yandex
onebrief
Страна
США
Зарплата
170 000 $ – 230 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
УдалённоПолная занятость

Technical Program Manager, Governance Risk & Compliance - Platform

Оценка ИИ

Высокая оценка обусловлена статусом компании-единорога ($2.15B) и критической важностью продукта. Работа полностью удаленная, но требует специфических допусков, что ограничивает круг кандидатов, но повышает ценность позиции.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует редкого сочетания глубоких знаний федеральных стандартов безопасности США (FedRAMP, DoD IL5/6) и навыков управления техническими программами в облачных средах. Высокая сложность обусловлена необходимостью наличия допуска к секретной информации (Secret Clearance) и сертификаций уровня CISSP/PMP.

Анализ зарплаты

Медиана195 000 $
Рынок170 000 $ – 230 000 $
Оценка ИИ

Указанный диапазон соответствует рыночным ставкам для Senior/Lead TPM в сфере кибербезопасности в США, особенно для компаний, работающих с оборонным сектором (GovTech). Учитывая стадию роста компании (Series C+) и требования к допуску, компенсация может включать значительный пакет опционов.

Сопроводительное письмо

I am writing to express my strong interest in the Technical Program Manager (GRC) position at Onebrief. With over 8 years of experience in cybersecurity and a proven track record of managing complex compliance frameworks such as FedRAMP High and NIST RMF, I am confident in my ability to accelerate Onebrief’s authorization efforts while maintaining engineering velocity. My background combines deep technical understanding of AWS cloud-native environments with the strategic oversight required to manage POA&Ms and Security Control Assessments.

Throughout my career, I have successfully bridged the gap between rigorous federal security requirements and modern DevSecOps workflows. I am particularly drawn to Onebrief’s mission of empowering military staffs through AI-powered collaboration software. Having worked extensively with eMASS and coordinated with 3PAOs, I understand that GRC is a continuous operational discipline. I am eager to bring my expertise in risk management and cross-functional leadership to your Infrastructure & Security team to ensure Onebrief remains the gold standard for secure military technology.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в onebrief уже сейчас

Присоединяйтесь к Onebrief, чтобы возглавить критически важные программы безопасности для оборонного сектора США!

Описание вакансии

About Onebrief

Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. By transforming this work, Onebrief makes the staff as a whole superhuman - meaning faster, smarter, and more efficient.

We take ownership, seek excellence, and play to win with the seriousness and camaraderie of an Olympic team. Onebrief operates as an all-remote company, though many of our employees work alongside our customers at military commands around the world.

Founded in 2019 by a group of experienced planners, today, Onebrief’s team spans veterans from all forces and global organizations, and technologists from leading-edge software companies. We’ve raised $320m+ from top-tier investors, including Battery Ventures, General Catalyst, Sapphire Ventures, Insight Partners, and Human Capital, and today, Onebrief is valued at $2.15B. With this continued growth, Onebrief is able to make an impact where it matters most.

About the Role

We are seeking an experienced Technical Program Manager with a strong background in cybersecurity, cloud governance, and compliance to lead Onebrief’s governance, risk, and compliance efforts. This role is pivotal in maintaining and scaling our security posture across regulated environments (FedRAMP, DoD IL5/6, JWICS, NIST RMF) while supporting fast-moving product development.

You will work cross-functionally with security engineers, infrastructure engineers, product engineers, product teams, and executive leadership to operationalize security frameworks, manage risk, and guide the organization through audit and authorization processes. This is a highly collaborative and strategic role with an emphasis on program execution and continual improvement.

About You

You are a technically fluent program management leader with deep experience supporting federal cybersecurity compliance efforts. You understand both the structure of frameworks like NIST SP 800-53 and the operational realities of engineering teams.

You excel at translating compliance requirements into clear execution plans, measurable milestones, and cross-team deliverables. You are organized, proactive, and comfortable driving accountability across stakeholders. Most importantly, you understand that GRC is a continuous operational discipline — not a one-time audit event.

What You’ll Do

  • Accelerate Onebrief’s execution of GRC programs supporting NIST RMF, FedRAMP High, CMMC, and SOC2 authorizations
  • Develop and manage integrated project plans for control implementation, remediation, and continuous monitoring
  • Coordinate cross-functional teams (Infrastructure, Engineering, Product) to ensure timely delivery of compliance requirements
  • Track control implementation status, POA&Ms, and remediation efforts to closure
  • Support preparation and coordination of Security Control Assessments (SCAs), 3PAOs, and Federal Customer audits
  • Coordinate and track development of SSP updates, control narratives, and authorization artifacts in partnership with GRC Architects
  • Track risk assessment outputs and ensure identified risks are translated into actionable remediation plans
  • Drive the implementation of secure CI/CD practices that meet evolving compliance requirements without blocking velocity.
  • Support the development and operationalization of scalable governance processes defined by GRC leadership
  • Ensure configuration management, vulnerability management, and change control activities align with compliance requirements
  • Identify program risks, dependencies, and blockers, and proactively escalate when necessary
  • Coach teams on security best practices and contribute to a culture of secure product development.

