Senior Program Manager, IT Governance and Compliance

True Anomaly

• $140K — $195K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of program/project management experience in technology or cybersecurity-related roles, with at least 5 in GRC/compliance environments.
  • Project Management Professional (PMP) certification required.
  • Proven experience with CMMC and DoD RMF IL5 and IL6 certification initiatives.
  • Strong leadership in managing multi-disciplinary teams and complex project interdependencies.
  • Proficiency in Jira, Confluence, MS Project, and similar PM tools.

Responsibilities

  • Lead GRC program tracking from inception to delivery across multiple compliance frameworks.
  • Build and maintain program dashboards and reports for cross-team transparency and leadership.
  • Coordinate timelines, resources, and deliverables among security, IT, and external stakeholders.
  • Track project status, identify risks, and execute timely mitigation strategies.
  • Define and monitor KPIs for compliance programs to ensure successful execution and audit readiness.
  • Serve as primary contact for internal and external stakeholders regarding compliance initiatives.
  • Support compliance readiness activities, including audits and post-audit remediation.

Benefits

  • Health, Dental, and Vision insurance, with HRA/HSA options.
  • Paid Time Off (PTO) and holidays provided.
  • 401K retirement plan with employer contributions.
  • Parental Leave for new parents.
Full Job Description
YOUR MISSION

We are seeking an experienced Senior Program Manager to lead and coordinate cross-functional GRC initiatives across our organization. The ideal candidate will have demonstrated success in managing certification programs such as DoD RMF IL5 and IL6, CMMC and other compliance frameworks, while overseeing program delivery through structured KPI tracking, cross-team milestone management, and dashboard-driven reporting.

The candidate must be comfortable operating in fast-paced, regulated environments and be able to drive alignment across engineering, security, legal, compliance, and business operations teams. This is a critical role that ensures successful execution and continuous visibility of compliance initiatives for both internal leadership and external partners, including government and commercial stakeholders.

RESPONSIBILITIES
  • Lead GRC-related program tracking from inception through delivery across multiple frameworks (e.g., DoD RMF IL5 and IL6, CMMC).
  • Build and maintain program dashboards and executive reports using tools such as Jira, Confluence, GRC platforms (e.g., Diligent), and MS Project to provide transparency across teams and to leadership.
  • Coordinate and manage timelines, resources, and deliverables across security operations, product compliance, IT operations, and external consultants.
  • Track program status against milestones, identify risks and dependencies, and drive timely mitigation plans and course correction as needed.
  • Define and monitor Key Performance Indicators (KPIs) for compliance programs and team performance, ensuring successful execution of tasks and ongoing audit readiness.
  • Serve as the primary point of contact for internal stakeholders, executive leadership, and external assessors or certification bodies.
  • Support compliance readiness activities including pre-assessment readiness, audit facilitation, evidence collection, and post-audit remediation planning.
  • Continuously improve project workflows, team coordination, and reporting processes for scalable and repeatable program management.


QUALIFICATIONS
  • 7+ years of program or project management experience in technology or cybersecurity-related roles, with at least 5 years in GRC or compliance environments.
  • PMP (Project Management Professional)
  • Proven experience managing certification initiatives involving CMMC, DoD RMF IL5 and IL6.
  • Demonstrated ability to manage multi-disciplinary teams and complex project interdependencies across business and technical stakeholders.
  • Strong proficiency in program management and documentation tools:
  • Jira and Confluence (Atlassian suite)
  • MS Project or similar PM software
  • Excellent communication and stakeholder management skills, with a strong ability to simplify complexity and drive results across levels of the organization.

Preferred Qualifications
  • Professional certifications such as:
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified ScrumMaster (CSM) or Agile PM certification
  • Certified Information Systems Security Professional (CISSP)
  • Experience with cloud environments (e.g., Azure Government) and understanding of government cloud authorization processes.
  • Familiarity with Agile/Scrum and hybrid project delivery models.
  • GRC platforms (e.g., Diligent)


COMPENSATION
  • Base Salary: Denver - $135,000 to $185,000, Long Beach - $140,000 to $195,000, Washington, DC - $140,000 to $195,000, SF Bay Area - $155,000 to $215,000
  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave


Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education and experience.

ADDITIONAL REQUIREMENTS
  • Ability to maintain or obtain TS//SCI clearance
  • Work Location: this role will be onsite at our facilities in Centennial, CO, Long Beach, CA, or Washington, DC.
  • Work environment is in a standard office, working at a desk or in a production factory.
  • Physical demands may include frequent standing, sitting, walking, bending, and lifting or carrying items up to 20lbs.

This position will be open until it is successfully filled. To submit your application, please follow the directions below.#LI-Onsite

Similar Jobs

More Jobs at True Anomaly

More Information Technology Jobs

Find similar Senior Program Manager, IT Governance and Compliance jobs: