Program Manager, Public Sector Compliance

MongoDB MongoDB · Enterprise · New York, NY · Remote · Govt Risk Compliance (GRC)

This role is for a Program Manager / Senior Analyst focused on Public Sector Compliance for MongoDB's Atlas for Government product. It involves managing federal authorizations like FedRAMP High, DoD IL5+, CJIS, and ITAR, interpreting NIST 800-53 controls, and translating them into technical requirements for engineering teams. The role leads federal assessments, continuous monitoring, and artifact reviews, acting as a technical advisor to ensure cloud configurations meet mandates. It also supports federal sales by acting as a subject matter expert during security reviews and explaining compliance posture. The role requires 5+ years in GRC, Technical Writing, or IT Audit with a focus on US Public Sector frameworks and a deep understanding of NIST controls within cloud architectures. US Citizenship is required.

What you'd actually do

  1. Lead the end-to-end execution of federal assessments, coordinating with Third Party Assessment Organizations (3PAOs), agency sponsors, and the FedRAMP PMO
  2. Manage the federal continuous monitoring (ConMon) program, including the timely analysis and reporting of vulnerabilities and the maintenance of the POA&M
  3. Lead the annual update and technical review of core FedRAMP artifacts, including the System Security Plan (SSP), Contingency Plan (ISCP), and Incident Response Plan (IRP)
  4. Act as a technical advisor to Engineering and Operations teams to ensure cloud configurations (e.g., FIPS 140-2/140-3, boundary protection, and access control) meet federal and DoD IL5+ mandates
  5. Perform deep-dive gap analyses for new public sector requirements (such as CMMC or GovRAMP) and define the roadmap for technical remediation

Skills

Required

  • 5+ years in GRC, Technical Writing, or IT Audit
  • US Public Sector frameworks (FedRAMP, DoD SRG, CJIS)
  • NIST 800-53
  • NIST 800-171
  • cloud architectures (AWS, GCP, or Azure)
  • managing federal audits from kickoff through to the issuance of an Authorization to Operate (ATO)
  • explain complex security configurations to government auditors and internal technical teams
  • Jira
  • Confluence

Nice to have

  • CMMC
  • GovRAMP

What the JD emphasized

  • US government authorizations
  • FedRAMP High
  • DoD IL5+
  • CJIS
  • ITAR
  • NIST 800-53
  • US Citizenship is required