Government Compliance Program Manager

MEDITECH International

Canton, Northern (MA, KY)

Hybrid

USD 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401(k) plan
Profit sharing
Tuition reimbursement
Generous PTO
Sick days
Personal time
Paid holidays

Job summary

MEDITECH is seeking a Government Compliance Program Manager to drive FedRAMP/ITSG-33 readiness and privacy program support in a hybrid role. You will author SSPs, map controls to NIST SP 800-53, and coordinate audits with third-party assessors and internal teams.

You will collect evidence, manage POA&M, and support continuous monitoring and GDP/privacy reviews across cloud environments.

Qualifications

  • 3+ years in Information Security, IT Compliance, or GRC with FedRAMP/ITSG-33 experience.
  • Knowledge of NIST SP 800-53 controls and cloud implementation.
  • Experience documenting compliance artifacts (SSP, POA&M, IRP).
  • Strong written regulatory communication and cross-functional collaboration.

Responsibilities

  • Prepare government compliance packages (SSP, SCTM) and policy documents.
  • Map controls across NIST 800-53 and CCCS Medium Cloud Profile.
  • Coordinate audits with 3PAOs and government reviewers.
  • Maintain POA&M and remediation tracking with Cloud/DevOps teams.
  • Organize audit evidence and support Continuous Monitoring artifacts.

Skills

Information Security
GRC
FedRAMP ITSG-33
NIST SP 800-53
Documentation writing
Auditing
Cross-functional collaboration
Regulatory language proficiency

Education

CISA
CRISC
CISM
CAP/CGRC
Security+

Tools

SIEM
Vulnerability management
SSPs/POA&M tooling
3PAO coordination

Job description

Description

As a Government Compliance Program Manager, you will be heavily involved in preparing our SaaS product and cloud operations for ITSG-33 and FedRAMP authorizations, as well as maintaining our broader data protection and privacy standards. Working under the direction of security leadership, you will serve as the operational bridge between technical teams and regulatory frameworks—writing security documentation, mapping control implementations, tracking remediation items, and facilitating auditor requests. As a member of our Cloud Services team, your job would involve:

  • Authoring, updating, and maintaining core government compliance packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), and supporting policy documents
  • Mapping operational controls across NIST SP 800-53 and CCCS Medium Cloud Profile to ensure clear alignment with engineering and IT workflows
  • Tracking control coverage and document evidence for identity management, access control, encryption standards, and monitoring routines
  • Coordinating day-to-day operations during third-party assessment (3PAOs) and government audits
  • Managing and updating the Plan of Action and Milestones (POA&M) register—working directly with Cloud/DevOps and Engineering teams to ensure timely remediation of vulnerabilities and findings
  • Collecting, organizing, and validating audit evidence to ensure smooth assessment lifecycles
  • Supporting the execution of the Continuous Monitoring program, including organizing monthly scan reviews, vulnerability logs, and quarterly deliverable packages
  • Assisting in conducting internal assessments, vendor risk evaluations, and data protection reviews for GDP/privacy compliance
  • Monitoring updates to federal standards (NIST, CCCS) and highlighting necessary operational updates to security leadership.
Requirements
  • Experience: 3+ years in Information Security, IT Compliance, or GRC, with direct experience participating in FedRAMP or ITSG-33 Protected B compliance efforts
  • Framework Knowledge: Practical understanding of NIST SP 800-53 controls and how they are implemented within cloud infrastructure (AWS GovCloud, Azure Government, or GCP)
  • Familiarity with general cloud architecture concepts, IAM, FIPS-compliant encryption, SIEM/logging platforms, and vulnerability management tools
  • Hands-on Artifact Creation: Demonstrated experience writing or maintaining compliance artifacts (SSPs, POA&M, Incident Response Plans)
  • Project Tracking: Strong organizational skills with experience tracking complex cross-functional deliverables across software and IT teams
  • Strong written communication skills—able to clearly explain technical controls in formal regulatory language
  • Collaborating effectively with software engineers, system admins, and external auditors
  • Certifications: CISA, CRISC, CISM, CAP/CGRC, or Security+ preferred
  • Clearance Eligibility: Ability to obtain or hold government security screening (e.g., PSPC Reliability/Secret in Canada, or US equivalent) is a strong plus.

Hiring salary range: $70,200- $90,000 per year.

Actual salary will be determined based on an individual's skills, experience, education, and other job-related factors permitted by law.

MEDITECH offers competitive employee benefits including but not limited to health, dental, & vision insurance; profit sharing trust and 401(k); tuition reimbursement, generous paid time off, sick days, personal time, and paid holidays.

This is a hybrid role which includes a blend of in-office and remote work as designated by the management team.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. MEDITECH will not sponsor applicants for work visas.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Government Compliance Program Manager
Government Compliance Program Manager

RXinsider LTD. • Northern (KY)

Hybrid
USD 70,000 - 90,000
Health, dental, & vision insurance
Profit sharing / 401(k)
Tuition reimbursement
+4
Hybrid Government Compliance Program Manager | FedRAMP/NIST
Hybrid Government Compliance Program Manager | FedRAMP/NIST

RXinsider LTD. • Northern (KY)

Hybrid
USD 70,000 - 90,000
Health, dental, & vision insurance
Profit sharing / 401(k)
Tuition reimbursement
+4
Senior Public Sector Compliance Manager
Senior Public Sector Compliance Manager

Jobgether SRL • United States

Remote
USD 110,000 - 170,000
Remote work within United States
Exposure to federal security programs
Cross-functional collaboration
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Hybrid Gov't Compliance & Cloud Security Manager
Hybrid Gov't Compliance & Cloud Security Manager

MEDITECH International • Canton (MA), Northern (KY)

Hybrid
USD 70,000 - 90,000
Health insurance
Dental insurance
Vision insurance
+7
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Compliance Engineer III
Compliance Engineer III

Menlo Ventures • California (MO)

On-site
USD 105,000 - 175,000
GovCloud Compliance Analyst (Cloud Controls & Audit) — E-level
GovCloud Compliance Analyst (Cloud Controls & Audit) — E-level

Sciata • New York (NY)

On-site
USD 65,000 - 79,000
Compliance Engineer III
Compliance Engineer III

Trueanomalyinc • Washington

On-site
USD 105,000 - 175,000
Health, Dental, Vision
401K
PTO and paid holidays
+1
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000