Government Compliance Program Manager
Medical Information Technology, Inc · Canton · United States · Hybrid
Pay: USD 70,200 – 90,000 a year
Posted Oct 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Apply
Job Type
Full-time
Description
As a Government Compliance Program Manager, you will be heavily involved in preparing our SaaS product and cloud operations for ITSG-33 and FedRAMP authorizations, as well as maintaining our broader data protection and privacy standards. Working under the direction of security leadership, you will serve as the operational bridge between technical teams and regulatory frameworks—writing security documentation, mapping control implementations, tracking remediation items, and facilitating auditor requests. As a member of our Cloud Services team, your job would involve:
Authoring, updating, and maintaining core government compliance packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), and supporting policy documents
Mapping operational controls across NIST SP 800-53 and CCCS Medium Cloud Profile to ensure clear alignment with engineering and IT workflows
Tracking control coverage and document evidence for identity management, access control, encryption standards, and monitoring routines
Coordinating day-to-day operations during third-party assessment (3PAOs) and government audits
Managing and updating the Plan of Action and Milestones (POA&M) register—working directly with Cloud/DevOps and Engineering teams to ensure timely remediation of vulnerabilities and findings
Collecting, organizing, and validating audit evidence to ensure smooth assessment lifecycles
Supporting the execution of the Continuous Monitoring program, including organizing monthly scan reviews, vulnerability logs, and quarterly deliverable packages
Assisting in conducting internal assessments, vendor risk evaluations, and data protection reviews for GDP/privacy compliance
Monitoring updates to federal standards (NIST, CCCS) and highlighting necessary operational updates to security leadership.
Requirements
Experience: 3+ years in Information Security, IT Compliance, or GRC, with direct experience participating in FedRAMP or ITSG-33 Protected B compliance efforts
Framework Knowledge: Practical understanding of NIST SP 800-53 controls and how they are implemented within cloud infrastructure (AWS GovCloud, Azure Government, or GCP)
Familiarity with general cloud architecture concepts, IAM, FIPS-compliant encryption, SIEM/logging platforms, and vulnerability management tools
Hands-on Artifact Creation: Demonstrated experience writing or maintaining compliance artifacts (SSPs, POA&Ms, Incident Response Plans)
Project Tracking: Strong organizational skills with experience tracking complex cross-functional deliverables across software and IT teams
Strong written communication skills—able to clearly explain technical controls in formal regulatory language
Collaborating effectively with software engineers, system admins, and external auditors
Certifications: CISA, CRISC, CISM, CAP/CGRC, or Security+ preferred
Clearance Eligibility: Ability to obtain or hold government security…