Own Kaizen’s federal security compliance program across FedRAMP, DoD Impact Levels, CMMC, contractual obligations, personnel security, and facility clearance readiness. The role requires hands-on federal portal experience, NIST assessment expertise, assessor engagement, and eligibility for a Tier 3 investigation.
130k – 175k/yr
HybridTechnical Program Management
About the role
Responsibilities
Build and run Kaizen's federal security compliance function in partnership with engineering, security, and executive leadership.
Own FedRAMP operations, including control implementation status, inherited-versus-owned controls, POA&M currency, continuous monitoring, Key Security Indicators, machine-readable packages, marketplace status, evidence flow to the independent assessor, and significant-change processes.
Manage DoD Impact Level reciprocity analysis, hosting-platform authorization coverage, and control-responsibility matrices.
Run the CMMC/NIST 800-171 self-assessment, maintain the corporate CUI system security plan, calculate and maintain the SPRS score, manage annual senior-official affirmations, and drive POA&M remediation.
Manage federal contract and agency paperwork, including DD Form 254, DD Form 2345, JCP registration, PIEE, SPRS, SAM.gov, agency security questionnaires, and DFARS flowdowns.
Track contractual SLAs, including incident notification, periodic reviews, and annual affirmations.
Maintain an obligation register covering FAR and DFARS flowdowns, employee notices, training, prohibited technology, EEO and labor reporting, OCI, and business ethics.
Review federal contracts and subcontracts before signature and identify compliance obligations.
Build and maintain control-to-evidence mappings.
Own personnel security operations, including US-person verification, background screening, onboarding and offboarding access controls, and quarterly access reviews.
Lead facility clearance readiness, including FSO vendor selection, key personnel clearance sequencing, SF 328 disclosures, and NISS submission.
Requirements
Direct experience submitting through federal portals, specifically SPRS and PIEE.
Experience completing a NIST 800-171 self-assessment or RMF package end to end.
Experience calculating and explaining a SPRS score, including the 110-control basis, weighting, and POA&M effects.
Hands-on experience with NIST 800-53 Rev. 5 in a real SSP.
Current knowledge of FedRAMP in 2026, including the 20x framework, Certification Classes, Key Security Indicators, machine-readable packages, and continuous validation.
Understanding of where NIST 800-53 Rev. 5 remains applicable, including the High baseline process and the June 2027 end of new Rev. 5 certifications.
Ability to reason about shared authorization boundaries, inherited and shared controls, application-specific controls, and significant-change requests.
Working knowledge of the DoD Cloud Computing SRG and Impact Levels on FedRAMP baselines.
Experience working with a 3PAO or independent assessor.
Ability to interpret FAR and DFARS flowdowns and maintain an obligation register.
Background in federal or defense contracting with ownership of a compliance function.
Experience as the sole compliance professional in an organization.
US person eligible for a Tier 3 background investigation.
Based in Washington, DC or New York City with regular in-office presence.
Nice-to-haves
FedRAMP authorization experience on the provider or assessor side.
Experience writing OSCAL or establishing a trust center using live control indicators.
Military background in security, intelligence, or information security.
Leads customer delivery engagements by coordinating technical resources, project plans, milestones, risks, and stakeholder alignment. Requires at least five years of project or technical program management experience in SaaS or technical services, with data-platform experience preferred.
130k – 140k/yrHybrid5+ YOETechnical Program Management
Project Manager, Implementations
PrelimNew York, NY +6
Lead multiple high-stakes bank software implementations as the primary coordinator between clients and cross-functional teams. Requires strong project management, technical aptitude, and ability to manage complex timelines and stakeholder relationships in a fintech environment.
130k – 140k/yrRemoteTechnical Program Management
Project Manager, Data Team
MercorSan Francisco, CA
Project Manager on Mercor's Data team responsible for end-to-end ownership of data initiatives from scoping through delivery. Requires 3-5+ years PM experience, strong leadership and stakeholder skills, and passion for data-driven projects in a cross-functional environment.
130k – 180k/yrOn-site3+ YOETechnical Program Management
Technical Quality Program Manager
NotionSan Francisco, CA +1
Technical Quality Program Manager responsible for improving bug reporting, feature request processes, incident management, and QA workflows at Notion. Collaborate with Product, Engineering, and CX teams to enhance product quality using data-driven insights and AI tools. Requires 3-5 years in support/ops/QA roles.
128k – 141k/yrHybrid3+ YOETechnical Program Management
Program Manager, Product
DatabricksBellevue, WA +3
Own execution of the Product Legal Program at Databricks, managing compliance workstreams, building Jira automations and AI tooling, and maintaining operational dashboards for legal reviews supporting engineering and product teams.
132k – 182k/yrOn-site5+ YOETechnical Program Management