Skip to content
GovsignalsGovsignals

Compliance Operations Lead

Build and own the end-to-end security and compliance program for a government contracting AI platform, driving FedRAMP High ATO, automating evidence collection in CI/CD, and serving as the customer-facing trust lead. Requires 3+ years leading compliance programs with proven FedRAMP success and fluency in public-sector frameworks.

About the job

What You'll Do

  • Build and run the master compliance program covering FedRAMP High, IL5, CMMC Level 2, SOC 2, and adjacent public-sector frameworks; maintain a forward-looking roadmap anticipating new frameworks, customer requirements, and regulatory changes.
  • Drive the FedRAMP High ATO roadmap end-to-end, including 3PAO coordination, agency sponsorship navigation, and continuous monitoring once authorized.
  • Own evidence management end-to-end: implement automated policy checks, control evidence capture, and continuous monitoring tooling to remain audit-ready daily.
  • Lead quarterly and annual security documentation cycles, coordinate penetration tests and red-team engagements, and track remediation to closure.
  • Serve as the primary voice on enterprise security questionnaires and customer trust calls; join pitches and discovery calls, brief prospects on compliance roadmap, represent at industry and federal/defense forums, and build a customer-facing trust center and reusable response library.
  • Embed secure-by-design practices with engineering, including policy checks in CI/CD, infrastructure-as-code guardrails, and hardened deployment pipelines; monitor threat landscape and propose proactive hardening measures.

What You Bring

  • 3+ years leading compliance or security programs at a high-growth technology or defense startup, comfortable in fast-moving, early-stage environments.
  • Demonstrated success achieving and maintaining FedRAMP High ATO or equivalent high-impact authorization; experience building a compliance program from scratch.
  • Deep working fluency with IL5, CMMC Level 2, SOC 2 Type II, NIST 800-171, and the broader U.S. public-sector compliance landscape.
  • Proven ability to design and run automated evidence collection, policy management, and vulnerability-tracking workflows; experience coordinating red-team, penetration-test, or bug-bounty programs and translating findings into engineering action.
  • Ability to write policy and read code; translate effectively between auditors and senior engineers.
  • Strong written and verbal communication for technical and executive audiences; comfortable owning customer security reviews end-to-end.

Nice-to-Haves

  • Hands-on exposure to Kubernetes, Terraform, JAMF, and modern DevSecOps toolchains.
  • Prior experience supporting an IC or DoD customer base.
  • Background in government contracting, the military, or the intelligence community.

Compensation & Benefits

  • Base Salary: $140,000 – $190,000
  • Equity: Meaningful stake in a well-funded, fast-growing startup
  • Benefits: medical, vision, and dental; unlimited PTO
  • Brooklyn Navy Yard office (3+ days/week in person)

Skills

Fedramp High, Il5, Cmmc Level 2, SOC 2, Nist 800-171, Kubernetes, Terraform, Jamf, DevSecOps, CI/CD, Penetration Testing, Red Teaming

Similar jobs

Chime

Chime

Chicago, IL

Lead Analyst, Financial Crimes
$139k+/yrOn-site7+ YOEOther

Leads high-complexity financial crime investigations, vendor operations, risk trend analysis, typology development, and audit readiness. Requires 7+ years of regulated-environment experience, advanced SQL, transaction-monitoring expertise, and knowledge of AML and fraud typologies.

Coalition Security

Coalition Security

United States

Senior/Executive Underwriter
$150k+/yrRemote5+ YOEOther

Underwrites complex cyber and Technology E&O risks for large enterprise accounts, leads broker and client negotiations, and shapes portfolio strategy. Requires at least five years of underwriting experience, strong executive communication, and demonstrated mentorship of other underwriters.

Crusoe

Crusoe

San Francisco, CA

Manager, Sourcing
$130k+/yrOn-site7+ YOEOther

Leads corporate services procurement for IT, Finance, Legal, HR, and Travel categories. Manages full procurement lifecycle, negotiates contracts, analyzes spend for cost savings, and builds sourcing team. Requires 7+ years experience and bachelor's degree.

Akur8

Akur8

New York, NY

Senior Life Actuary
$170k+/yrRemote7+ YOEOther

Senior Life Actuary responsible for designing and maintaining Life, Annuity, and Health actuarial models, supporting client onboarding, demos, and technical guidance. Requires ASA/FSA-level qualification, 7+ years of relevant experience, actuarial platform expertise, and strong communication skills.

Mercury

Mercury

San Francisco, CA
Senior KYC Investigator - Ongoing Due Diligence
$96k+/yrRemote5+ YOEOther

The Senior KYC Investigator will strengthen ongoing due diligence controls, improve KYC workflows, support complex refresh cases, and partner across Compliance, Product, and Risk teams to increase efficiency and reduce customer friction. The role requires at least 3–5 years in KYC, AML, sanctions, or risk investigations.