Security Compliance Program Manager (Contract)

Kaizen Labs

$110K — $130K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of direct experience in compliance roles, focusing on federal contracts
  • Hands-on knowledge of NIST 800-53 Rev 5 and 800-171 frameworks
  • Experience with FedRAMP certification processes and documentation
  • Proven ability to manage and track federal regulatory obligations
  • Familiarity with SPRS score computation and associated controls
  • Background in defense contracting or familiarity with FAR/DFARS requirements
  • Must be eligible for a Tier 3 background investigation

Responsibilities

  • Lead the development of a compliance register tracking federal obligations
  • Implement a monthly process for tracking and reporting POA&M
  • Create and maintain an obligation calendar with deadlines and responsible parties
  • Conduct a NIST 800-171 self-assessment and maintain the SPRS score
  • Oversee certification application materials and continuous monitoring processes
  • Manage agency security questionnaires independently
  • Prepare and stage FCL readiness materials for submission

Benefits

  • 100% coverage for medical, dental, and vision insurance for employees and dependents
  • $100,000 in life insurance and flexible spending accounts
  • 16 weeks fully paid parental leave and unlimited PTO with a minimum requirement
  • Home office stipends and commuter benefits for employees
  • Wellness benefits including gym memberships and fitness reimbursements
  • Annual stipends for professional development and recreation
  • Remote employees receive a company laptop and investment in home office setup
Full Job Description
The Role

Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it.

We are standing up a dedicated compliance function and hiring for it permanently. This engagement builds the operating machinery in the meantime: the register, the calendar, the submissions, and the evidence trail. Hands-on production work rather than advisory.

The Programs

FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. We are designing for reuse rather than authorizing each product from scratch, so the change-control side of an authorization matters here as much as the initial package. You would own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor.

DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer's or a partner's. You would own knowing the reciprocity map, reading a hosting platform's actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary.

CMMC. A separate track from the product, and keeping the two separate matters: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You would run the self-assessment against NIST 800-171 Rev 2, build a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries. The scoping decision is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident-reporting clauses matters here.

Deliverables

What we expect to have in hand at each stage.

Weeks 1 to 4
  • An obligation register covering every federal contractual and regulatory requirement Kaizen carries, with its source, cadence, and owner. This means reading the contracts and subcontracts for FAR and DFARS flowdowns, not just the security frameworks. Expect employee notices, required training, prohibited technology, EEO and labor reporting, and OCI alongside the control work
  • A monthly POA&M process stood up, with the first cycle assembled and submitted to our platform partner on schedule. Version one can be a spreadsheet with ten honest rows
  • An obligation calendar covering every recurring deadline, each with a named owner and an escalation path

Weeks 5 to 12
  • NIST 800-171 self-assessment completed and scored, with the SPRS package staged for a company official to affirm and every gap carrying a dated POA&M entry
  • Control-to-evidence mapping, version one, with inherited controls separated from shared and from application-specific
  • Certification application materials assembled, including a machine-readable package that validates
  • A corporate CUI system security plan scoped to a named group of users, separate from the product SSP
  • Federal paperwork current: DD Form 2345 and JCP registration, DD 254, PIEE and SPRS administration, SAM.gov
  • Identity verification vendor evaluated and selected against FedRAMP-aligned screening requirements

Months 3 to 6
  • Four plans written and usable: configuration management, incident response, contingency, supply chain risk management
  • Continuous monitoring and log retention documented and running
  • Agency security questionnaires answered without executive involvement
  • FCL readiness package staged


What You'll Bring
  • Direct experience submitting in federal portals, SPRS and PIEE specifically. "Supported" and "submitted" are different things
  • Has run a NIST 800-171 self-assessment or RMF package end to end, with personal accountability for the outcome
  • Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it
  • Hands-on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor
  • Current on FedRAMP as it exists in 2026, and fluent in 20x specifically. Certification Classes, Key Security Indicators, machine-readable packages, continuous validation. We are building on 20x, so experience that stops at Rev 5 documentation will be working against the grain
  • Knows where Rev 5 still binds. High remains a Rev 5 process and new Rev 5 certifications stop in June 2027
  • Can reason about a shared authorization boundary: inherited versus shared versus application-specific controls, and what kind of change triggers a significant-change request
  • Working knowledge of the DoD Cloud Computing SRG and how Impact Levels sit on FedRAMP baselines. The CSP and Mission Owner split matters here, and so does reading a hosting platform's ATO coverage against the agency doing the buying
  • Has worked opposite a 3PAO or independent assessor on evidence requests and knows what they accept in practice
  • Can read a contract for FAR and DFARS flowdowns and turn them into a tracked obligation register. Subcontract flowdown matrix experience is a strong signal
  • Background in federal or defense contracting, agency-side, prime, or sub
  • Comfortable being the only compliance person on an engagement, with a vCISO firm for advice and an engineering team for implementation
  • US person, eligible for a Tier 3 background investigation


Strong Candidates May Also
  • Have owned a FedRAMP authorization through to completion, on the provider or the assessor side. This is the single most valuable thing on this list and it moves our rate
  • Have written OSCAL by hand, or stood up a trust center against live control indicators
  • Bring a military background in security, intelligence, or information security
  • Hold a CMMC CCP or RP, or have worked in eMASS, Xacta, or Paramify
  • Know the GovRAMP reciprocity path into FedRAMP Class A
  • Have done exactly this as a contract engagement before and can describe what made it work or fail


Scope

You prepare the SPRS package and the FCL readiness materials; a company officer signs the submission and holds the FSO designation. Admin access to the federal enclave stays with employees.

Don't Apply If...
  • Your compliance background is in financial services, insurance, or telecom. Large-team GRC with no federal exposure doesn't transfer here
  • You've assessed federal compliance programs but never owned one. Assessing a program and being accountable for it are different jobs
  • You want a retainer to advise. We have advisors. This engagement produces artifacts with dates on them
  • Accuracy under commercial pressure is negotiable for you. What we submit carries real legal exposure, and holding the truthful answer is the job


What Kaizen Offers

Health & Insurance
  • 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam - all fully covered for employees, with 100% coverage for dependents.
  • $100,000 in fully paid life insurance. FSA and Dependent Care FSA.
  • One Medical membership, on us - same-day primary care, 24/7 virtual visits, and offices all over the city.
  • Fertility and family-building support through Carrot.
  • 401(k) through Guideline, with a 2% company match.

Family & Time Off
  • 16 weeks of fully paid parental leave for birthing parents. 10 weeks fully paid for non-birthing parents.
  • Unlimited PTO, with a two-week minimum (we mean it when we say take time off!)
  • Closed for all federal holidays.
  • Company-wide winter break the week of Christmas.
  • Company offsites throughout the year.

Office & Remote Setup
  • Up to $750 one-time home office or desk setup stipend for NYC-based employees. $500 for remote employees.
  • $50/month commuter benefit (company contribution).
  • Expensed lunch while in the office.
  • Company-provided laptop of your choice.

Wellness
  • Fully covered gym membership at Grindhouse - right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement.

Stipends
  • $100/month utility stipend.
  • $500/year professional development.
  • $250/year recreation.
  • $300/quarter pet care stipend.

Similar Jobs

  • Executive Officer
    $110K — $130K *
    Executive Office for U.S. Attorneys/The Office of the U.S. A
    Falls Church, VA 22042 (Fairfax County)
  • Management and Program Analyst
    $121K — $158K *
    Customs and Border Protection
    Ashburn, VA 20147 (Loudoun County)
  • Management Analysis Officer
    $110K — $130K *
    National Oceanic and Atmospheric Administration (NOAA)
    College Park, MD 20740 (Prince Georges County)
  • Management Analysis Officer
    $110K — $130K *
    National Oceanic and Atmospheric Administration (NOAA)
    Suitland, MD 20746 (Prince Georges County)
  • Management Analysis Officer
    $110K — $130K *
    National Oceanic and Atmospheric Administration (NOAA)
    Greenbelt, MD 20770 (Prince Georges County)
  • Management Analysis Officer
    $110K — $130K *
    National Oceanic and Atmospheric Administration (NOAA)
    Silver Spring, MD 20906 (Montgomery County)

More Jobs at Kaizen Labs

More Aerospace & Defense Jobs

Find similar Security Compliance Program Manager (Contract) jobs: