Sr Program Manager, Continuous Monitoring

SAS

Cary (NC)

Hybrid

USD 120,000 - 160,000

Full time

35 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health benefits
401k plan
Tuition assistance
Vacation & holidays
Parental leave
Childcare benefits

Job summary

SAS is seeking a Senior Program Manager for Continuous Monitoring in Cary, NC, with a hybrid work model. You will drive the Continuous Monitoring program, coordinate cross-functional teams, manage artifacts, evidence, and reporting to support authorization and certification efforts.

You will partner with Global Information Security, Governance, Risk, Compliance and Audit, Cloud Operations and agency stakeholders to improve audit readiness, reduce risk, and align with regulatory requirements

Qualifications

  • Bachelor's degree in computer science, information systems, risk management, cybersecurity, business administration, or a related field.
  • Eight years of experience managing security, compliance, audit, governance, technology, or risk-related programs in a cloud or regulated technology environment.
  • Experience with continuous monitoring, POA&M management, vulnerability management, security control assessment, and evidence management.

Responsibilities

  • Manage the Continuous Monitoring program for SAS Managed Cloud Services, including recurring deliverables, artifact readiness, stakeholder coordination, and submission timelines.
  • Track vulnerabilities, deviation requests, remediation plans, milestones, and success metrics to support timely risk visibility and resolution.
  • Lead cross-functional alignment with Global Information Security, Governance, Risk, Compliance and Audit, Product Management, Cloud Operations, agency stakeholders, consultants, and assessment teams.
  • Oversee the readiness, quality, and timely submission of Continuous Monitoring artifacts, evidence, and reporting packages required to support authorization and certification commitments.
  • Lead recurring Continuous Monitoring operating cadences that drive agency alignment, internal decision-making, status visibility, issue follow-up, and risk escalation.
  • Coordinate key activities within the annual 3PAO security assessment lifecycle, with a focus on remediation status and SLA aging.

Skills

Program management
Security governance
Cross-functional leadership
Continuous Monitoring
Policy compliance

Education

Bachelor's degree in a related field (see description)

Tools

GRC platforms
Vulnerability management tools
Ticketing systems

Job description

Senior Program Manager, Continuous Monitoring - Hybrid, Cary, North Carolina

We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.

If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.

About The Job

The Managed Cloud Services organization within the Cloud and Information Services (CIS) division is seeking a Senior Program Manager focused on Continuous Monitoring to strengthen program execution, improve audit readiness, and support consistent compliance outcomes across SAS Managed Cloud Services.

In this role, you will partner with security, compliance, cloud operations, and agency stakeholders to manage recurring Continuous Monitoring activities, maintain required evidence and reporting, coordinate assessments, and reduce operational risk. This opportunity comes at a pivotal time, as the organization continues to grow rapidly and strengthen its enterprise operating model.

