Jobgether
Senior Public Sector Compliance Manager
- Location
- US
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Senior
- Posted
- 29 September 2026 (yesterday)
Checked yesterdayApplications go to the employer, never to RoleSprint
About this role
Accountabilities • Develop and maintain a comprehensive compliance roadmap covering federal security requirements, authorization activities, and risk mitigation initiatives.
• Support FedRAMP Moderate and High authorization and reauthorization processes, including the preparation, review, and maintenance of SSPs, POA&Ms, SAPs, SARs, and related documentation.
• Serve as a subject matter expert on FedRAMP High, NIST SP 800-53, and associated federal compliance requirements.
• Support strategic federal initiatives, including security and compliance requirements associated with DoD Impact Level 6 environments.
• Map, assess, and monitor security controls against FedRAMP Moderate/High baselines and NIST SP 800-53 requirements.
• Coordinate with engineering, operations, and DevSecOps teams to ensure security and compliance requirements are incorporated into system design and ongoing operations.
• Manage continuous monitoring activities, including periodic assessments, penetration testing, vulnerability scanning, and associated documentation.
• Track POA&M items through remediation and closure while monitoring outstanding risks and compliance gaps.
• Coordinate with Third Party Assessment Organizations (3PAOs), government customers, and internal stakeholders during audits, assessments, and authorization activities.
• Support federal sales and business development teams by providing guidance on regulatory requirements, security frameworks, and compliance considerations.
• Administer and maintain the FedRAMP compliance platform and manage recurring monthly, quarterly, and annual authorization requirements.
• Produce compliance metrics, reporting, and risk analysis for leadership and maintain awareness of changes to FedRAMP, NIST, FISMA, CMMC, and related frameworks.
Requirements
• 2–3 years of experience in information security compliance, governance, risk management, or a related field, preferably within a FedRAMP- or FISMA-regulated environment.
• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related discipline, or equivalent professional experience.
• U.S. citizenship and eligibility to obtain a security clearance are required for work involving applicable government cloud environments.
• Strong working knowledge of NIST SP 800-53, FedRAMP Moderate/High baselines, and the federal authorization process.
• Hands-on experience creating, maintaining, or reviewing security documentation such as SSPs, POA&Ms, SARs, and SAPs.
• Familiarity with governance, risk, and compliance tools, as well as vulnerability scanning technologies such as Nessus or Qualys and the ability to interpret security findings.
• Experience implementing or assessing security controls in cloud environments such as AWS, Azure, or Google Cloud is highly valuable.
• Experience working with a 3PAO or federal agency is preferred.
• Relevant certifications such as CISSP, CISA, CAP, CompTIA Security+, or equivalent credentials are advantageous.
• Strong analytical and problem-solving abilities, with a structured approach to identifying risks, resolving compliance gaps, and managing multiple priorities.
• Excellent written and verbal communication skills, including the ability to translate technical compliance requirements for non-technical stakeholders.
• Ability to work independently while collaborating effectively across security, engineering, operations, sales, and other functions in a fast-paced environment.
Benefits
• Remote position within the United States.
• Opportunity to contribute to federal security and compliance programs involving FedRAMP and other high-assurance environments.
• Cross-functional exposure to cybersecurity, cloud infrastructure, engineering, DevSecOps, sales, and public sector initiatives.
• Opportunity to work on compliance programs aligned with evolving federal security requirements.
• Employment benefits and compensation are subject to the applicable terms and programs offered by the hiring organization.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 29 September 2026, last checked yesterday. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.