What We Look For

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field
  • 8+ years of experience in cybersecurity, compliance, or technical program management roles
  • Demonstrated experience supporting systems under NIST RMF, FedRAMP, or DoD RMF
  • Experience managing cross-functional technical programs in cloud-native environments and technologies
  • Familiarity with eMASS or similar authorization management systems
  • Experience maintaining or coordinating SSPs, POA&Ms, and authorization packages
  • Strong understanding of:

+ AWS Cloud Technologies

+ NIST SP 800-53 control families

+ Risk management and continuous monitoring practices

+ CI/CD and modern DevSecOps workflows

  • Experience supporting Security Control Assessments or 3PAO audits

Certifications (one or more required)

  • CISSP
  • CISM
  • CGRC
  • PMP or equivalent program management certification
  • Security+ or equivalent

Must-Have Skills and Qualifications

  • Proven ability to drive complex, compliance-focused technical programs across multiple stakeholders
  • Experience operating within DoD or federal compliance frameworks (e.g., RMF, FedRAMP)
  • Experience supporting Security Control Assessments, external audits, and Federal Customers
  • Experience managing POA&Ms and remediation efforts in dynamic, cloud-based environments
  • Excellent communication skills with the ability to brief engineers, leadership, and federal stakeholders
  • Secret Clearance, TS/SCI Eligible

Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Cybersecurity
  • AWS
  • Risk Management
  • FedRAMP
  • CI/CD
  • CISSP
  • CISM
  • NIST SP 800-53
  • DevSecOps
  • PMP
  • eMASS
  • NIST RMF
  • Governance, Risk and Compliance (GRC)

Возможные вопросы на собеседовании

Проверка практического опыта работы с ключевым процессом управления рисками в федеральных системах.

Опишите ваш опыт управления процессом POA&M (Plan of Action and Milestones): как вы приоритизируете задачи и обеспечиваете их закрытие в срок?

Важно понять, как кандидат находит баланс между безопасностью и скоростью разработки.

Как вы внедряете требования NIST 800-53 в CI/CD пайплайны, не блокируя при этом работу инженеров и скорость выпуска продукта?

Оценка опыта взаимодействия с внешними аудиторами и государственными заказчиками.

Расскажите о самом сложном аудите 3PAO или проверке со стороны государственного заказчика, которым вы руководили. Какие возникли трудности и как вы их преодолели?

Проверка технических знаний облачной инфраструктуры в контексте комплаенса.

Какие специфические сервисы AWS вы использовали для обеспечения непрерывного мониторинга (Continuous Monitoring) в рамках FedRAMP High?

Оценка лидерских качеств и умения работать с кросс-функциональными командами.

Как вы транслируете сложные нормативные требования (например, из NIST RMF) в понятные технические задачи для команд разработки и инфраструктуры?

Похожие вакансии

Сбербанк
Не указана

Руководитель направления SberUp

УдалённоРоссия
Project Management · Venture Capital · Startups · Artificial Intelligence · Business Development · Innovation Management
+6 навыков
oscar
105 808 $ – 138 886 $

UM Program Operations Manager

УдалённоГрузия
Program Management · Project Management · Prior Authorization · Utilization Management · SOP Development · Compliance · Data Analysis · Stakeholder Management · PMP · Lean Six Sigma
+10 навыков
axon
128 700 CA$ – 205 920 CA$

Deployment Program Manager - Enterprise

SeniorУдалённоКанада
SaaS · Program Management · PMP · Change Management · Technical Project Management · Stakeholder Management · Budget Control · Risk Management · English · French
+10 навыков
netradyne
110 000 $ – 150 000 $

Senior Customer Success Manager / Program Manager – Amazon Relay Rewards (US)

SeniorУдалённоСША
Customer Success · Program Management · Project Management · SaaS · Logistics · Enterprise Account Management · Stakeholder Management · Cross-functional Team Leadership
+8 навыков
splashfinancial
143 000 $ – 200 000 $

Senior Technical Program Manager

SeniorУдалённоСША
Jira · Asana · Confluence · Agile · Kanban · ProductBoard · Aha! · Jira Align · SDLC · Program Management · Fintech
+11 навыков
reddit
180 200 $ – 252 300 $

Senior Program Manager, Go-To-Market Systems

SeniorУдалённоСША
CRM · Marketing Automation · CPQ · Program Management · Digital Advertising · Sales Operations · Project Management · Analytics
+8 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

onebrief
Страна
США
Зарплата
170 000 $ – 230 000 $