As a Senior Program Manager focused on Continuous Monitoring, you will:
  • Manage the Continuous Monitoring program for SAS Managed Cloud Services, including recurring deliverables, artifact readiness, stakeholder coordination, and submission timelines.
  • Track vulnerabilities, deviation requests, remediation plans, milestones, and success metrics to support timely risk visibility and resolution.
  • Lead cross-functional alignment with Global Information Security, Governance, Risk, Compliance and Audit, Product Management, Cloud Operations, agency stakeholders, consultants, and assessment teams.
  • Oversee the readiness, quality, and timely submission of Continuous Monitoring artifacts, evidence, and reporting packages required to support authorization and certification commitments.
  • Lead recurring Continuous Monitoring operating cadences that drive agency alignment, internal decision-making, status visibility, issue follow-up, and risk escalation.
  • Coordinate key activities within the annual 3PAO security assessment lifecycle, with a focus on remediation status and SLA aging
  • Shape and mature the Continuous Monitoring program roadmap, aligning regulatory requirements, customer commitments, operational priorities, reporting standards, and organizational growth objectives.
  • Drive cross-functional action with technical teams to assess security control effectiveness, surface compliance gaps and lifecycle risks, and advance required remediation actions.
  • Ensure all applicable security policies and processes are followed to support the organization's secure software development goals.
  • Embrace curiosity, passion, authenticity and accountability. These are our values and influence everything we do.
Required Qualifications
  • Bachelor’s degree in computer science, information systems, risk management, cybersecurity, business administration, or a related field.
  • Eight years of experience managing security, compliance, audit, governance, technology, or risk-related programs in a cloud or regulated technology environment.
  • Demonstrated experience with continuous monitoring, POA&M management, vulnerability management, security control assessment, and evidence management.
  • Experience working with cloud infrastructure, SaaS, managed services, cybersecurity, compliance, privacy, DevOps, or cloud operations teams.
  • Demonstrated ability to influence outcomes across cross-functional technical, compliance, and senior leadership stakeholders while managing milestones, risks, and decisions.
  • Strong execution discipline with the ability to manage multiple recurring deliverables, documentation cycles, reporting timelines, and assessment activities concurrently.
  • Ability to translate security and compliance requirements into actionable plans, operating cadences, and measurable outcomes.
  • Equivalent combination of related education, training and experience may be considered in place of the above qualifications.
Preferred Qualifications
  • Prior experience supporting FedRAMP Moderate or High environments, CSP continuous monitoring submissions, or agency authorization activities.
  • Practical experience applying federal compliance standards and frameworks, such as NIST 800-53, FedRAMP, FISMA, NIST SP 800-30, NIST SP 800-34, or NIST 800-171, in a cloud or regulated technology environment.
  • Experience using GRC platforms, vulnerability management tools, ticketing systems, evidence repositories, or compliance reporting workflows.
  • Understanding of public cloud architectures, SaaS/IaaS operating models, managed services, and lifecycle management in regulated environments.
  • Security, compliance, risk, audit, or program management certifications such as CISA, CISSP, Security+, CRISC, CISM, PMP, or other industry-recognized credentials.
Requirements
  • U.S. citizenship is required.
  • Successful completion of a background check is required.
World-class Benefits

Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include:
  • PPO with low annual deductible and copays.
  • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Tuition Assistance Program and programs and resources to support your development
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.
You are welcome here.

At SAS, it's not about fitting into our culture - it's about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.

Additional Information

To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law. Read more: Know Your Rights.

Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process.

SAS only sends emails from verified “sas.com” email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact Recruitingsupport@sas.com.

Let's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more.

#SAS

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, GRC-A (Information Security Risk)
Manager, GRC-A (Information Security Risk)

Sas • Cary (NC)

Hybrid
USD 140,000 - 180,000
Comprehensive medical, prescription, –
401k plan
Tuition Assistance Program
+5
Senior Program Manager, Continuous Monitoring & Compliance
Senior Program Manager, Continuous Monitoring & Compliance

SAS • Cary (NC)

Hybrid
USD 120,000 - 160,000
Health benefits
401k plan
Tuition assistance
+3
Sr Application Security Architect
Sr Application Security Architect

Sas • Cary (NC)

On-site
USD 140,000 - 210,000
Comprehensive medical, prescription, 

401k plan
Tuition Assistance Program
+1
Managed Cloud Services Senior Offering Manager, Hyperscaler
Managed Cloud Services Senior Offering Manager, Hyperscaler

SAS • Cary (NC)

Hybrid
USD 130,000 - 170,000
Comprehensive medical plans
Industry-leading 401k
Tuition assistance
+2
Manager, Software Development
Manager, Software Development

Sas • Cary (NC)

On-site
USD 140,000 - 190,000
Comprehensive medical/dental/vision
401k plan
Tuition assistance
+1
Sr. Software Development Engineer in Test (SDET)
Sr. Software Development Engineer in Test (SDET)

SAS • Cary (NC)

Hybrid
USD 90,000 - 120,000
Comprehensive medical, prescription, dental and vision plans.
Onsite Health Care Center with pharmacy.
Generous time off including vacation time.
Software Development Manager, SAS Developer Portal
Software Development Manager, SAS Developer Portal

Sas • Cary (NC)

Hybrid
USD 140,000 - 180,000
Medical plan
401k plan
Paid holidays
+2
AI/Model Security Architect
AI/Model Security Architect

Sas • Cary (NC)

Hybrid
USD 150,000 - 210,000
Comprehensive benefits
401k plan
Tuition assistance
+4
SDET: Data & AI Test Automation (Hybrid)
SDET: Data & AI Test Automation (Hybrid)

SAS • Cary (NC)

On-site
Senior SDET
Senior SDET

SAS • Cary (NC)

Hybrid
USD 110,000 - 160,000
Health insurance
401k plan
Tuition assistance
+6