Back to Jobs
Legal & HR Just now

Senior Program Manager

United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Project ManagementBestseller 🔥
Learn in 8 Hours
ComplianceISO 27001Risk ManagementFedRAMP

Want to know if you're a match for this job?

Calculate My Match Score

We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams — driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701, Cyber Essentials, TISAX). The ideal candidate is a skilled program leader who can translate complex, multi-jurisdictional regulatory requirements into actionable roadmaps, manage cross-functional execution, and communicate risk and progress clearly to senior leadership.

Your Impact

  • Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
  • Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle.
  • Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans.
  • Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market's requirements.
  • Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks.
  • Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans).
  • Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business.
  • Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed.
  • Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
  • Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups.
  • Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs.

Your Qualifications

  • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
  • 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs.
  • Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) is required.
  • Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks).
  • Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53).
  • Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines.
  • Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders.
  • Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements.
  • Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC, or similar).
  • Must be a U.S. Citizen or U.S. Person residing in the U.S. (FedRAMP Moderate/High requirement).

Nice to Haves

  • PMP, PgMP, or equivalent program management certification.
  • ISO 27001 Lead Auditor or Lead Implementer certification.
  • HITRUST Certified CSF Practitioner (CCSFP).
  • CISSP, CISA, or CISM.
  • Experience supporting a FedRAMP JAB or Agency authorization from initiation through ATO, including familiarity with OSCAL and continuous monitoring deliverables.
  • Experience operating in multiple international markets and navigating varying regional compliance/certification requirements.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More