, deadlines, evidence requirements, and acceptance criteria.
• Experience in evaluating evidence and remediation responses, with the authority to reject inadequate submissions.
• Ability to drive commitments across engineering, cloud/platform engineering, IT, security, support, product, and other teams without direct management authority.
• Working technical knowledge of SaaS and cloud environments, including identity and access management, CI/CD, vulnerability management, logging and monitoring, system boundaries, encryption, change management, software dependencies, and cloud infrastructure.
• Capability to engage subject-matter experts for specialized technical validation.
• Ability to independently establish program structure, priorities, deadlines, and escalation paths.
• Experience in leveraging AI-enabled tools and automation while validating outputs.
• Exceptional written and verbal communication skills.
• Must be a U.S. Person and reside in the United States.
• Floating holidays.
• Quarterly wellness day with no questions asked.
• Employee Resource Groups (ERGs).
• Healthy work/life balance.
• Accommodation provided during the recruiting process.
Circular Action Alliance
Circular Action Alliance
Hotwire Communications Ltd
Get handpicked remote jobs straight to your inbox weekly.