Security Governance Manager

Jobtailor

Washington (WA, District of Columbia)

On-site

USD 120,000 - 155,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a seasoned GRC and Security Governance leader to drive strategy, processes, ownership, reporting, and continuous improvement within the security team. You will shape a robust governance program that aligns with business needs and regulatory expectations.

In this role, you will oversee FedRAMP and related certifications, maintain SSPs, coordinate evidence quality, support annual assessments, and manage remediation efforts.

Qualifications

  • 6+ years in GRC, security governance, compliance, audit, or risk management.
  • Hands-on FedRAMP experience including authorization, continuous monitoring, SSP maintenance, evidence management, assessments, and POA&M coordination.
  • Exposure to DoD IL4/IL5 or CMMC and similar programs.
  • Working knowledge of NIST SP 800-53 and control expectations for FedRAMP/CMMC.
  • Proven ability to manage people and to communicate credibly with auditors, technical teams, customers, and executives.
  • Strong written communication for policies, procedures, narratives, responses, risk summaries, and executive updates.

Responsibilities

  • Lead and mature the Security Governance function as part of the security team, covering strategy, processes, ownership, reporting, and continuous improvement.
  • Maintain and strengthen FedRAMP, IL4, and CMMC authorizations by managing documentation, SSP updates, evidence quality, control-owner coordination, audit readiness, and annual assessment support.
  • Support FedRAMP continuous monitoring activities, including evidence collection, monthly/annual deliverables, risk documentation, remediation commitments, approvals, and deadlines.
  • Coordinate with agency Authorizing Officials, 3PAOs, agency stakeholders, auditors, and control owners through assessments and ongoing authorization activity.
  • Own the lifecycle of security policies, standards, and procedures, keeping documentation aligned with actual business and technical practice.
  • Manage customer trust and assurance activities, including customer security reviews, questionnaires, RFPs, due-diligence responses, and reusable evidence packages.
  • Communicate governance, compliance, audit, and risk topics clearly to technical teams, customers, auditors, executives, and business stakeholders.

Skills

GRC
Security governance
FedRAMP
POA&M coordination
NIST SP 800-53
Vendor management
Audit communications

Tools

Documentation tools

Job description

Responsibilities
  • Lead and mature the Security Governance function as part of the broader Security team, covering strategy, processes, ownership, reporting, and continuous improvement.
  • Maintain and strengthen Unison’s authorizations and certifications, including FedRAMP, IL4, and CMMC, by managing documentation, SSP updates, evidence quality, control-owner coordination, audit readiness, and annual assessment support.
  • Support FedRAMP continuous monitoring activities, including recurring evidence collection, monthly and annual deliverables, risk documentation, remediation commitments, approvals, and deadlines.
  • Coordinate with agency Authorizing Officials, 3PAOs, agency stakeholders, auditors, and control owners through assessments and ongoing authorization activity.
  • Own the lifecycle of security policies, standards, and procedures, keeping documentation aligned with actual business and technical practice.
  • Manage customer trust and assurance activities, including customer security reviews, questionnaires, RFPs, due-diligence responses, and reusable evidence packages.
  • Communicate governance, compliance, audit, and risk topics clearly to technical teams, customers, auditors, executives, and business stakeholders.
Requirements
  • 6+ years in GRC, security governance, compliance, audit, or risk management.
  • Hands‑on FedRAMP experience, including authorization, continuous monitoring, SSP maintenance, evidence management, assessments, annual assessment support, and POA&M coordination.
  • Exposure to other federal authorizations and certifications such as DoD IL4/IL5 or CMMC.
  • Working knowledge of NIST SP 800-53 and the control expectations behind FedRAMP, CMMC, and similar programs, including authorization documentation and audit evidence practices.
  • Proven ability to manage people and vendors and to communicate credibly with auditors, technical teams, customers, and executives.
  • Strong written communication skills, including the ability to produce clear policies, procedures, control narratives, customer responses, risk summaries, and executive‑ready updates.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Lead
Security GRC Lead

Jobtailor • Washington

On-site
USD 150,000 - 190,000
Security and Compliance Lead
Security and Compliance Lead

247Hire • North Dakota

On-site
USD 120,000 - 170,000
Lead Federal Auditor
Lead Federal Auditor

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
CMMC Continuous Compliance Analyst
CMMC Continuous Compliance Analyst

Jobtailor • United States

On-site
USD 85,000 - 120,000
Information System Security Engineer
Information System Security Engineer

CACI International Inc • Leesburg (VA)

On-site
USD 120,000 - 180,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Security Engineering Controls Program Lead
Security Engineering Controls Program Lead

Jobtailor • California (MO)

On-site
USD 60,000 - 90,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
IT and Security Manager
IT and Security Manager

brightline • Ashburn (VA)

On-site
USD 150,000 - 190,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus