Jobedly Post a Job

Security Compliance Program Manager

kaizenlabs · Remote
RemoteFull-timeEngineeringConstruction$179,000–$241,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Security Compliance Program Manager role

Security Compliance Program Manager positions focus on delivering results in their domain. This page aggregates open Security Compliance Program Manager roles and what employers typically expect.

Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services. Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service. Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year. Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back. THE ROLE Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function to own the obligations, the paperwork of record, and the accuracy of everything we submit. You will build and run that function, working directly with the engineering lead, the incoming security engineer, and the executive team. LOCATION New York, NY or Washington, D.C. (Hybrid). This is the permanent version of the role. We are also posting a contract equivalent for the same scope. The differences are that this one carries the authorization program long term, including the path from Moderate to High, and a path to holding the FSO designation yourself. THE PROGRAMS FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. The change-control side of an authorization matters here as much as the initial package. You own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor. You also own the significant-change process, which is the mechanism that makes the model work. DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer's or a partner's. This role owns knowing the reciprocity map cold, reading a hosting platform's actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary. Reciprocity is inconsistent, so it has to be verified per agency rather than assumed. CMMC. A separate track from the product, and keeping the two separate is part of the job: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You run the self-assessment against NIST 800-171 Rev 2, own a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries. You drive the scoping decision, which is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident-reporting clauses matters here. WHAT YOU'LL DO - Own the POA&M end to end: keep it current, submit it to our hosting partner on the contractual cadence, and make sure what gets signed is accurate - Run NIST 800-171 self-assessment workbooks to completion, maintain the SPRS score, and drive remediation items in priority order through to close - Manage all federal contract and agency paperwork: DD Form 254, DD Form 2345, JCP registra…

Salary estimate

$179,000 – $241,000/yr
Provided by the employer.

Skills for this role

Security

Resume tips for Security Compliance Program Manager applicants

Interview preparation

Prepare concrete STAR-format stories that show Security Compliance Program Manager outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Security Compliance Program Manager problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About kaizenlabs

kaizenlabs is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles