Sr. Security Program Manager, Commercial & Federal Compliance
Listed on 2026-07-30
-
IT/Tech
-
Management
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.
What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.
Our customers rank among the who’s who in the Fortune 50. Coca-Cola, Linked In, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in‑class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.
Supported by operating principles of being strategy-led, values –based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!
We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams — driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701, Cyber Essentials, TISAX).
The ideal candidate is a skilled program leader who can translate complex, multi‑jurisdictional regulatory requirements into actionable roadmaps, manage cross‑functional execution, and communicate risk and progress clearly to senior leadership.
- Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
- Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3
PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle. - Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800‑171/800‑53) and translate them into program plans.
- Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market‑access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market’s requirements.
- Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks.
- Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans).
- Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business.
- Build and manage relationships with external auditors, 3
PAOs, certification bodies, regulators, and government program offices as needed. - Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
- Manage a portfolio of compliance‑related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups.
- Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs.
- Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
- 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).