Security Compliance Program Manager
$100kKaizen
Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services. Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service. Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year. Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn\'t be a luxury in government. It\'s how you earn trust back. The Role Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function to own the obligations, the paperwork of record, and the accuracy of everything we submit. You will build and run that function, working directly with the engineering lead, the incoming security engineer, and the executive team. Location New York, NY or Washington, D.C. (Hybrid). This is the permanent version of the role. We are also posting a contract equivalent for the same scope. The differences are that this one carries the authorization program long term, including the path from Moderate to High, and a path to holding the FSO designation yourself. The Programs FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. The change-control side of an authorization matters here as much as the initial package. You own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor. You also own the significant-change process, which is the mechanism that makes the model work. DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer\'s or a partner\'s. This role owns knowing the reciprocity map cold, reading a hosting platform\'s actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary. Reciprocity is inconsistent, so it has to be verified per agency rather than assumed. CMMC. A separate track from the product, and keeping the two separate is part of the job: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You run the self-assessment against NIST 800-171 Rev 2, own a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries. You drive the scoping decision, which is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident-reporting clauses matters here. What You\'ll Do Own the POA&M end to end: keep it current, submit it to our hosting partner on the contractual cadence, and make sure what gets signed is accurate Run NIST 800-171 self-assessment workbooks to completion, maintain the SPRS score, and drive remediation items in priority order through to close Manage all federal contract and agency paperwork: DD Form 254, DD Form 2345, JCP registration, PIEE and SPRS portal administration, SAM.gov, agency security questionnaires, and DFARS security clause flowdowns Track every live contractual SLA, from incident notification through periodic reviews and annual affirmations, and prove we met them Own the obligation register. Read every federal contract and subcontract for what it actually binds us to, including FAR and DFARS flowdowns, and run the register that tracks it. This reaches well past security into employee notices, required training, prohibited technology, EEO and labor reporting, OCI, and business ethics. Much of it gets executed by People Ops, legal or IT, but one person has to hold the map Sit in on new federal contracts and subcontracts before signature and flag what we are agreeing to Build and maintain the control-to-evidence mapping so any control\'s status is a two-minute answer instead of an archaeology dig through tickets Own personnel security operations: US-person verification, background screening at federal-aligned tiers, onboarding and offboarding access controls, and quarterly access reviews Lead FCL readiness: FSO vendor selection, key personnel clearance sequencing, SF 328 disclosures, and NISS submission when sponsorship lands, with a path to holding the FSO designation yourself What You\'ll Bring Direct experience submitting in federal portals, SPRS and PIEE specifically. "Supported" and "submitted" are different things Has run a NIST 800-171 self-assessment or RMF package end to end, with personal accountability for the outcome Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it Hands-on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor Current on FedRAMP as it exists in 2026, and fluent in 20x specifically. Certification Classes, Key Security Indicators, machine-readable packages, continuous validation. We are building on 20x, so experience that stops at Rev 5 documentation will be working against the grain here Knows where Rev 5 still binds. High remains a Rev 5 process and new Rev 5 certifications stop in June 2027. Knowing which parts of a roadmap that constrains is more useful to us than depth in either framework alone Can reason about a shared authorization boundary: which controls are inherited, which are shared, which stay application-specific, and what kind of change triggers a significant-change request Working knowledge of the DoD Cloud Computing SRG and how Impact Levels sit on FedRAMP baselines. The CSP and Mission Owner split matters here, and so does reading a hosting platform\'s ATO coverage against the agency doing the buying Has worked opposite a 3PAO or independent assessor on evidence requests and knows what they accept in practice Can read a contract for FAR and DFARS flowdowns and turn them into a tracked obligation register. If you have run a subcontract flowdown matrix, say so Background in federal or defense contracting (agency-side, prime, or sub) where you owned a compliance function rather than a slice of one Has been the only compliance person at an organization; you know how to close a loop without a team behind you US person, eligible for a Tier 3 background investigation; DC-based or NYC-based with regular in-office presence An active or recently held clearance is a meaningful accelerant. Existing investigations don\'t convert, and a Tier 3 takes roughly five months Strong Candidates May Also... Have owned a FedRAMP authorization through to completion, on the provider or the assessor side. This is the most valuable thing on this list and it moves our offer Have written OSCAL by hand, or stood up a trust center against live control indicators Bring a military background in security, intelligence, or information security (unit security manager, SSO, S2/G2, cyber operations, or similar) Hold a CMMC CCP or RP, or have direct experience with eMASS, Xacta, Paramify, or equivalent GRC tools in a federal context Know the GovRAMP reciprocity path into FedRAMP Class A Come from a GovTech or SaaS company actively pursuing FedRAMP or CMMC, rather than one that already holds it Don\'t Apply If... Your compliance background is in financial services, insurance, or telecom. Large-team GRC with no federal exposure doesn\'t transfer here You\'ve assessed federal compliance programs but never owned one. Assessing a program and being accountable for it are different jobs Your first instinct when asked about our SPRS score is to open a platform and run a report rather than know the number and the story behind it You need a clean program to walk into. Your first 90 days are inventory, triage, and unglamorous paperwork Owning a high-side authorization end to end is what you want as your next move. The near-term scope here is the base authorization and the operating machinery around it Accuracy under commercial pressure is negotiable for you. What we submit carries real legal exposure, and holding the truthful answer is the job What Kaizen Offers Health & Insurance 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam — all fully covered for employees, with 100% coverage for dependents. $100,000 in fully paid life insurance. FSA and Dependent Care FSA. One Medical membership, on us — same-day primary care, 24/7 virtual visits, and offices all over the city. Fertility and family-building support through Carrot. 401(k) through Guideline, with a 2% company match. Family & Time Off 16 weeks of fully paid parental leave for birthing parents. 10 weeks fully paid for non-birthing parents. Unlimited PTO, with a two-week minimum (we mean it when we say take time off!) Closed for all federal holidays. Company-wide winter break the week of Christmas. Company offsites throughout the year. Office & Remote Setup Up to $750 one-time home office or desk setup stipend for NYC-based employees. $500 for remote employees. $50/month commuter benefit (company contribution). Expensed lunch while in the office. Company-provided laptop of your choice. Wellness Fully covered gym membership at Grindhouse — right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement. Stipends
- 100/month utility stipend.
