Anaplan

Sr. Security Program Manager, Commercial & Federal Compliance

Anaplan$100K — $130K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
  • 6+ years of program/project management experience, with 3-5 years leading compliance, security, or risk programs.
  • Hands-on experience with FedRAMP authorization and continuous monitoring is required.
  • Experience managing ISO 27001, SOC 2, and HITRUST certification/audit cycles, plus exposure to other certifications.
  • Working knowledge of CMMC, NIST 800-171/800-53 standards.
  • Strong analytical skills to translate regulatory requirements into operational needs.
  • Proficiency with project management tools and GRC platforms.

Responsibilities

  • Own end-to-end program management for compliance initiatives from planning to audit readiness.
  • Lead FedRAMP authorization and continuous monitoring efforts, coordinating with relevant teams.
  • Partner with various departments to interpret compliance requirements and develop program plans.
  • Manage international and commercial certification programs, adapting to market requirements.
  • Develop program roadmaps and risk registers while proactively mitigating project risks.
  • Coordinate internal and external audits, ensuring evidence collection and stakeholder readiness.
  • Support the establishment of governance processes for sustainable compliance.

Benefits

  • Flexible remote working opportunities.
  • Collaborative work environment across multiple teams.
  • Professional development and training support.
  • Access to innovative compliance and regulatory frameworks.
  • Opportunities to engage with senior leadership and external stakeholders.
Full Job Description
We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams - driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701, Cyber Essentials, TISAX). The ideal candidate is a skilled program leader who can translate complex, multi-jurisdictional regulatory requirements into actionable roadmaps, manage cross-functional execution, and communicate risk and progress clearly to senior leadership.

Your Impact
  • Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
  • Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle.
  • Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans.
  • Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market's requirements.
  • Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks.
  • Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans).
  • Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business.
  • Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed.
  • Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
  • Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups.
  • Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs.

Your Qualifications
  • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
  • 6+ years of program or project management experience, including at least 3-5 years directly leading compliance, security, or risk programs.
  • Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) is required.
  • Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks).
  • Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53).
  • Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines.
  • Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders.
  • Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements.
  • Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC, or similar).
  • Must be a U.S. Citizen or U.S. Person residing in the U.S. (FedRAMP Moderate/High requirement).

Nice to Haves
  • PMP, PgMP, or equivalent program management certification.
  • ISO 27001 Lead Auditor or Lead Implementer certification.
  • HITRUST Certified CSF Practitioner (CCSFP).
  • CISSP, CISA, or CISM.
  • Experience supporting a FedRAMP JAB or Agency authorization from initiation through ATO, including familiarity with OSCAL and continuous monitoring deliverables.
  • Experience operating in multiple international markets and navigating varying regional compliance/certification requirements.

#LI-Remote

About Anaplan

Anaplan is a cloud-based business planning and performance management platform that enables businesses to manage their financial and operational planning processes. The platform provides a range of solutions, including sales performance management, workforce planning, supply chain planning, and financial planning and analysis. Anaplan's platform is designed to be flexible and scalable, allowing businesses to adapt to changing market conditions and business needs. The company was founded in 2006 and is headquartered in San Francisco, California.
Learn more about Anaplan
Size
14 employees
Market Cap
$9.4 billion
Industry
Net Income
-$153.9 million
Founded
2006
5 Year Trend
+37.5%
Revenue
$447.7 million
NASDAQ

Similar Jobs

More Jobs at Anaplan

More Technical Services Jobs

Find similar Sr. Security Program Manager, Commercial & Federal Compliance jobs: