Security Compliance Program Manager
$100kKaizen
Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services. Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service. Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year. Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back. The Role Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function to own the obligations, the paperwork of record, and the accuracy of everything we submit. You will build and run that function, working directly with the engineering lead, the incoming security engineer, and the executive team. Location New York, NY or Washington, D.C. (Hybrid). This is the permanent version of the role. We are also posting a contract equivalent for the same scope. The differences are that this one carries the authorization program long term, including the path from Moderate to High, and a path to holding the FSO designation yourself. The Programs FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. The change-control side of an authorization matters here as much as the initial package. You own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor. You also own the significant-change process, which is the mechanism that makes the model work. DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer’s or a partner's. This role owns knowing the reciprocity map cold, reading a hosting platform’s actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary. Reciprocity is inconsistent, so it has to be verified per agency rather than assumed. CMMC. A separate track from the product, and keeping the two separate is part of the job: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You run the self-assessment against NIST 800-171 Rev 2, own a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior‑official affirmation on schedule, and own the POA&M entries. You drive the scoping decision, which is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident‑reporting clauses matters here. What You'll Do Own the POA&M end to end: keep it current, submit it to our hosting partner on the contractual cadence, and make sure what gets signed is accurate Run NIST 800-171 self-assessment workbooks to completion, maintain the SPRS score, and drive remediation items in priority order through to close Manage all federal contract and agency paperwork: DD Form 254, DD Form 2345, JCP registration, PIEE and SPRS portal administration, SAM.gov, agency security questionnaires, and DFARS security clause flowdowns Track every live contractual SLA, from incident notification through periodic reviews and annual affirmations, and prove we met them Own the obligation register. Read every federal contract and subcontract for what it actually binds us to, including FAR and DFARS flowdowns, and run the register that tracks it. This reaches well past security into employee notices, required training, prohibited technology, EEO and labor reporting, OCI, and business ethics. Much of it gets executed by People Ops, legal or IT, but one person has to hold the map Sit in on new federal contracts and subcontracts before signature and flag what we are agreeing to Build and maintain the control-to-evidence mapping so any control's status is a two-minute answer instead of an archaeology dig through tickets Own personnel security operations: US-person verification, background screening at federal-aligned tiers, onboarding and offboarding access controls, and quarterly access reviews Lead FCL readiness: FSO vendor selection, key personnel clearance sequencing, SF 328 disclosures, and NISS submission when sponsorship lands, with a path to holding the FSO designation yourself What You'll Bring Direct experience submitting in federal portals, SPRS and PIEE specifically. "Supported" and "submitted" are different things Has run a NIST 800-171 self‑assessment or RMF package end to end, with personal accountability for the outcome Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it Hands‑on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor Current on FedRAMP as it exists in 2026, and fluent in 20x specifically. Certification Classes, Key Security Indicators, machine‑readable packages, continuous validation. We are building on 20x, so experience that stops at Rev 5 documentation will be working against the grain here Knows where Rev 5 still binds. High remains a Rev 5 process and new Rev 5 certifications stop in June 2027. Knowing which parts of a roadmap that constrains is more useful to us than depth in either framework alone Can reason about a shared authorization boundary: which controls are inherited, which are shared, which stay application‑specific, and what kind of change triggers a significant‑change request Working knowledge of the DoD Cloud Computing SRG and how Impact Levels sit on FedRAMP baselines. The CSP and Mission Owner split matters here, and so does reading a hosting platform's ATO coverage against the agency doing the buying Has worked opposite a 3PAO or independent assessor on evidence requests and knows what they accept in practice Can read a contract for FAR and DFARS flowdowns and turn them into a tracked obligation register. If you have run a subcontract flowdown matrix, say so Background in federal or defense contracting (agency‑side, prime, or sub) where you owned a compliance function rather than a slice of one Has been the only compliance person at an organization; you know how to close a loop without a team behind you US person, eligible for a Tier 3 background investigation; DC‑based or NYC‑based with regular in‑office presence An active or recently held clearance is a meaningful accelerant. Existing investigations don't convert, and a Tier 3 takes roughly five months Strong Candidates May Also... Have owned a FedRAMP authorization through to completion, on the provider or the assessor side. This is the most valuable thing on this list and it moves our offer Have written OSCAL by hand, or stood up a trust center against live control indicators Bring a military background in security, intelligence, or information security (unit security manager, SSO, S2/G2, cyber operations, or similar) Hold a CMMC CCP or RP, or have direct experience with eMASS, Xacta, Paramify, or equivalent GRC tools in a federal context Know the GovRAMP reciprocity path into FedRAMP Class A Come from a GovTech or SaaS company actively pursuing FedRAMP or CMMC, rather than one that already holds it Don't Apply If... Your compliance background is in financial services, insurance, or telecom. Large‑team GRC with no federal exposure doesn't transfer here You've assessed federal compliance programs but never owned one. Assessing a program and being accountable for it are different jobs Your first instinct when asked about our SPRS score is to open a platform and run a report rather than know the number and the story behind it You need a clean program to walk into. Your first 90 days are inventory, triage, and unglamorous paperwork Owning a high‑side authorization end to end is what you want as your next move. The near‑term scope here is the base authorization and the operating machinery around it Accuracy under commercial pressure is negotiable for you. What we submit carries real legal exposure, and holding the truthful answer is the job What Kaizen Offers Health & Insurance 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam — all fully covered for employees, with 100% coverage for dependents. $100,000 in fully paid life insurance. FSA and Dependent Care FSA. One Medical membership, on us — same‑day primary care, 24/7 virtual visits, and offices all over the city. Fertility and family‑building support through Carrot. 401(k) through Guideline, with a 2% company match. Family & Time Off 16 weeks of fully paid parental leave for birthing parents. 10 weeks fully paid for non‑birthing parents. Unlimited PTO, with a two‑week minimum (we mean it when we say take time off!) Closed for all federal holidays. Company‑wide winter break the week of Christmas. Company offsites throughout the year. Office & Remote Setup Up to $750 one‑time home office or desk setup stipend for NYC‑based employees. $500 for remote employees. $50/month commuter benefit (company contribution). Expensed lunch while in the office. Company‑provided laptop of your choice. Wellness Fully covered gym membership at Grindhouse — right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement. Stipends
- 100/month utility stipend.