- 500/year professional development.
- 250/year recreation.
- 300/quarter pet care stipend.
- ...is hiring for a senior role focused on program development and consulting to help higher... ...and maintain PCI DSS, GLBA, and related compliance programs. You will lead multi-stakeholder... ...experience in IT compliance and program management, with a track record of delivering #J-1...SuggestedRemote job
$122k - $237k
Security Compliance - Technical Program Manager - Weights & Biases CoreWeave, the AI hyperscaler, has acquired Weights & Biases to create the most powerful end‑to‑end platform for AI development, deployment, and iteration. Since 2017 CoreWeave has built a global footprint...SuggestedTemporary workCasual workWork at officeRemote workFlexible hours- ...professional for a contract position focusing on project management and ISO 27001 compliance. The ideal candidate will have over 15 years of... ...insight to clients. The role also supports annual ISO 27001 security certification efforts and offers competitive hourly compensation...SuggestedHourly payContract work
$125k - $150k
...Strategas Asset Management provided pay range This range is provided by Strategas Asset... ...ownership, SAM is affiliated with Strategas Securities, LLC (STS), a FINRA member broker‑... ...experienced and detail‑oriented Compliance Program Manager to support and enhance the firm...SuggestedFull time$180k - $225k
...Preferred Qualifications:The Compliance Transformation team is focused... ...defined, risks are actively managed, progress is transparent, and... ...This Compliance Transformation Program Manager plays a central part... ...designation.Who We Are TD Securities offers a wide range of capital...SuggestedFull timeLocal areaWork from homeFlexible hours- ...ABOUT THE ROLE The Compliance Program Manager helps build the compliance backbone of Catena Trust Bank. Reporting to the Chief Compliance Officer and partnering closely with the Chief Trust Officer, the Program Manager operates core elements of the Compliance Management...Full time
- Compliance & Program Manager (HCP Events) Join to apply for the Compliance & Program Manager (HCP Events) role at Maritz Maritz is seeking a Compliance & Program Manager (HCP Events). This role combines healthcare compliance expertise in event management with planning...Full timeContract workRemote work
- Catena Trust Bank is seeking a Compliance Program Manager to help build the compliance backbone of the bank. Reporting to the Chief Compliance Officer, you will oversee fiduciary and third-party risk programs and guide non-financial crimes compliance, privacy, and data...
$126.07k - $196.98k
...Chemours chemistry. Chemours is seeking a Privacy, AI & Compliance Program Manager to join our growing team. This position will be available... ...will include Legal, Data Enablement, IT, Cybersecurity, HR, Security, Global Trade/Export Compliance, Procurement, and Sales teams...Work at officeLocal area$153k - $245k
...collaboration, join us!As the Federal Compliance Manager, you will collaborate with internal stakeholders... ...adherence to Figma's FedRAMP cloud security standards. Responsibilities include... ...auditsIdentify and escalate technical and program risks to relevant stakeholders,...Minimum wageFull timeLocal areaRemote workFlexible hours$169k - $296k
...and collaboration, join us!Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across... ...such as FAIRExperience with security and compliance requirements in a public company environment, including...Minimum wageFull timeLocal areaRemote workFlexible hours- ...settlement, and the industry's leading security infrastructure. Home to Anchorage... ...on LinkedIn.As the Lead for Regulated Compliance Programs, you will be a key architect in adapting... ...protection. You will act as a qualified manager with a wide range of expertise, meaningfully...
