- Company Name
- Mark43
- Job Title
- Lead Program Manager - FedRAMP
- Job Description
-
Job title: Lead Program Manager – FedRAMP
Role Summary:
Senior individual‑contributor responsible for end‑to‑end FedRAMP compliance (Moderate/High) within a SaaS/cloud organization. Owns authorization lifecycle, controls mapping, and cross‑functional alignment to regulatory frameworks (NIST SP 800‑53, DoD IL2/IL4/IL5, CJIS, SOC 2, UK regulations, CMMC). Drives translation of regulatory requirements into engineering‑ready guidance, maintains evidence for 3PAOs, and collaborates with engineering, product, security, and federal stakeholders.
Expectations:
- Deliver a fully compliant FedRAMP Moderate/High authorization and maintain ongoing authorization.
- Influence technical architecture and product decisions to meet security baselines without hindering delivery.
- Maintain up‑to‑date control implementation and evidence for continuous monitoring.
- Act as the primary FedRAMP subject‑matter expert across the organization.
Key Responsibilities:
1. Own the FedRAMP Authorization To Operate (ATO) lifecycle: produce and maintain SSP, manage POA&M, coordinate 3PAO assessments, and engage with authorizing officials.
2. Translate FedRAMP and related regulatory requirements (NIST SP 800‑53, DoD ILs, CMMC) into actionable, engineering‑ready guidance.
3. Review architectural decisions for federal roadmap features; balance product delivery with compliance needs.
4. Partner with Security & Engineering teams to implement consistent, evidence‑backed controls across frameworks (CJIS, SOC 2, UK).
5. Engage federal customer stakeholders to communicate compliance posture and roadmap.
6. Map technical requirements of federal contract opportunities to current FedRAMP controls and identify gaps.
7. Ensure alignment between FedRAMP baselines and DoD IL2/IL4/IL5 requirements; resolve control inheritance and boundary gaps.
Required Skills:
- 7+ years of federal compliance program leadership in SaaS/cloud/technology.
- Direct ownership of FedRAMP Moderate and/or High ATO, including continuous monitoring.
- Deep expertise with NIST SP 800‑53 (Rev 4/Rev 5) – tailoring, implementation, and continuous monitoring.
- Experience with DoD Impact Levels (IL2/IL4/IL5): boundary definitions, inheritance, customer expectations.
- Proficiency in translating complex regulatory requirements into pragmatic engineering guidance.
- Strong influence skills: ability to persuade Engineering, Product, Security leaders without formal authority.
- Technical problem‑solving: collaborate with engineers on control tradeoffs, boundary decisions, architecture constraints.
- Autonomous, self‑directed; primary FedRAMP subject‑matter expert.
- Preferred: familiarity with CMMC Level 2/Level 3 mapping, SOC 2, CJIS, ISO 27001, UK public sector regulations, and cloud environments in AWS GovCloud or equivalent.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (advanced degree preferred).
- Relevant certifications (CISSP, CISA, CCP, CompTIA Security+, or equivalent) are a plus.
- Valid Federal security clearance is not required but beneficial.
Washington, United states
Hybrid
Senior
25-01-2026