Sr. Security Program Manager, Commercial & Federal Compliance

Anaplan

Atlanta (GA)

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Anaplan is seeking an experienced Senior Program Manager to drive compliance initiatives across commercial and federal lines. You will coordinate legal, security, contracts, engineering, and ops to meet FedRAMP, CMMC, and ISO/SOC/HITRUST standards, while aligning with international market certifications.

You will translate complex regulations into actionable roadmaps, manage audits, and report progress to senior leadership.

Qualifications

  • Bachelor's degree or equivalent in a related field.
  • 6+ years of program or project management experience.
  • 3–5 years leading compliance, security, or risk programs.
  • Hands-on FedRAMP authorization and continuous monitoring experience.
  • Experience with ISO 27001, SOC 2, HITRUST CSF cycles.

Responsibilities

  • Own end-to-end program management for compliance initiatives across commercial and federal contracts.
  • Lead FedRAMP authorization and continuous monitoring with 3PAOs and sponsors.
  • Translate federal requirements into actionable program plans.
  • Direct international and commercial certification programs (ISO 27001, ISO 27701, SOC 2, HITRUST).
  • Develop roadmaps, schedules, and risk registers; mitigate slippage.
  • Coordinate audits, assessments, and remediation plans (POA&Ms).
  • Establish governance processes and SOPs for scalable compliance.
  • Manage relationships with auditors, regulators, and certification bodies.
  • Track program status and KPIs for executives and stakeholders.
  • Oversee multiple certification tracks across regions with competing priorities.
  • Stay current on FedRAMP, NIST, and international standards.

Skills

FedRAMP
ISO 27001
SOC 2
HITRUST CSF
NIST 800-171/800-53
3PAO coordination
Executive communication

Education

Bachelor's degree or equivalent experience

Tools

Wrike
SharePoint
Confluence
Jira

Job description

Sr. Security Program Manager, Commercial & Federal Compliance

Remote-Atlanta, United States

At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.

What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.

Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.

Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.

Supported by operating principles of being strategy-led, values -based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!

We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams — driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701,Cyber Essentials, TISAX). The ideal candidate is a skilled program leader who can translate complex, multi-jurisdictional regulatory requirements into actionable roadmaps, manage cross-functional execution, and communicate risk and progress clearly to senior leadership.

Your Impact
  • Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
  • Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle.
  • Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans.
  • Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX,ENS, Cyber Essentials), tailoring approach to each market's requirements.
  • Develop andmaintainprogram roadmaps, schedules, andprogramrisk registers; proactivelyidentifyand mitigateprojectrisks and schedule slippage across concurrent certification tracks.
  • Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, andtimelyremediation of findings (POA&Ms, corrective action plans).
  • Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business.
  • Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed.
  • Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
  • Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups.
  • Stay current on evolving federaland commercialregulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs.
Your Qualifications
  • Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
  • 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs.
  • Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) isrequired.
  • Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks).
  • Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53).
  • Strongtrack recordmanaging complex, cross-functional programs with multiple stakeholders and competing deadlines.
  • Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders.
  • Strong analytical and risk‑assessment skills, with the ability to translate regulatory language into practical operational requirements.
  • Proficiencywith program/project management tools (e.g.,Wrike, SharePoint,Confluence, Jira) and GRC platforms (e.g.,Archer,Vanta,ServiceNow GRC, or similar).
  • Must be a U.S. Citizen or U.S. Personresidingin the U.S. (FedRAMP Moderate/High requirement).
Nice to Haves
  • PMP,PgMP, or equivalent program management certification.
  • ISO 27001 Lead Auditor or Lead Implementer certification.
  • CISSP, CISA, or CISM.
  • Experience supporting a FedRAMP JAB or Agency authorization from initiation through ATO, including familiarity with OSCAL and continuous monitoring deliverables.
  • Experienceoperatingin multiple international markets and navigating varying regional compliance/certification requirements.
Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)

We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business.

DEIB improves our workforce, enhances trust with our partners and customers, and drives business success.

Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader.

We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique.

We hire you for who you are, and we want you to bring your authentic self to work every day!

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment.

Please contact us to request accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer III
Security Engineer III

Anaplan • San Francisco (CA)

On-site
USD 163,000 - 220,000
Staff Technical Program Manager - Cleared/Security
Staff Technical Program Manager - Cleared/Security

United States Digital Space LLC • McLean (VA)

On-site
USD 150,000 - 210,000
Director, Governance, Risk & Compliance
Director, Governance, Risk & Compliance

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
Senior GRC Analyst
Senior GRC Analyst

Workato • Palo Alto (CA)

On-site
USD 150,000 - 190,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
ICS Authorizations Program Analyst II
ICS Authorizations Program Analyst II

Signature Performance, Inc. • United States

On-site
USD 95,000 - 135,000
Health Insurance
401(k) Program with Employer Match
Paid Vacation
+1
Customer Success Strategy & Operations, Sr. Manager
Customer Success Strategy & Operations, Sr. Manager

Anaplan • San Francisco (CA)

On-site
USD 154,000 - 209,000
Manager, Government Compliance & Authorization
Manager, Government Compliance & Authorization

United States Digital Space LLC • United States

Remote
USD 126,000 - 154,000
401K match
Flexible PTO
Health & Wellness programs
+1
Senior Compliance Engineer, AI Governance
Senior Compliance Engineer, AI Governance

True Anomaly • Long Beach (CA)

Hybrid
USD 150,000 - 205,000
Health
Dental
Vision
+3
Third Party Risk Analyst
Third Party Risk Analyst

Anaplan • Reston (VA)

On-site
USD 85,000 - 120,000