Agiloft logo
AgiloftΒ·

Senior FedRAMP Program Manager - Agiloft

Fully remoteFull-timeSeniorUTC-8–-4USA only#fedramp#nist#complianceWellness

As the most trusted global leader in data-first contract lifecycle management (CLM) software, Agiloft helps organizations manage the end-to-end process of proposing, negotiating, signing, and leveraging contracts using our flexible Data-first Agreement Platform (DAP). We are seeking a Senior FedRAMP Program Manager to serve as the day-to-day owner of company responsibilities within a partner-managed FedRAMP environment.

Position Overview

The FedRAMP Program Manager translates FedRAMP, NIST SP 800-53, assessment, and external-partner requirements into clear internal actions; coordinates evidence and remediation activities across functional teams; manages deadlines and shared-responsibility dependencies; and independently evaluates whether company work, remediation responses, and evidence are sufficiently complete and responsive.

This role works under the direction of the Director of Security and Compliance with limited day-to-day supervision. This is an individual-contributor program execution and subject-matter-expert role; it does not perform engineering implementation or technical remediation.

Job Responsibilities

FedRAMP Program Execution

  • Own day-to-day execution of company responsibilities within the FedRAMP program, including milestones, dependencies, risks, deadlines, and internal follow-through.
  • Translate FedRAMP requirements, findings, partner requests, and service-level commitments into clear internal actions with defined owners, due dates, and evidence expectations.
  • Maintain an authoritative view of program status and proactively identify work that may threaten assessment, remediation, continuous-monitoring, or other FedRAMP deadlines.
  • Assess overall program readiness and identify systemic gaps in controls, evidence, ownership, or processes.
  • Operate independently within established direction, resolving routine issues and escalating material risks or disputed requirements.
  • Leverage approved AI-enabled tools and automation to improve efficiency while validating outputs against authoritative requirements.

Evidence, Controls, and Remediation Coordination

  • Coordinate implementation and ongoing operation of organizational and procedural controls retained by the company.
  • Collect and review evidence for completeness, accuracy, relevance, and traceability before submission.
  • Act as the company-side quality gate for evidence and remediation responses, independently rejecting incomplete submissions.
  • Track findings from initial assessments, continuous monitoring, and authorized testing through assignment, remediation, evidence submission, and closure.

Cross-Functional and Partner Coordination

  • Serve as the primary operational interface with the company's external FedRAMP infrastructure and compliance partner.
  • Coordinate with Software Engineering, Cloud Engineering, Security, IT, Support, Operations, Product, Legal, and leadership.
  • Drive commitments across cross-functional teams through clear requirements, accountability, and escalation.

Scope, Change, and Program Governance

  • Maintain clarity over FedRAMP-in-scope users, systems, workflows, integrations, and shared-responsibility boundaries.
  • Coordinate review of proposed product, infrastructure, operational, or process changes that may affect FedRAMP scope.
  • Continuously improve FedRAMP processes, documentation, evidence practices, and operating routines.

Reporting and Escalation

  • Provide concise, decision-ready reporting to the Director of Security and Compliance on program status, open findings, remediation progress, and material risks.
  • Escalate early when missed deadlines, disputed requirements, or unresolved ownership issues require management intervention.

Required Qualifications

  • 7+ years of relevant professional experience in security, compliance, technical program management, risk management, or cloud security.
  • At least 3 years of direct FedRAMP program execution or ownership experience.
  • Demonstrated ownership of a substantial portion of at least one FedRAMP authorization lifecycle (gap assessment, control implementation, assessment support, POA&M remediation, and continuous monitoring).
  • Strong working knowledge of NIST SP 800-53 and the FedRAMP Moderate baseline.
  • Experience operating within cloud or compliance shared-responsibility models.
  • Demonstrated ability to translate requirements into actionable expectations for technical and non-technical teams.
  • Working technical knowledge of SaaS and cloud environments (IAM, CI/CD, vulnerability management, logging, system boundaries, encryption).
  • Strong written and verbal communication skills.

Timezone overlap

UTC-8–-4

Benefits

Wellness

Open to

US

Sign in to track applications and earn points.

More roles at Agiloft

Similar remote roles