SAS

Sr Program Manager, Continuous Monitoring

SAS$100K — $130K *
Cary, NC 27513In-Person
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science, information systems, risk management, cybersecurity, business administration, or a related field.
  • Eight years of experience in managing security, compliance, audit, or risk-related programs in a cloud or regulated environment.
  • Demonstrated expertise in continuous monitoring and vulnerability management.
  • Experience collaborating with cloud infrastructure and related technology teams.
  • Strong ability to influence outcomes across cross-functional teams.
  • Proven track record of managing multiple deliverables and timelines effectively.
  • Ability to translate compliance requirements into actionable plans.

Responsibilities

  • Manage the Continuous Monitoring program activities and deliverables for Managed Cloud Services.
  • Track vulnerabilities and remediation plans to support timely risk resolution.
  • Lead alignment with various security and compliance functions and stakeholders.
  • Ensure quality and timely submission of Continuous Monitoring documentation required for compliance.
  • Drive recurring meetings to enhance agency alignment and risk management processes.
  • Coordinate activities within the annual security assessment lifecycle, focusing on remediation status.
  • Develop and refine the Continuous Monitoring program roadmap to meet regulatory and operational goals.

Benefits

  • Comprehensive medical, prescription, dental and vision plans.
  • Onsite Health Care Center with free access for employees and family enrolled in PPO plan.
  • An industry-leading 401k plan.
  • Tuition Assistance Program and resources for personal development.
  • Generous vacation and paid holidays, plus a winter wellness break.
  • Volunteer Time Off, parental leave, and unlimited paid sick days.
  • Childcare benefits available for all full-time employees.
Full Job Description

Senior Program Manager, Continuous Monitoring - Hybrid, Cary, North Carolina

 

About the job

The Managed Cloud Services organization within the Cloud and Information Services (CIS) division is seeking a Senior Program Manager focused on Continuous Monitoring to strengthen program execution, improve audit readiness, and support consistent compliance outcomes across SAS Managed Cloud Services.

In this role, you will partner with security, compliance, cloud operations, and agency stakeholders to manage recurring Continuous Monitoring activities, maintain required evidence and reporting, coordinate assessments, and reduce operational risk. This opportunity comes at a pivotal time, as the organization continues to grow rapidly and strengthen its enterprise operating model.

 

As a Senior Program Manager focused on Continuous Monitoring, you will:

  • Manage the Continuous Monitoring program for SAS Managed Cloud Services, including recurring deliverables, artifact readiness, stakeholder coordination, and submission timelines.
  • Track vulnerabilities, deviation requests, remediation plans, milestones, and success metrics to support timely risk visibility and resolution.
  • Lead cross-functional alignment with Global Information Security, Governance, Risk, Compliance and Audit, Product Management, Cloud Operations, agency stakeholders, consultants, and assessment teams.
  • Oversee the readiness, quality, and timely submission of Continuous Monitoring artifacts, evidence, and reporting packages required to support authorization and certification commitments.
  • Lead recurring Continuous Monitoring operating cadences that drive agency alignment, internal decision-making, status visibility, issue follow-up, and risk escalation.
  • Coordinate key activities within the annual 3PAO security assessment lifecycle, with a focus on remediation status and SLA aging
  • Shape and mature the Continuous Monitoring program roadmap, aligning regulatory requirements, customer commitments, operational priorities, reporting standards, and organizational growth objectives.
  • Drive cross-functional action with technical teams to assess security control effectiveness, surface compliance gaps and lifecycle risks, and advance required remediation actions.
  • Ensure all applicable security policies and processes are followed to support the organization's secure software development goals.
  • Embrace curiosity, passion, authenticity and accountability. These are our values and influence everything we do.

 

Required qualifications

  • Bachelor’s degree in computer science, information systems, risk management, cybersecurity, business administration, or a related field.
  • Eight years of experience managing security, compliance, audit, governance, technology, or risk-related programs in a cloud or regulated technology environment.
  • Demonstrated experience with continuous monitoring, POA&M management, vulnerability management, security control assessment, and evidence management.
  • Experience working with cloud infrastructure, SaaS, managed services, cybersecurity, compliance, privacy, DevOps, or cloud operations teams.
  • Demonstrated ability to influence outcomes across cross-functional technical, compliance, and senior leadership stakeholders while managing milestones, risks, and decisions.
  • Strong execution discipline with the ability to manage multiple recurring deliverables, documentation cycles, reporting timelines, and assessment activities concurrently.
  • Ability to translate security and compliance requirements into actionable plans, operating cadences, and measurable outcomes.
  • Equivalent combination of related education, training and experience may be considered in place of the above qualifications.

 

Preferred Qualifications

  • Prior experience supporting FedRAMP Moderate or High environments, CSP continuous monitoring submissions, or agency authorization activities.
  • Practical experience applying federal compliance standards and frameworks, such as NIST 800-53, FedRAMP, FISMA, NIST SP 800-30, NIST SP 800-34, or NIST 800-171, in a cloud or regulated technology environment.
  • Experience using GRC platforms, vulnerability management tools, ticketing systems, evidence repositories, or compliance reporting workflows.
  • Understanding of public cloud architectures, SaaS/IaaS operating models, managed services, and lifecycle management in regulated environments.
  • Security, compliance, risk, audit, or program management certifications such as CISA, CISSP, Security+, CRISC, CISM, PMP, or other industry-recognized credentials.

 

Requirements

  • U.S. citizenship is required.
  • Successful completion of a background check is required.

 

World-class benefits  

Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include:
    • PPO with low annual deductible and copays.
    • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Tuition Assistance Program and programs and resources to support your development
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.

 

About SAS

SAS is a multinational software company that provides advanced analytics, business intelligence, and data management software and services. SAS is the largest privately held software company in the world and is headquartered in Cary, North Carolina. The company was founded in 1976 by Jim Goodnight and John Sall, who are still the CEO and Executive Vice President, respectively. SAS has over 83,000 customers worldwide and employs over 14,000 people in more than 60 countries. SAS has been recognized as one of the best places to work by Fortune magazine and the Great Place to Work Institute.
Learn more about SAS
Size
14,000 employees
Industry
Founded
1976

Similar Jobs

More Jobs at SAS

More Information Technology Jobs

Find similar Sr Program Manager, Continuous Monitoring jobs: