Governance, Risk, and Compliance Manager - FedRAMP

Decagon

• $190K — $275K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of GRC experience in high-growth SaaS or technology companies
  • Proven track record with SOC 2, ISO 27001, or similar certifications
  • Experience in data privacy regulations such as CCPA and GDPR
  • Strong project management skills with a focus on tight deadlines
  • Excellent written and verbal communication skills
  • Working knowledge of technical security controls for collaboration with engineering teams

Responsibilities

  • Drive compliance certifications including SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and CCPA
  • Automate or execute compliance evidence gathering and documentation
  • Maintain and enhance security documentation including policies and customer-facing materials
  • Support customer security assessments and technical inquiries from Fortune 500 security teams
  • Manage security and compliance topics in RFPs, coordinating responses across teams
  • Build and optimize processes to scale GRC operations for numerous enterprise customers
  • Collaborate with security, engineering, and product teams to align compliance with technical controls

Benefits

  • Take what you need vacation policy
  • Medical, Dental, and Vision benefits for you and your family
  • Life Insurance and Disability Benefits
  • Retirement Plan (e.g., 401K, pension)
  • Parental Leave
  • Fertility and family building benefits through Carrot
  • Daily lunches and snacks in the office
Full Job Description
About the Role

Join Decagon as a Governance, Risk, and Compliance Manager and play a critical role in securing customer trust as we scale to serve Fortune 500 and international enterprises. Working closely with the head of security and compliance, you'll be responsible for the day-to-day execution of our compliance program and customer security engagements. This is a high-impact role where you'll directly contribute to closing enterprise deals by efficiently managing security communications with customers, supporting compliance audits, and improving our security documentation. Perfect for someone who thrives in a high impact organization with attention to detail, excellent writing skills, and who wants to build expertise in enterprise AI compliance.

In this role, you will
  • Own our route to FedRAMP compliance, with experience on both 20x and traditional Rev 5 approach. Partner heavily with our Public Sector sales team to ensure our authorization path and timeline match the agencies we're actually selling into, sequencing sponsorship, boundary decisions, and control work around live deals rather than in isolation.
  • Define and establish the authorization boundary, 3PAO selection and management, SSP and control narratives, NIST 800-53 baselines, POA&M, and continuous monitoring. Set ConMon up as automated, machine-readable evidence rather than a manual documentation exercise.
  • Run StateRAMP and TX-RAMP alongside the federal track.
Your background looks something like this
  • 5+ years of GRC experience in high-growth SaaS or technology companies, with direct responsibility for FedRAMP compliance programs
  • Proven track record successfully contributing to SOC 2, ISO 27001, or similar enterprise compliance certifications
  • Experience in data privacy regulations including CCPA, GDPR, and emerging AI governance frameworks
  • Strong project management skills with ability to coordinate cross-functional teams under tight deadlines
  • Excellent written and verbal communication skills to translate complex security concepts for diverse audiences
  • Working knowledge of technical security controls and ability to collaborate effectively with engineering teams
Even better if you have
  • Experience with AI/ML compliance frameworks and understanding of unique risks in conversational AI systems
  • Background in healthcare or financial services with knowledge of HIPAA or PCI requirements
  • Track record of building GRC programs at companies scaling from startup to enterprise
  • Experience with GRC platforms like Vanta, Drata, or SecureFrame to automate compliance workflows
  • Understanding of cloud security particularly Google Cloud Platform compliance and security features
Compensation

$190K - $275K + Offers Equity

Benefits

We proudly offer the following benefits for our full-time employees:
  • Medical, Dental, and Vision benefits for you and your family
  • Life Insurance and Disability Benefits
  • Retirement Plan (e.g., 401K, pension)
  • Parental Leave
  • Fertility and family building benefits through Carrot
  • Monthly stipend to support your wellness, lifestyle, and work-life balance
  • Daily lunches and snacks in the office to keep you at your best
  • Take what you need vacation policy (subject to local requirements; UK employees receive 25 days of statutory leave)

These benefits are described in more detail in Decagon's policies, may vary by location, and can change at any time according to applicable compensation and benefits plans.

Similar Jobs

More Jobs at Decagon

More Information Technology Jobs

Find similar Governance, Risk, and Compliance Manager - FedRAMP jobs: