Grc Program Manager, US Government Compliance

OpenAI OpenAI · AI Frontier · Washington, DC · Security

Program Manager responsible for obtaining and maintaining US Government Authorizations to Operate (ATOs) and compliance with frameworks like FedRAMP for OpenAI products in highly regulated and secure environments. Requires deep understanding of USG security frameworks, technical program management, and collaboration with engineering teams.

What you'd actually do

  1. Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.
  2. Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
  3. Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
  4. Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
  5. Continuously refine processes to improve the efficiency and quality of compliance efforts.

Skills

Required

  • Technical program management
  • NIST
  • RMF
  • FedRAMP
  • System Security Plans (SSPs)
  • risk assessments
  • architecture diagrams
  • audits and assessments

Nice to have

  • Active US security clearance
  • Cloud platforms (Azure, AWS)
  • Kubernetes
  • Terraform
  • Authentication
  • Encryption
  • Vulnerability management
  • Audit logging
  • Cross-functional team collaboration
  • Navigating ambiguity

What the JD emphasized

  • Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.
  • A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).
  • An active US security clearance.