← Back to Connect Jobs
CONNECT VERIFIED

Senior FedRamp Program Manager

Jobgether

US · remote · Full-time

Jobgether

Accountabilities:: Own day-to-day execution of the company-side FedRAMP program, managing milestones, dependencies, risks, deadlines, and internal follow-through. Translate FedRAMP requirements, findings, partner requests, and service-level commitments into actionable plans with defined owners, due dates, evidence expectations, and acceptance criteria. Maintain an authoritative view of program status and proactively identify risks that could affect assessments, remediation, continuous monitoring, or authorization deadlines. Assess overall program readiness and identify systemic gaps in controls, evidence, ownership, processes, and dependencies. Independently determine priorities and next actions, resolve routine program issues, and escalate material risks, disputed requirements, missed commitments, and matters requiring specialized intervention. Coordinate organizational and procedural controls, evidence collection, remediation activities, control narratives, and other company inputs required for partner-managed FedRAMP records. Review evidence for completeness, accuracy, relevance, currency, traceability, and consistency with applicable requirements before external submission. Act as the company-side quality gate for evidence and remediation responses, requiring corrections when submissions are incomplete or inadequate. Track findings from assessments, continuous monitoring, and authorized testing through assignment, remediation, evidence submission, and closure. Establish internal remediation deadlines based on external commitments, risk, dependencies, and program requirements. Serve as the primary operational interface with external FedRAMP infrastructure and compliance partners and coordinate actions arising from continuous-monitoring activities. Partner with Software Engineering and Cloud Engineering to communicate technical compliance requirements, remediation expectations, deadlines, and evidence needs without performing technical remediation directly. Coordinate with Security, IT, Support, Operations, Product, Legal, and leadership on organizational controls, process changes, contractual considerations, and FedRAMP obligations. Drive commitments across teams without direct reporting authority through clear requirements, accountability, follow-through, and escalation. Maintain visibility into FedRAMP scope, systems, workflows, integrations, control inheritance, and shared-responsibility boundaries. Coordinate reviews of product, infrastructure, operational, and process changes that may affect FedRAMP scope or control responsibilities. Continuously improve compliance processes, documentation, evidence practices, ownership models, and operating routines. Provide concise reporting to security and compliance leadership on program status, deadlines, findings, remediation progress, evidence quality, dependencies, and material risks. Escalate threatened deadlines, disputed requirements, repeated quality issues, unresolved ownership gaps, and external dependencies requiring management or executive intervention. Use approved AI-enabled tools and automation to improve program efficiency while independently validating outputs against authoritative requirements and program context. Requirements: 7+ years of relevant professional experience in security, compliance, technical program management, risk management, cloud security, or related disciplines, including at least 3 years of direct FedRAMP program execution or ownership experience. Demonstrated ownership of a substantial portion of a FedRAMP authorization lifecycle, including readiness or gap assessments, control implementation and evidence readiness, assessment support, POA&M remediation, authorization activities, and transition to continuous monitoring. Experience operating a FedRAMP program after authorization, including continuous monitoring, recurring evidence collection, remediation deadlines, scope considerations, significant changes, and assessment preparation. Strong working knowledge of NIST SP 800-53 and the FedRAMP Moderate baseline, including control interpretation, implementation statements, control inheritance, shared responsibility, assessment findings, and evidence requirements. Experience with cloud or compliance shared-responsibility models and the ability to identify control ownership, inherited responsibilities, evidence dependencies, and gaps between provider and customer obligations. Proven ability to translate regulatory requirements into clear expectations, owners, deadlines, evidence requirements, and acceptance criteria for technical and non-technical teams. Experience evaluating whether evidence and remediation responses adequately address control requirements or findings, with the judgment to reject inadequate submissions before external review. Demonstrated ability to drive remediation and compliance commitments across Software Engineering, Cloud or Platform Engineering, IT, Security, Support, Product, and other teams without direct management authority. Working technical knowledge of SaaS and cloud environments, including identity and access management, CI/CD, vulnerability management, logging and monitoring, system boundaries, encryption, change management, software dependencies, and cloud infrastructure. Ability to recognize when specialized technical validation is required and engage the appropriate subject-matter experts rather than serving as the hands-on implementer. Strong ability to independently establish program structure, resolve ambiguous ownership, set priorities and deadlines, and escalate matters requiring management, risk-owner, partner, or technical-specialist decisions. Experience leveraging AI-enabled tools, automation, or advanced systems to improve productivity, analysis, and program execution, with sound judgment in validating outputs. Excellent written and verbal communication skills, with the ability to communicate requirements, deficiencies, risks, program status, and decisions clearly to engineers, business stakeholders, external partners, assessors, and leadership. Must be a U.S. Person and reside in the United States. Preferred Qualifications: 5+ years of direct FedRAMP program execution experience and/or experience owning multiple authorization lifecycles. Experience independently leading company-side execution through a FedRAMP authorization lifecycle, from program structure and organizational readiness through assessment coordination and continuous monitoring. Experience operating in a fully self-managed FedRAMP environment, particularly within a SaaS or cloud software provider. Experience in a partner-managed FedRAMP implementation with responsibility for company-side execution, evidence quality, remediation tracking, control ownership, and shared-responsibility coordination. Experience working directly with FedRAMP assessors, 3PAOs, agency or authorization stakeholders, managed hosting providers, or other external authorization and compliance partners. Experience supporting FedRAMP scope, authorization-boundary, significant-change, change-management, or continuous-monitoring decisions in a SaaS or cloud environment. Benefits: Supportive work environment focused on employee experience and healthy work/life balance. Floating holidays. Quarterly no-questions-asked wellness day. Opportunities to participate in Employee Resource Groups and contribute to an inclusive workplace. Opportunity to work across security, compliance, engineering, product, legal, operations, and external compliance stakeholders. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

AWSSaaSExcelAIGitUI
FREE MATCHED JOB ALERTS

Get jobs like this without searching manually.

Tell Connect what you want once. We will use your preferences to surface matching opportunities and invite you into your free career workspace.