- 500/year professional development.
- 250/year recreation.
- 300/quarter pet care stipend.
$162k - $310k
About the TeamGovernance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building... ...high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government...SuggestedWork at officeLocal areaRelocation packageFlexible hours$86.45k - $136k
...effective nuclear solutions for global security, clean energy, environmental... ...environmental restoration and operations management at a dozen U.S. Department of Energy... ...difference. Position Overview: The Compliance Audit Program Manager serves as a key liaison for...SuggestedContract workFor contractorsWork at officeLocal areaHome officeFlexible hours$109.44k - $244.8k
...the Trust & Safety Regulatory Compliance team to partner with... ...responsibility for programme management and the ongoing monitoring of... ...regulatory obligations. As Program Manager, you will manage large... ...other regulatory interactions, securing contributions and reviews from...SuggestedTemporary work- Apogee Engineering, LLC is seeking a Program Manager to support the Headquarters United States Air Force (HAF/A10) in Arlington, VA. You will provide programmatic expertise for national security initiatives and manage Contractor performance at the Pentagon. The ideal candidate...SuggestedFull timeContract workFor contractors
- JOB SUMMARY: The Sr. Director, Global Information Security (GIS) Compliance Program is a key member of the GIS leadership team responsible for the... ...projects needed to maintain compliance. This includes the management testing of the Information Security Program, monitoring...SuggestedFull timeRemote workFlexible hours
- CACI International Inc. seeks a Program Manager to lead a large-scale IT operations program for the U.S. Department of State Bureau of Diplomatic Security. The role oversees service desk, network engineering, cloud operations, cybersecurity, and enterprise applications...Work at office
- DANE LLC is seeking an experienced Program Support Manager (PSM) to lead all operations under the Passport Headquarters Program Support Services contract. The PSM will serve as the senior on-site leader with full authority to manage personnel, performance, and daily operations...Contract work
- ...collection enable engineering, safety, and security teams to stay ahead of evolving threats and deploy AI systems safely. Compliance Manager About The Role We're seeking a... ...improve our security and privacy compliance programs. This individual will serve as the operational...
$113k - $188k
...You Will Do:Lead teams and growth within Guidehouse's Defense and Security Segment with a specific focus on our IC clientsHave on the ground presences and leadership over teams delivering program management, financial management, and operational effectiveness support to...Full timeContract workFlexible hours- ...seeks a senior technical authority for CJIS compliance and cybersecurity governance within the... ...across enterprise systems and manage audits, risk, and policy enforcement to... ...bring at least one year of specialized CJIS security experience, with strong leadership, communication...Work at office
- Job TitleSenior Program ManagerLocationWashington, DC 20032 US (Primary)CategoryIntelligenceJob... ...'s DegreeTravel-Security Clearance RequiredTS/SCI with CI PolygraphJob... ...analysis of analytic operations and knowledge management issues across organizational and intra-IC...Contract work
- ...and trusted results to enable national security missions worldwide.Job Description**This... ...**SOSi is seeking a highly qualified Program Manager to support an Intelligence government customer... ...activities across the spectrum.Ensure compliance with all contract requirements and...Contract workFor contractorsWork at officeWorldwideMonday to Friday
- ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and... ...technology. We are seeking highly qualified candidates for a Program Manager role supporting SPA's clients within Naval Sea Systems Command...Contract workFor subcontractorLocal areaFlexible hours
$200k
Ignite Digital enables national security agencies to accelerate... ...industrySupportive colleagues and management who invest in your... ...experienced and highly skilled Program Manager (PM) to lead contractor... ...work products for accuracy and compliance, and ensure high-quality...Permanent employmentContract workFor contractorsLocal area$180k - $240k
Celestar, a B&A Company, is seeking a Program Manager to support the Defense Advanced Research Projects Agency (DARPA) Program Security Services (PSS) task order. If interested and meet the qualifications, we encourage you to apply for this rewarding and impactful opportunity...Contract workLocal area- ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and... ...the future.We have a near-term need for a Irregular Warfare Program Manager to provide onsite support out of the Pentagon.ResponsibilitiesThe...Work at officeFlexible hours
- DescriptionThe Program Manager / Senior Strategic Advisor (Homeland Defense) serves as the senior representative and primary point... ...satisfaction and continuously improve service delivery.Ensure compliance with security, operational, and contractual requirements.Reporting and...Contract workFor contractorsWork at officeLocal areaImmediate startFlexible hours
$174k - $210k
The Program Manager will lead and oversee a Cybersecurity/Security Operations Center (SOC) program, ensuring the delivery of mission-critical cybersecurity services... ...or international law.What we want you to know:In compliance with federal law, all persons hired will be...Full timeLocal area- DescriptionPosition SummaryRed Gate is seeking a Program Manager to be responsible for leading the... ...mitigate program risks while ensuring compliance with contract requirements and quality... ...a fast-paced environment.Active Secret security clearance.Company DescriptionThe Red...Contract workFor contractorsFor subcontractorLocal areaImmediate startFlexible hours
- Job TitleProgram Manager Level 5LocationWashington, DC 20032 US (Primary)CategoryResearch, Development... ...LevelStaffEducationBachelor's DegreeTravel-Security Clearance RequiredTS/SCIJob DescriptionPrescient Edge is seeking a Program Manager Level 5 to support a federal...Contract work
- ...technical solutions to complex national security issues. With over 50 years of business expertise... ...provides analytical, technical, and program support to promote, grow, and protect... ...have an upcoming need for a Sr. Program Manager to provide onsite support out of the...Contract workFor subcontractorWork at officeFlexible hours
$131.3k - $237.35k
...expertise to customers in the national security, engineering, and health industries. We... ...OpportunityLeidos is seeking an experienced Program Manager to lead execution of a complex, mission... ...to achieve customer objectives.Risk, Compliance & Acquisition SupportLead program risk...Full timeContract workFor contractorsFor subcontractor$185k - $210k
...insights that strengthen U.S. national security and intelligence, support disaster response... ...here at Umbra.About the JobAs a Senior Program Manager at Umbra, you will lead a portfolio of... ....Employment Eligibility VerificationIn compliance with federal laws, all hired persons...Permanent employmentFull timeContract workWork at officeLocal areaRemote workWorldwide$182.8k - $223.5k
Title:Program ManagerBelong. Connect. Grow. with KBR!KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers... ..., logistics, operations, science, program management, mission IT and cybersecurity solutions....Full timeContract workTemporary workFor contractorsFor subcontractorLocal areaRelocation packageFlexible hours- ...solutions, tested leadership, and trusted results to enable national security missions worldwide.Job Description*** This position is contingent upon contract award ***OverviewSOSi is seeking a Senior Program Manager to support a cybersecurity program aligned to our customer....Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$142.73k - $237.88k
...thinking organization, apply now.We are currently seeking a Senior Program Manager to join our team in Washington, District of Columbia (US-DC),... ...a Public Trust clearance. Preferred QualificationsSecret security clearanceAble to work onsite in Washington, DCNTT DATA...Temporary workWork at officeRemote workFlexible hours- Overview Amyx is seeking to hire a Sr. Program Manager to support our Department of Homeland Security, CISA contract in the Washington DC area. Responsibilities The Sr. Program Manager shall provide support to the development and conduct of multiple supporting...Full timeContract workFor contractorsFlexible hours
$120k - $180k
Job TitleSenior Program ManagerLocationBethesda, MD 20800 US (Primary)CategoryResearch,... ...LevelStaffEducationBachelor's DegreeTravel-Security Clearance RequiredSecretJob... ...DescriptionPrescient Edge is seeking a Senior Program Manager to support a Federal Government client....- DescriptionActioNet has an opportunity for a Program Manager requiring a Public Trust clearance in the Washington D.C. metro area. Hybrid... ...expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 26+ years of stellar past...Full timeContract workFlexible hours
- ...a contingent opportunityProgram Manager (CISA HSEEP)K2 Group is seeking a Program Manager (PM) to serve as the senior... ...Cybersecurity and Infrastructure Security Agency (CISA) Infrastructure... ...growth strategies while ensuring full compliance with federal acquisition...Contract workFor contractorsLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Compliance Program Manager. Be the first to apply!
- security engineering manager Washington DC
- corporate security manager Washington DC
- program manager with security clearance Washington DC
- surveillance manager Washington DC
- security systems manager Washington DC
- director global security Washington DC
- security operations manager Washington DC
- director information security Washington DC
- physical security manager Washington DC
- security manager Washington DC


