GRC Program Manager (FedRAMP & Compliance)
Port
About Port At Port.io , we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M Series C funding round, we are in a phase of rapid hypergrowth with strong enterprise momentum. We act as the central nervous system for engineering, enabling platform teams to unify their stack and expose it as a governed layer through golden paths for developers and AI agents. By combining rich engineering context, workflows, and actions, we help organizations transition from manual processes to autonomous, AI‑assisted engineering workflows while maintaining control and accountability. As a product‑led company, we believe in building world‑class platforms that fundamentally shape how modern engineering organizations operate. Why we’re looking for you We’re looking for a GRC Program Manager to drive Port’s FedRAMP authorization and oversee our broader compliance portfolio. You’ll be the program’s operational backbone - coordinating 3PAO assessments, managing documentation, and ensuring readiness across teams. FedRAMP authorization is a strategic milestone for Port as we expand into enterprise and federal markets. This is a high‑visibility initiative with executive sponsorship, requiring precise coordination across engineering, security, and product. We need a program manager who thrives in complex, cross‑functional environments and can translate regulatory frameworks into clear execution plans while managing timelines, budgets, and stakeholder expectations. Who you’ll work with You’ll report to the CISO and work closely with the Security team, Engineering, DevOps, IT, and Product teams. You’ll manage relationships with external partners, including the 3PAO, FedRAMP consultants, and government agency sponsors. You will also collaborate with Legal and Finance on contracts, budgets, and compliance obligations. In addition, you’ll support the US sales process, compliance and regulatory inquiries, RFIs/RFPs, and other related business processes. What you’ll do Lead the FedRAMP project from kickoff through ATO: schedule, documentation, 3PAO engagement, and agency coordination. Own the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and all readiness deliverables. Manage the 3PAO relationship, coordinate assessments, and drive remediation efforts. Build and maintain the compliance evidence repository and continuous monitoring program. Manage cross‑team milestones, track control implementation progress, and identify blockers. Develop repeatable processes and frameworks to sustain compliance post‑authorization. Partner with Engineering, Security, IT, and Product to translate NIST 800‑53 controls into technical implementations. Lead internal readiness assessments and gap analysis. Assist and support GRC initiatives, other compliance frameworks, team processes and systems. Requirements Direct FedRAMP experience (managing an authorization from start to ATO) — Must have. 5+ years of experience managing compliance or GRC programs in SaaS or regulated environments. Proven track record running complex audits or certification programs (FedRAMP, SOC 2, ISO, etc.). Deep understanding of control frameworks (NIST 800‑53, ISO 27001) and how they translate to technical implementations. Exceptional project management and communication skills — ability to manage timelines, budgets, and complex dependencies. Experience managing vendor relationships, including 3PAOs, consultants, and compliance tooling providers. Strong stakeholder management skills — comfortable managing multiple workstreams and influencing across technical and non‑technical teams. Detail‑oriented with strong documentation and organizational skills. Nice to have Experience working with government agency sponsors and understanding FedRAMP agency workflows. Hands‑on experience with GRC automation platforms (Drata, Tugboat Logic, Vanta, OneTrust). Risk Management. Background in technical security controls, cloud infrastructure, or DevSecOps. CISSP, CISM, PMP, or FedRAMP‑related certifications. Experience with continuous monitoring and ongoing compliance management. #J-18808-Ljbffr
$95k - $110k
Blackkite in Boston seeks a Senior GRC Analyst to manage compliance platforms and customer security assessments. The ideal candidate will have 2-4... ...paired with skills in SOC 2 and ISO 27001. You'll support FedRAMP ConMon reporting and ensure audit-ready documentation while...Suggested$137k - $165k
...Overview The Senior Manager, Global Trade Compliance – Export Compliance is a strategic leadership role responsible for designing, executing, and... ...continuously enhancing the company’s global export control program. This position will lead the development of policies, processes...SuggestedFull timeTemporary workPart timeWork at officeLocal area$95k - $110k
...complex cyber, financial, and compliance signals into clear,... ...their third‑party cyber risk management programs in an increasingly complex digital... ...THE OPPORTUNITY The Senior GRC Analyst reports to the Director... ...security assessments, and FedRAMP ConMon execution support. This...SuggestedWorldwideFlexible hours- RTX in Cambridge, MA is seeking an EHS Generalist to support environmental, health, and safety compliance. The ideal candidate will manage EHS programs, provide technical support, and ensure adherence to regulations while promoting a culture of safety and sustainability...Suggested
- ...EHS Generalist based in Cambridge, MA to support our Environmental, Health, and Safety (EHS) function. You will manage programs, ensure regulatory compliance, and develop EHS communications. The ideal candidate possesses a relevant Bachelor's or Master's degree and at least...Suggested
- ...Join 0100 Mass General Brigham Incorporated as a 340B Program Manager. This role leads the 340B program, ensuring compliance and maximizing savings across the healthcare system. With responsibilities ranging from audit readiness to reporting, you'll collaborate with critical...
$157k
...Job Description We're looking for a FedRAMP Technical Program Manager to own day-to-day oversight and execution of Nexthink's FedRAMP and U.S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar...Work at officeImmediate startRemote workFlexible hours- ...GRC Program Operations Specialist Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution. Perform and support... ...activities. Support security compliance monitoring and audit readiness activities,...
