Senior Program Manager, IT Governance and Compliance

True Anomaly

• $140K — $195K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of program or project management experience in technology or cybersecurity-related roles, with 5+ years in GRC or compliance environments.
  • PMP (Project Management Professional) certification required.
  • Proven experience managing certification initiatives involving CMMC and DoD RMF IL5/IL6.
  • Ability to manage multi-disciplinary teams and complex project interdependencies.
  • Strong proficiency in program management tools such as Jira, Confluence, MS Project, and GRC platforms.

Responsibilities

  • Lead GRC-related program tracking from inception through delivery across multiple frameworks.
  • Build and maintain program dashboards and executive reports for transparency to leadership.
  • Coordinate timelines, resources, and deliverables across various teams including security, compliance, and IT operations.
  • Identify risks and dependencies, and drive timely mitigation plans as necessary.
  • Define and monitor Key Performance Indicators (KPIs) to ensure audit readiness and successful task execution.
  • Act as the primary point of contact for internal stakeholders and external compliance assessors.
  • Support compliance readiness, including audit facilitation and remediation planning.
  • Continuously improve project workflows and reporting processes for scalable program management.

Benefits

  • Comprehensive health, dental, vision, HRA/HSA options.
  • Generous PTO and paid holidays.
  • 401(k) plan with company contributions.
  • Parental leave policies to support work-life balance.
  • Opportunities for equity participation.
Full Job Description
YOUR MISSION

We are seeking an experienced Senior Program Manager to lead and coordinate cross-functional GRC initiatives across our organization. The ideal candidate will have demonstrated success in managing certification programs such as DoD RMF IL5 and IL6, CMMC and other compliance frameworks, while overseeing program delivery through structured KPI tracking, cross-team milestone management, and dashboard-driven reporting.

The candidate must be comfortable operating in fast-paced, regulated environments and be able to drive alignment across engineering, security, legal, compliance, and business operations teams. This is a critical role that ensures successful execution and continuous visibility of compliance initiatives for both internal leadership and external partners, including government and commercial stakeholders.

RESPONSIBILITIES
  • Lead GRC-related program tracking from inception through delivery across multiple frameworks (e.g., DoD RMF IL5 and IL6, CMMC).
  • Build and maintain program dashboards and executive reports using tools such as Jira, Confluence, GRC platforms (e.g., Diligent), and MS Project to provide transparency across teams and to leadership.
  • Coordinate and manage timelines, resources, and deliverables across security operations, product compliance, IT operations, and external consultants.
  • Track program status against milestones, identify risks and dependencies, and drive timely mitigation plans and course correction as needed.
  • Define and monitor Key Performance Indicators (KPIs) for compliance programs and team performance, ensuring successful execution of tasks and ongoing audit readiness.
  • Serve as the primary point of contact for internal stakeholders, executive leadership, and external assessors or certification bodies.
  • Support compliance readiness activities including pre-assessment readiness, audit facilitation, evidence collection, and post-audit remediation planning.
  • Continuously improve project workflows, team coordination, and reporting processes for scalable and repeatable program management.


QUALIFICATIONS
  • 7+ years of program or project management experience in technology or cybersecurity-related roles, with at least 5 years in GRC or compliance environments.
  • PMP (Project Management Professional)
  • Proven experience managing certification initiatives involving CMMC, DoD RMF IL5 and IL6.
  • Demonstrated ability to manage multi-disciplinary teams and complex project interdependencies across business and technical stakeholders.
  • Strong proficiency in program management and documentation tools:
  • Jira and Confluence (Atlassian suite)
  • MS Project or similar PM software
  • Excellent communication and stakeholder management skills, with a strong ability to simplify complexity and drive results across levels of the organization.

Preferred Qualifications
  • Professional certifications such as:
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified ScrumMaster (CSM) or Agile PM certification
  • Certified Information Systems Security Professional (CISSP)
  • Experience with cloud environments (e.g., Azure Government) and understanding of government cloud authorization processes.
  • Familiarity with Agile/Scrum and hybrid project delivery models.
  • GRC platforms (e.g., Diligent)


COMPENSATION
  • Base Salary: Denver - $135,000 to $185,000, Long Beach - $140,000 to $195,000, Washington, DC - $140,000 to $195,000, SF Bay Area - $155,000 to $215,000
  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave


Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education and experience.

ADDITIONAL REQUIREMENTS
  • Ability to maintain or obtain TS//SCI clearance
  • Work Location: this role will be onsite at our facilities in Centennial, CO, Long Beach, CA, or Washington, DC.
  • Work environment is in a standard office, working at a desk or in a production factory.
  • Physical demands may include frequent standing, sitting, walking, bending, and lifting or carrying items up to 20lbs.

This position will be open until it is successfully filled. To submit your application, please follow the directions below.#LI-Onsite

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (IT
  1. AR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Similar Jobs

More Jobs at True Anomaly

More Information Technology Jobs

Find similar Senior Program Manager, IT Governance and Compliance jobs: