Technical Program Manager, Governance Risk & Compliance - Platform @Onebrief
Project Management
Salary usd 205,000 - 2..
Remote Location
🇺🇸 USA Only
Job Type full-time
Posted 5d ago

[Hiring] Technical Program Manager, Governance Risk & Compliance - Platform @Onebrief

5d ago - Onebrief is hiring a remote Technical Program Manager, Governance Risk & Compliance - Platform. 💸 Salary: usd 205,000 - 230,000 per year 📍Location: USA

Role Description

We are seeking an experienced Technical Program Manager with a strong background in cybersecurity, cloud governance, and compliance to lead Onebrief’s governance, risk, and compliance efforts. This role is pivotal in maintaining and scaling our security posture across regulated environments (FedRAMP, DoD IL5/6, JWICS, NIST RMF) while supporting fast-moving product development.

You will work cross-functionally with security engineers, infrastructure engineers, product engineers, product teams, and executive leadership to:

  • Operationalize security frameworks
  • Manage risk
  • Guide the organization through audit and authorization processes

This is a highly collaborative and strategic role with an emphasis on program execution and continual improvement.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field
  • 8+ years of experience in cybersecurity, compliance, or technical program management roles
  • Demonstrated experience supporting systems under NIST RMF, FedRAMP, or DoD RMF
  • Experience managing cross-functional technical programs in cloud-native environments and technologies
  • Familiarity with eMASS or similar authorization management systems
  • Experience maintaining or coordinating SSPs, POA&Ms, and authorization packages
  • Strong understanding of:
    • AWS Cloud Technologies
    • NIST SP 800-53 control families
    • Risk management and continuous monitoring practices
    • CI/CD and modern DevSecOps workflows
  • Experience supporting Security Control Assessments or 3PAO audits
  • Certifications (one or more required):
    • CISSP
    • CISM
    • CGRC
    • PMP or equivalent program management certification
    • Security+ or equivalent

Requirements

  • Proven ability to drive complex, compliance-focused technical programs across multiple stakeholders
  • Experience operating within DoD or federal compliance frameworks (e.g., RMF, FedRAMP)
  • Experience supporting Security Control Assessments, external audits, and Federal Customers
  • Experience managing POA&Ms and remediation efforts in dynamic, cloud-based environments
  • Excellent communication skills with the ability to brief engineers, leadership, and federal stakeholders
  • Secret Clearance, TS/SCI Eligible

What You’ll Do

  • Accelerate Onebrief’s execution of GRC programs supporting NIST RMF, FedRAMP High, CMMC, and SOC2 authorizations
  • Develop and manage integrated project plans for control implementation, remediation, and continuous monitoring
  • Coordinate cross-functional teams (Infrastructure, Engineering, Product) to ensure timely delivery of compliance requirements
  • Track control implementation status, POA&Ms, and remediation efforts to closure
  • Support preparation and coordination of Security Control Assessments (SCAs), 3PAOs, and Federal Customer audits
  • Coordinate and track development of SSP updates, control narratives, and authorization artifacts in partnership with GRC Architects
  • Track risk assessment outputs and ensure identified risks are translated into actionable remediation plans
  • Drive the implementation of secure CI/CD practices that meet evolving compliance requirements without blocking velocity
  • Support the development and operationalization of scalable governance processes defined by GRC leadership
  • Ensure configuration management, vulnerability management, and change control activities align with compliance requirements
  • Identify program risks, dependencies, and blockers, and proactively escalate when necessary
  • Coach teams on security best practices and contribute to a culture of secure product development

Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement, Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

Before You Apply
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Technical Program Manager, Governance Risk & Compliance - Platform @Onebrief
Project Management
Salary usd 205,000 - 2..
Remote Location
🇺🇸 USA Only
Job Type full-time
Posted 5d ago
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Unlock 152,720 Remote Jobs
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Unlock 152,720 Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 152,720+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later