Senior Security Program Manager
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• 5+ years of experience in information security or compliance, with a focus on government and public sector regulatory frameworks (e.g., FedRAMP, GovRAMP, FISMA, NIST RMF). • Knowledge of NIST SP 800-53 and experience mapping controls across frameworks. • Experience with cloud environments like AWS GovCloud or Azure Government, including implementation of compliant architectures. • Proven ability to manage large-scale compliance programs across diverse stakeholder groups. • Demonstrated success developing and maintaining regulatory documentation and audit evidence. • Experience leading engagements with internal teams, assessors, and government partners. • Strong written and verbal communication skills, including translating between technical and executive audiences. • Excellent organizational skills and the ability to manage multiple initiatives with competing priorities. • Self-starter with strong problem-solving abilities in ambiguous, fast-moving environments. • Nice-to-Haves • Nice-to-Haves • Relevant certifications: CISSP, CISA, CRISC, CCAK, CGRC (formerly CAP). • Experience with automation platforms for GRC and security monitoring (e.g., Wiz, Paramify). • Familiarity with other public sector compliance programs (CJIS, IRS 1075, DoD IL5, etc.). • Experience supporting product or infrastructure teams through ATO processes. • Experience with FedRAMP 20x initiatives. • Leadership experience or management of small security/GRC teams. • Benefits (for U.S.-based full-time employees) • 100% medical, dental & vision insurance coverage for you • Partially covered for your dependents • One Medical annual membership • 401k (including employer match on contributions made while employed by Ramp) • Fertility HRA (up to $10,000 per year) • Unlimited AI token usage • Centralized home-office equipment ordering for all employees • Health and Wellness stipend • In-office perks: lunch, snacks, drinks, and more • Budget for intra-office travel • Relocation support to NYC or SF (as needed) • Referral Instructions • If you are being referred for the role, please contact that person to apply on your behalf. • Other notices • Other notices • Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. • Ramp Applicant Privacy Notice
Responsibilities
• Lead all aspects of the compliance lifecycle across multiple public sector frameworks (e.g., FedRAMP, GovRAMP), including risk assessments, continuous monitoring, audits, and authorization management • Drive complex cross-functional program management efforts involving teams across security, legal, engineering, infrastructure, and product functions. • Serve as a subject matter expert on risk management and regulatory compliance for federal, state, and local government environments. • Develop and maintain comprehensive security documentation aligned with applicable frameworks, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and data flow diagrams. • Monitor compliance with control requirements (e.g., NIST 800-53, GovRAMP Baselines) and coordinate the implementation of technical and procedural safeguards. • Engage with third-party assessors (3PAOs or independent assessors), government sponsors, and internal teams to support assessments and audits. • Lead readiness assessments and support the prioritization of remediation activities across teams. • Manage timely tracking and closure of vulnerabilities and findings; ensure reporting and documentation obligations are met. • Provide risk-informed compliance recommendations that influence infrastructure and product development decisions. • Collaborate with legal and government affairs teams to ensure compliance with emerging federal and state regulatory requirements. • Stay informed on evolving threats, compliance trends, and guidance updates across FedRAMP, GovRAMP, NIST, and other frameworks.
Benefits
• $160,400 – $259,150 • The final compensation will depend on the location and level at which the candidate is hired. • Upload your resume here to autofill key application fields. • Drop your resume here! • Parsing your resume. Autofilling key fields... • or drag and drop here • Examples outside of work (e.g. from hobbies, sports, or games) are welcomed • Recruiting Privacy Policy