$60k - $90k
...As a GRC Analyst, Operations & Risk, you will support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate third-party risk activities, strengthen operational workflows, and improve visibility across risk and compliance work. This...Full timeWork at officeRelocation- ...Job Summary The GRC Analyst – Third-Party & Client Questionnaire Management is responsible for supporting and managing security, risk, compliance, and due diligence questionnaires received from clients, prospects, vendors, and business partners. This role serves as a subject...Contract workWork at office
$115k - $125k
...results through our technology, innovation, unbiased expertise, client experience. We are seeking a Security Assurance and Compliance Program Manager to support FRT’s information security, information technology, and compliance governance program by ensuring that the...Temporary workWork at officeLocal area- ...Responsible for ensuring that the organization's programs and services for dual-eligible... ..., and monitoring the organization's compliance with federal and state regulations related... ...Medicare Compliance Officer, senior management, and relevant regulatory bodies as required...Work at officeFlexible hours
- ...Position: GRC Policy Analyst Location: Boston, MA (Hybrid) Duration... ...Responsibilities Oversee and manage all policies including... ...Manage the cybersecurity awareness program including annual training, phishing... ...around risk analysis and compliance requirements Qualifications 3-...Long term contract
$75 per hour
Insight Global is seeking a ServiceNow GRC Analyst in Boston to join a growing Security team. This role will be responsible for operationalizing security controls in ServiceNow across SaaS applications, working closely with system owners and technical leads. The ideal candidate...- ...GoTo Meeting is seeking a GRC Analyst to manage security and compliance questionnaires from various stakeholders. This role emphasizes automating processes, enhancing GRC platform functionalities, and ensuring accurate responses to compliance inquiries. The ideal candidate...
$75 per hour
Job Description We’re looking for a hands‑on ServiceNow GRC Analyst to join a growing Security organization and support the implementation... ...owners and technical leads to document, validate, and track compliance—while intentionally excluding physical security-related...$70k - $80k
...As a GRC Cybersecurity Analyst (CA), you will play a pivotal... ...their cybersecurity improvement programs. In this position, you will... ...leadership in Governance, Risk, and Compliance (GRC) directly to our clients... ...of a good cybersecurity management program, including: Leading...Full timeWork at office- ...Vertex Pharmaceuticals in Boston is seeking a Quality Manager to provide oversight for quality assurance and compliance in pharmaceutical processes. This role involves coordinating quality activities across multiple projects and ensuring adherence to corporate goals. The...Remote work
$42.7k - $79.3k
...your voice is valued. Summer Intern – GRC Amex GBT’s Security GRC team is looking... ...Intern to support our Governance, Risk, and Compliance programs. This is an exciting opportunity to... ...foundational skills in information security, risk management, and compliance. What You'll Do Support...InternshipSummer internshipImmediate startFlexible hours- ...Motion Recruitment Partners LLC is seeking a highly experienced Technical Program Manager focused on FedRAMP compliance within a dynamic AI-driven SaaS environment. This full-time position is fully remote and offers significant executive visibility and the chance to shape...Full timeRemote workFlexible hours
- ...Tech Mirrors is seeking a GRC Policy Analyst to oversee and manage the development and revisions of cybersecurity... ...Framework and experience in policy program management. The successful... ...cybersecurity training initiatives, and ensure compliance with applicable laws and...Long term contract
- ...Senior Strategic Program Manager, Ai Factory This role has been designated as 'Remote/Teleworker', which means you will primarily work from home. Job Description Leads customer engagement to ensure that it meets all scope, time, budget and quality expectations, through...Work at officeRemote workWork from home
$130k - $180k
...Brown Brothers Harriman is seeking a Program Manager in Boston, MA, to oversee projects in Corporate Actions and Tax Systems. The role entails managing project planning and execution, stakeholder communication, and resource management to ensure timely project delivery....- ...Draper Labs, based in Cambridge, MA, is seeking a Program Manager 2 to oversee complex projects in Air Force and Missile Defense. You'll manage the entire lifecycle of significant programs while ensuring cost, schedule, and technical performance. The ideal candidate has...
- ...Phase2 Technology is looking for a Senior Analyst to provide research and strategic advice for risk management teams. The successful candidate will conduct research, create reports, and consult with clients to enhance their risk management capabilities. A background in...
- ...Northeastern University is hiring a Governance, Risk and Compliance Analyst in Boston. This hybrid role involves supporting compliance initiatives and NIST frameworks in government and higher education environments. The ideal candidate will have a Bachelor's degree, 2...
- ...Forrester Research, based in Cambridge, MA, is seeking a Senior Analyst to deliver strategic advice and conduct research for risk management leaders. The ideal candidate will possess strong knowledge of risk practices, cyber risk quantification, and excellent...
$147.68k - $236.28k
...practical. Design and deliver training programs, workshops, demos, and enablement... ...evangelizing AI capabilities—not managing people. What You’ll Do Adoption & Enablement... ..., prompt injection risks, and compliance requirements (CJIS, FedRAMP, SOC 2). Develop and maintain a "...Work experience placementWork at office$95k - $245k
...customer stakeholders in support of current and future production programs within the Strategic Systems Program Office. Drive program... ...effectively recruit, retain and develop key talent for the business. Manage and control all phases of programs from inception through...Full timeContract workWork at officeLocal area$100k - $275k
...Inuplands in Cambridge, MA is looking for a Program Manager 2 for Air Force and Missile Defense. This role requires overseeing complex projects, managing teams, and ensuring customer satisfaction while meeting targets. The ideal candidate should possess at least 7 years...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Program Manager (FedRAMP & Compliance). Be the first to apply!
- program coordinator remote Boston, MA
- head of program management Boston, MA
- agile transformation program manager Boston, MA
- program supervisor Boston, MA
- executive program manager Boston, MA
- staff program manager Boston, MA
- service program manager Boston, MA
- marketing program manager Boston, MA
- programme manager Boston, MA
- international program coordinator Boston, MA