$106.9k - $169.1k
...By taking advantage of all structured and unstructured data - securing and protecting private information more effectively - Elastic... ...of AI. What is The Role Elastic is looking for a Marketing Program Manager to join the Marketing PMO team, focused on supporting the execution...Local areaFlexible hours- ...Community Coordinator to review and process Certificates of Insurance and manage related records. Under supervision, you will interact with staff, providers, and insurance companies to ensure compliance with NYC law and DYCD policies. Responsibilities include tracking...
- Emerging Tech is seeking a Program Manager for Cybersecurity & Compliance in Florida with remote work options. You will oversee end-to-end contract deliverables, including kickoff, planning, testing oversight, reporting, quality management, and closeout across up to 30...Remote jobContract work
- Hitachi Energy is seeking a Cybersecurity Compliance Project Manager in the United States to lead the CFIUS program and align with NSA obligations. You will coordinate with monitoring agencies and translate complex regulatory requirements into practical, scalable processes...
$127.2k - $185k
...operations, and legal teams.We are seeking a high-judgment Sr. Program Manager to lead Fleet Accountability. This role will be instrumental... ...partners, insist on the highest standards for safety and compliance, and demonstrate cross-functional ownership by building long...WorldwideFlexible hoursDay shift- Stripe is building a new function in Global Partnerships (PE&O) to oversee Card Network Compliance. You will develop programs addressing card network changes, ensuring Stripe and its users stay informed and compliant, and drive operational efficiency. In this role you will...Remote job
$135k - $180k
...Select how often (in days) to receive an alert: Job Title: Manager I/II Program Management Job Location: Great River, NY Advanced Acoustic Concepts, LLC, a wholly owned subsidiary Thales Defense & Security Inc., is a technical leader in the fields of sonar systems, sonar...Contract workWork experience placementFor subcontractorImmediate startRemote work- ...Job Posting: Program Manager – Atlantic City International Airport (ACY) BOS Security, Inc. Location: Atlantic City, NJ (On-site) About BOS Security BOS Security is... ...Manage operational performance, quality, and compliance. Lead, supervise, train, and evaluate screening...Contract workFor contractors
$140k - $215k
...changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on... ...starts with you.About the Role:We're investing in program managers who are energetic, eager to learn, flexible and capable of managing...Full timeWork experience placementWork at officeLocal areaWorldwideFlexible hours2 days per week- ...Health insurance Paid time off Vision insurance Regulatory Program Manager SRE Engineering is seeking a Regulatory Program Manager to support... ...framework governing the site. What you'll do Ensure ongoing compliance with applicable Judicial, Federal, or State consent decrees,...
- Bugcrowd is seeking a versatile security technical program manager to drive keystone programs and ensure the engineering team remains on a path of success. You will drive multiple programs, foster accountability, and enable engineering to own security across the company...Remote job
- ...Miratech is seeking a seasoned Project Manager to lead the Compliance and Security workstream within a telecom transformation program. You will coordinate SOC 2, ISO/IEC 27001, GDPR, and related readiness activities across multiple teams to deliver structured execution...
$125k - $140k
...access control, video surveillance, and identity management. What makes us exceptional is our end-to-end approach to Managed Security as a Service. Because we engineer, install,... ...learn more about our solutions. Pre-Sales Program Manager, you are the single point of...Contract workFor subcontractor$143k - $210k
...more at .What You’ll Do:The Data Center Security organization at CoreWeave is responsible... ...environments through scalable physical security programs, operational rigor, and strong cross-... ...Security Business Operations Program Manager, you will own the financial, contractual...Permanent employmentFull timeContract workTemporary workFor contractorsCasual workWork at officeFlexible hours$163.6k - $221.3k
...businesses at Amazon — and the GPS (Guidance, Personalization, and Security) team is at the center of how advertisers experience it. Join... ..., vendors, and offsite advertisers. As a Sr. Technical Program Manager on GPS, you will drive programs that directly shape how millions...WorldwideFlexible hours- The City of New York seeks a Community Coordinator to ensure contracted programs meet DYCD requirements, conducting site visits across NYC and NYS while producing detailed reports on program performance. The role requires interpreting complex contracts, coordinating with...Contract workWork at office
- Advanced Acoustic Concepts LLC, a Thales Defense & Security subsidiary, seeks a Manager I/II Program Management in Great River, NY. Lead programs from planning to execution, ensuring cost, schedule, and performance success while pursuing new business opportunities. You...
- ...offering more than 180integrated programs in: Education & Youth... ...Yorkers today. Position: Program Manager Reports To: Program Director... ...Federal, State, City and CAMBA security and privacy polices intended... ...program files are kept in compliance with CAMBA’s and funder’s standards...Full timeContract workLive inImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Compliance Program Manager. Be the first to apply!
- security engineering manager New York, NY
- cloud security manager New York, NY
- corporate security manager New York, NY
- program manager with security clearance New York, NY
- facilities security manager New York, NY
- surveillance manager New York, NY
- data security manager New York, NY
- security systems manager New York, NY
- director global security New York, NY
- security operations manager New York, NY


