Senior Security Program Manager | Public Sector

Ramp Ramp · Fintech · New York, NY · Security

This role is for a Senior Security Program Manager focused on public sector compliance, specifically FedRAMP and GovRAMP. It involves leading compliance lifecycle, cross-functional program management, developing security documentation, monitoring controls, engaging with assessors, and providing risk-informed recommendations. Requires 5+ years in information security/compliance with government frameworks and knowledge of NIST SP 800-53.

What you'd actually do

  1. Lead all aspects of the compliance lifecycle across multiple public sector frameworks (e.g., FedRAMP, GovRAMP), including risk assessments, continuous monitoring, audits, and authorization management
  2. Drive complex cross-functional program management efforts involving teams across security, legal, engineering, infrastructure, and product functions.
  3. Serve as a subject matter expert on risk management and regulatory compliance for federal, state, and local government environments.
  4. Develop and maintain comprehensive security documentation aligned with applicable frameworks, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and data flow diagrams.
  5. Monitor compliance with control requirements (e.g., NIST 800-53, GovRAMP Baselines) and coordinate the implementation of technical and procedural safeguards.

Skills

Required

  • 5+ years of experience in information security or compliance
  • Focus on government and public sector regulatory frameworks (e.g., FedRAMP, GovRAMP, FISMA, NIST RMF)
  • Knowledge of NIST SP 800-53
  • Experience mapping controls across frameworks
  • Experience with cloud environments like AWS GovCloud or Azure Government
  • Proven ability to manage large-scale compliance programs across diverse stakeholder groups
  • Demonstrated success developing and maintaining regulatory documentation and audit evidence
  • Experience leading engagements with internal teams, assessors, and government partners
  • Strong written and verbal communication skills
  • Excellent organizational skills
  • Self-starter with strong problem-solving abilities

Nice to have

  • CISSP
  • CISA
  • CRISC
  • CCAK
  • CGRC
  • Experience with automation platforms for GRC and security monitoring (e.g., Wiz, Paramify)
  • Familiarity with other public sector compliance programs (CJIS, IRS 1075, DoD IL5, etc.)
  • Experience supporting product or infrastructure teams through ATO processes
  • Experience with FedRAMP 20x initiatives
  • Leadership experience or management of small security/GRC teams

What the JD emphasized

  • FedRAMP
  • GovRAMP
  • NIST 800-53
  • risk management
  • regulatory compliance