Government Compliance Program Manager

RXinsider LTD.

Northern (KY)

Hybrid

USD 70,000 - 90,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health, dental, & vision insurance
Profit sharing / 401(k)
Tuition reimbursement
Generous paid time off
Sick days
Personal time
Paid holidays

Job summary

MEDITECH is seeking a Government Compliance Program Manager to lead government compliance activities for our SaaS and cloud operations. You will author SSPs, SCTMs, and policy documents, map controls to NIST SP 800-53, and coordinate audits with 3PAOs and government bodies.

The role requires 3+ years in Information Security or GRC, familiarity with FedRAMP/ITSG-33, and strong written communication. Hybrid work arrangement and comprehensive benefits are offered.

Qualifications

  • 3+ years in Information Security, IT Compliance, or GRC
  • FedRAMP or ITSG-33 experience preferred
  • Understanding of NIST SP 800-53 controls in cloud environments
  • Experience writing or maintaining compliance artifacts (SSPs, POA&M)
  • Strong written communication and cross-functional collaboration skills

Responsibilities

  • Author, update, and maintain SSPs, SCTMs, and policy documents
  • Map controls across NIST SP 800-53 to cloud workflows
  • Track control coverage and evidence for IAM, encryption, monitoring
  • Coordinate third-party assessments and government audits
  • Manage POA&M register and remediation tracking
  • Collect, organize, and validate audit evidence for assessments
  • Support Continuous Monitoring with monthly reviews and vulnerability logs
  • Assist in vendor risk evaluations and GDP/privacy reviews
  • Monitor updates to federal standards and advise security leadership

Skills

GRC expertise
Regulatory writing
Project tracking

Tools

SIEM
Vulnerability management tools

Job description

Job Type

Full-time

Description

As a Government Compliance Program Manager, you will be heavily involved in preparing our SaaS product and cloud operations for ITSG-33 and FedRAMP authorizations, as well as maintaining our broader data protection and privacy standards. Working under the direction of security leadership, you will serve as the operational bridge between technical teams and regulatory frameworks—writing security documentation, mapping control implementations, tracking remediation items, and facilitating auditor requests. As a member of our Cloud Services team, your job would involve:

  • Authoring, updating, and maintaining core government compliance packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), and supporting policy documents
  • Mapping operational controls across NIST SP 800-53 and CCCS Medium Cloud Profile to ensure clear alignment with engineering and IT workflows
  • Tracking control coverage and document evidence for identity management, access control, encryption standards, and monitoring routines
  • Coordinating day-to-day operations during third-party assessment (3PAOs) and government audits
  • Managing and updating the Plan of Action and Milestones (POA&M) register—working directly with Cloud/DevOps and Engineering teams to ensure timely remediation of vulnerabilities and findings
  • Collecting, organizing, and validating audit evidence to ensure smooth assessment lifecycles
  • Supporting the execution of the Continuous Monitoring program, including organizing monthly scan reviews, vulnerability logs, and quarterly deliverable packages
  • Assisting in conducting internal assessments, vendor risk evaluations, and data protection reviews for GDP/privacy compliance
  • Monitoring updates to federal standards (NIST, CCCS) and highlighting necessary operational updates to security leadership.
Requirements
  • Experience: 3+ years in Information Security, IT Compliance, or GRC, with direct experience participating in FedRAMP or ITSG-33 Protected B compliance efforts
  • Framework Knowledge: Practical understanding of NIST SP 800-53 controls and how they are implemented within cloud infrastructure (AWS GovCloud, Azure Government, or GCP)
  • Familiarity with general cloud architecture concepts, IAM, FIPS-compliant encryption, SIEM/logging platforms, and vulnerability management tools
  • Hands-on Artifact Creation: Demonstrated experience writing or maintaining compliance artifacts (SSPs, POA&M, Incident Response Plans)
  • Project Tracking: Strong organizational skills with experience tracking complex cross-functional deliverables across software and IT teams
  • Strong written communication skills—able to clearly explain technical controls in formal regulatory language
  • Collaborating effectively with software engineers, system admins, and external auditors
  • Certifications: CISA, CRISC, CISM, CAP/CGRC, or Security+ preferred
  • Clearance Eligibility: Ability to obtain or hold government security screening (e.g., PSPC Reliability/Secret in Canada, or US equivalent) is a strong plus.
Hiring salary range

$70,200- $90,000 per year.

Actual salary will be determined based on an individual's skills, experience, education, and other job-related factors permitted by law.

Benefits

MEDITECH offers competitive employee benefits including but not limited to

  • health, dental, & vision insurance
  • profit sharing trust and 401(k)
  • tuition reimbursement
  • generous paid time off
  • sick days
  • personal time
  • paid holidays

This is a hybrid role which includes a blend of in-office and remote work as designated by the management team.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. MEDITECH will not sponsor applicants for work visas.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hybrid Government Compliance Program Manager | FedRAMP/NIST
Hybrid Government Compliance Program Manager | FedRAMP/NIST

RXinsider LTD. • Northern (KY)

Hybrid
USD 70,000 - 90,000
Health, dental, & vision insurance
Profit sharing / 401(k)
Tuition reimbursement
+4
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Senior Public Sector Compliance Manager
Senior Public Sector Compliance Manager

Jobgether SRL • United States

Remote
USD 110,000 - 170,000
Remote work within United States
Exposure to federal security programs
Cross-functional collaboration
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
IT Risk and Compliance Specialist Principal
IT Risk and Compliance Specialist Principal

General Dynamics Information Technology, Inc. • Bossier City (LA)

Hybrid
USD 111,000 - 150,000
Compliance Engineer III
Compliance Engineer III

Menlo Ventures • California (MO)

On-site
USD 105,000 - 175,000
Compliance Engineer III
Compliance Engineer III

Trueanomalyinc • Washington

On-site
USD 105,000 - 175,000
Health, Dental, Vision
401K
PTO and paid holidays
+1
Staff Security Analyst - GRC
Staff Security Analyst - GRC

harnessinc • United States

Remote
USD 150,000 - 164,000
Monthly internet reimbursement
Multi-Cloud Security & Compliance Engineer
Multi-Cloud Security & Compliance Engineer

Latitude IT Solutions • United States

Remote
USD 135,000 - 155,000
Medical, Vision, Dental
Paid Vacation & Sick Time
Paid Federal Holidays
+6
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000