GRC Program Manager (FedRAMP & Compliance)
Port.io
About Port At Port.io , we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M Series C funding round, we are in a phase of rapid hypergrowth with strong enterprise momentum. We act as the central nervous system for engineering, enabling platform teams to unify their stack and expose it as a governed layer through golden paths for developers and AI agents. By combining rich engineering context, workflows, and actions, we help organizations transition from manual processes to autonomous, AI‑assisted engineering workflows while maintaining control and accountability. As a product‑led company, we believe in building world‑class platforms that fundamentally shape how modern engineering organizations operate. Why we’re looking for you We’re looking for a GRC Program Manager to drive Port’s FedRAMP authorization and oversee our broader compliance portfolio. You’ll be the program’s operational backbone - coordinating 3PAO assessments, managing documentation, and ensuring readiness across teams. FedRAMP authorization is a strategic milestone for Port as we expand into enterprise and federal markets. This is a high‑visibility initiative with executive sponsorship, requiring precise coordination across engineering, security, and product. We need a program manager who thrives in complex, cross‑functional environments and can translate regulatory frameworks into clear execution plans while managing timelines, budgets, and stakeholder expectations. Who you’ll work with You’ll report to the CISO and work closely with the Security team, Engineering, DevOps, IT, and Product teams. You’ll manage relationships with external partners, including the 3PAO, FedRAMP consultants, and government agency sponsors. You will also collaborate with Legal and Finance on contracts, budgets, and compliance obligations. In addition, you’ll support the US sales process, compliance and regulatory inquiries, RFIs/RFPs, and other related business processes. What you’ll do Lead the FedRAMP project from kickoff through ATO: schedule, documentation, 3PAO engagement, and agency coordination. Own the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and all readiness deliverables. Manage the 3PAO relationship, coordinate assessments, and drive remediation efforts. Build and maintain the compliance evidence repository and continuous monitoring program. Manage cross‑team milestones, track control implementation progress, and identify blockers. Develop repeatable processes and frameworks to sustain compliance post‑authorization. Partner with Engineering, Security, IT, and Product to translate NIST 800‑53 controls into technical implementations. Lead internal readiness assessments and gap analysis. Assist and support GRC initiatives, other compliance frameworks, team processes and systems. Requirements Direct FedRAMP experience (managing an authorization from start to ATO) — Must have. 5+ years of experience managing compliance or GRC programs in SaaS or regulated environments. Proven track record running complex audits or certification programs (FedRAMP, SOC 2, ISO, etc.). Deep understanding of control frameworks (NIST 800‑53, ISO 27001) and how they translate to technical implementations. Exceptional project management and communication skills — ability to manage timelines, budgets, and complex dependencies. Experience managing vendor relationships, including 3PAOs, consultants, and compliance tooling providers. Strong stakeholder management skills — comfortable managing multiple workstreams and influencing across technical and non‑technical teams. Detail‑oriented with strong documentation and organizational skills. Nice to have Experience working with government agency sponsors and understanding FedRAMP agency workflows. Hands‑on experience with GRC automation platforms (Drata, Tugboat Logic, Vanta, OneTrust). Risk Management. Background in technical security controls, cloud infrastructure, or DevSecOps. CISSP, CISM, PMP, or FedRAMP‑related certifications. Experience with continuous monitoring and ongoing compliance management. #J-18808-Ljbffr Port.io
- ...modern engineering organizations operate. Why we’re looking for you We’re looking for a GRC Program Manager to drive Port’s FedRAMP authorization and oversee our broader compliance portfolio. You’ll be the program’s operational backbone - coordinating 3PAO assessments,...SuggestedFlexible hours
$149k - $266.2k
...Senior Principal Technical Program Manager to lead security-focused technical... ...programs for Autodesk’s FedRAMP and Public Sector cloud... ...execution across security, compliance, engineering, infrastructure... ...Jira, Confluence, dashboards, GRC tools, service catalogs, and...SuggestedPermanent employmentFull timeFor contractorsWork at officeRemote work- RTX in Cambridge, MA is seeking an EHS Generalist to support environmental, health, and safety compliance. The ideal candidate will manage EHS programs, provide technical support, and ensure adherence to regulations while promoting a culture of safety and sustainability...Suggested
- ...EHS Generalist based in Cambridge, MA to support our Environmental, Health, and Safety (EHS) function. You will manage programs, ensure regulatory compliance, and develop EHS communications. The ideal candidate possesses a relevant Bachelor's or Master's degree and at least...Suggested
- ...Analyst Governance, Risk, and Compliance, a member of the Information... ...Governance, Risk and Compliance (GRC) team, focuses on... ...maintaining governance frameworks, managing risk remediation activities,... ...access to an Employee Assistance Program focused on mental and...SuggestedWork experience placementWork at officeLocal area
$130k - $170k
...healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity... ...the ongoing operation of the GRC program in a fast-paced, high-growth... ...cybersecurity and AI risk assessments, exceptions management, SDLC reviews and security compliance...Full timeWork at officeRelocation$220k - $260k
...experience The Role Security and compliance at Blitzy currently run... ...: a Security Delegate managing our frameworks with help... ...to fix that. As Head of GRC, you'll own a compliance program that's audit-ready by... ...like Insight Assurance and FedRAMP platform partners such as...$125k - $198k
Job TitleCompliance Program Manager (Operations and Investigations)Job DescriptionCompliance Program Manager (Operations and Investigations):The Compliance Program Manager supports the Corporate Compliance Program by ensuring adherence to healthcare laws, regulations, and...Full timeContract workWork at officeImmediate startWork visaRelocation package3 days per week- KAYAK, part of Booking Holdings, is seeking an Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team. This early‑career role develops skills in risk assessments, policy management, and control monitoring while modernizing GRC practices. The position...Work at office3 days per week
$70k - $80k
...As a GRC Cybersecurity Analyst (CA), you will play a pivotal... ...their cybersecurity improvement programs. In this position, you will... ...leadership in Governance, Risk, and Compliance (GRC) directly to our clients... ...of a good cybersecurity management program, including: Leading...Full timeWork at office- Babel Street is seeking a GRC Analyst to support cybersecurity governance, risk management, and compliance across multiple stakeholders. You will help maintain compliance with NIST CSF, CMMC, ISO/IEC 27001, SOC 2, and related controls, and support audits and policy management...
$90k - $130k
We are hiring a GRC Analyst to support the Governance, Risk, and Compliance program with a focus on third-party vendor risk. You will own the intake, triage, and completion... ...available Here\'s what you\'ll be doing: Manage and triage third-party vendor risk assessment...Relocation package$90k - $130k
Hampton North is seeking a GRC Analyst to support governance, risk, and compliance with a focus on third-party vendor risk. You will own intake, triage, and completion of vendor assessments, maintaining progress across a fast-paced, cross-functional environment. Hybrid...Relocation package- ...more.In collaboration with the Senior Director, Government programs, manage the vendor oversight programs for government payer programs... ...models, intake monitoring performance reports and evaluate compliance and initiate corrective action and/or process improvement activities...Full timeWork at officeFlexible hours
$155k - $185k
WHOOP is seeking a Senior Program Manager, SaMD, located in Boston, MA. This role involves driving execution of Software as a Medical Device... ..., collaborating with various teams to ensure regulatory compliance and successful product delivery. Candidates should have 6-10...- Elliot Health System - Compliance & Privacy Program Sr. Manager - Full Time Position Summary - 40 hr/wk. Days, hours can be flexible. Required on site presence. Key Responsibilities Manages the implementation of Elliot Health System entities' compliance activities, programs...Full timeTemporary workPart timeWork at officeLocal areaFlexible hours
$60k - $90k
Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will have...- KAYAK is seeking an Associate GRC Analyst to join the Cyber Governance, Risk, and Compliance team in Cambridge/Concord, MA. Early‑career professional with a solid... .... The role focuses on risk assessments, policy management, control monitoring, and BC/DR efforts, with collaboration...Work at office3 days per week
- Philips is seeking a Compliance Program Manager (Operations and Investigations) to support the Corporate Compliance Program in the Cambridge, MA area, ensuring adherence to healthcare laws and corporate integrity commitments within Philips AM&D. The role emphasizes risk...Contract work
- Philips in Cambridge, MA is seeking a Compliance Program Manager (Operations and Investigations) to support the Corporate Compliance Program and ensure adherence to healthcare laws and corporate integrity commitments. The role involves developing risk-based auditing plans...
- Philips in Cambridge, MA seeks a Compliance Program Manager (Operations and Investigations) to support the Corporate Compliance Program and ensure adherence to healthcare laws within Philips AM&D. The role supports the Compliance Officer, develops risk-based auditing plans...
$98.78k - $148.18k
...communities. Learn more about who we are at Point32Health.Job SummaryUnder the direction of the Director or Senior Manager of the department, the Compliance Program Manager III manages compliance programs, regulatory projects and initiatives with significant complexity, risk...Full timeWork experience placementWork at officeWork from homeFlexible hours$125.1k - $225.2k
...your talent and redefine what’s possible.Job Description:Parsons is seeking a dynamic Senior Rail & Transit Operations Planning Program Manager to join our growing Rail and Transit business. This is a high-impact leadership role for a seasoned professional who thrives at...Full timeContract workFor contractorsFlexible hours- Blitzy, a Cambridge, MA based AI software platform, seeks a Head of GRC to own a proactive compliance program built into design. You’ll manage SOC 2 Type II and ISO 27001:2022 cycles, govern a GRC platform, and lead auditor relationships directly for enterprise deals....
$147k - $210k
...renewable energy, power, oil & gas, or energy technology) Senior Program Manager - Strategic Projects _______________________________________... ...a deep understanding of industry trends, market dynamics, compliance standards, and emerging technologies. ______________________...$147.68k - $236.28k
AI/Technology Evangelist - Program Manager (Corporate AI Team) Join Axon and be a Force for Good. At Axon, we’re on a mission... ..., data classification, prompt injection risks, and compliance requirements (CJIS, FedRAMP, SOC 2). Develop and maintain a “Vibe Coding” safety...Work at office- ...preferred8+ years professional experience in legal, regulatory, compliance environments; attorneys with “Big Law” and/or in house experience preferred5+ years in end-to-end allegations management programs including intake/triage, case management and/or investigations,...ApprenticeshipWork at office
$110k - $150k
...Liberty airport.Position SummaryWe have an opportunity for a Manager, Global Trade Compliance to join our team. In this role, you will communicate... ...various trade topics. You will support export compliance programs, conduct audits, and ensure adherence to global trade regulations...Full timeWork at officeLocal area- Work Flexibility: RemoteWhat you will doThe Senior Manager, Compliance PMO is responsible for leading the project management office across the... ...drive alignment and buy-in across the organization.Serve as program manager for critical projects, driving both strategy and...Full timeTemporary workFor contractorsRemote work
- ...Office at Harvard University provides strategic, operational, and financial leadership for the HIO. You will set the vision, ensure compliance with federal and institutional policies, and build a robust service portfolio for international students, scholars, and staff...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Program Manager (FedRAMP & Compliance). Be the first to apply!
- global program manager Boston, MA
- program operations manager Boston, MA
- foundation program manager Boston, MA
- clinical program director Boston, MA
- senior program coordinator Boston, MA
- program manager government Boston, MA
- healthcare program manager Boston, MA
- executive program manager Boston, MA
- program coordinator remote Boston, MA
- agile transformation program manager Boston, MA

