Назад
Company hidden
6 дней назад

Senior FedRAMP Program Manager (AI)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior FedRAMP Program Manager (AI): Owns day-to-day FedRAMP program execution for a partner-managed environment, coordinating controls, evidence, remediation, deadlines, and shared-responsibility dependencies with an accent on authorization readiness, continuous monitoring, and compliance governance. Focus on evaluating evidence quality, driving remediation across technical and business teams, managing external partner coordination, and using AI-enabled tools while validating outputs against authoritative requirements.

Location: Remote within the United States; must be a U.S. Person and reside in the United States.

Company

hirify.global provides SaaS software and operates a FedRAMP compliance program in a partner-managed environment.

What you will do

  • Own day-to-day execution of the company-side FedRAMP program, including milestones, dependencies, risks, deadlines, and internal follow-through.
  • Translate FedRAMP, NIST SP 800-53, partner requests, and findings into actions with owners, deadlines, evidence expectations, and acceptance criteria.
  • Coordinate control implementation, evidence collection and quality review, remediation tracking, continuous monitoring, and authorization-related documentation.
  • Act as the operational interface with external FedRAMP infrastructure and compliance partners, assessors, and other stakeholders.
  • Drive commitments across Software Engineering, Cloud Engineering, IT, Security, Support, Operations, Product, Legal, and leadership without direct management authority.
  • Report program status, risks, blockers, evidence quality, remediation progress, and decisions to the Director of Security and Compliance.

Requirements

  • 7+ years of relevant experience in security, compliance, technical program management, risk management, cloud security, or related disciplines.
  • At least 3 years of direct FedRAMP program execution or ownership experience, including authorization lifecycle activities.
  • Experience operating FedRAMP after authorization, including continuous monitoring, recurring evidence collection, remediation deadlines, scope changes, and assessment preparation.
  • Strong working knowledge of NIST SP 800-53, the FedRAMP Moderate baseline, control inheritance, shared responsibility, findings, and evidence requirements.
  • Working technical knowledge of SaaS and cloud environments, including IAM, CI/CD, vulnerability management, logging, monitoring, encryption, change management, and cloud infrastructure.
  • Must be a U.S. Person and reside in the United States.

Nice to have

  • 5+ years of direct FedRAMP execution experience or ownership of multiple authorization lifecycles.
  • Experience leading company-side execution in self-managed or partner-managed FedRAMP environments.
  • Experience working with FedRAMP assessors, 3PAOs, agencies, authorization stakeholders, managed hosting providers, or compliance partners.
  • Experience with FedRAMP scope, authorization boundaries, significant changes, change management, and continuous monitoring in SaaS or cloud environments.

Culture & Benefits

  • Remote work arrangement within the United States.
  • Individual-contributor role with limited day-to-day supervision and direction from the Director of Security and Compliance.
  • Cross-functional work with technical, business, legal, leadership, and external partner stakeholders.
  • Use of approved AI-enabled tools and automation to improve program efficiency and quality, with human validation of outputs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →