Sr. Security Program Manager, Commercial & Federal Compliance

New
A
AnaplanBusiness Planning Software
Remote-Atlanta, United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs.
Required Skills
Project ManagementRisk Management

Requirements

  • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
  • 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs.
  • Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors).
  • Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles.
  • Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53).
  • Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines.
  • Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC).
  • Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements.
  • Excellent written and verbal communication skills.

Responsibilities

  • Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
  • Lead FedRAMP authorization and continuous monitoring efforts, coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle.
  • Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements and translate them into program plans.
  • Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications.
  • Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage.
  • Serve as the primary point of coordination for internal and external audits, ensuring evidence collection, stakeholder readiness, and timely remediation of findings.
  • Support the establishment and refinement of governance processes, policies, and standard operating procedures.
  • Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now