×
Register Here to Apply for Jobs or Post Jobs. X

Security Compliance & Assurance Manager

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: Port.io
Full Time position
Listed on 2025-12-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Consultant, Data Security
Job Description & How to Apply Below

At Port, we are pioneering a new dimension of the Developer Experience. Our innovative platform for Internal Developer Portals has been designed with the ultimate aim of enhancing developer satisfaction, increasing productivity, and ensuring the highest standards of engineering output. Port brings everything a developer needs together, encapsulated within a single user‑friendly interface. From comprehending the software development lifecycle, executing tasks, to adhering to the organization’s development standards, Port ensures that every aspect of software development is within easy reach for every developer.

As a team, we personify the values that underpin our product: openness, transparency, resourcefulness, community orientation, and kindness. We are on the lookout for like‑minded individuals who share our ethos to join us on our exciting journey of revolutionizing the platform engineering sector. By joining Port, you’ll be a part of a team that’s changing how developers collaborate, enabling them to work faster, smarter, and more efficiently.

Why

we're looking for you

We’re seeking a Security Compliance & Assurance Manager to own the hands‑on documentation, policy writing, and evidence management across Port’s security and compliance programs. This is a technical writing and audit readiness role supporting our FedRAMP authorization and broader GRC initiatives.

Who You'll Work With

You’ll report to the CIO and work closely with the GRC Manager and FedRAMP Program Manager as part of the Security & Risk team. You'll collaborate cross‑functionally with Engineering, Dev Ops, IT, and Product teams to document technical controls and collect evidence. You'll also partner with Legal, HR, and external auditors (3

PAOs, SOC 2 auditors) to ensure Port maintains and demonstrates the highest levels of security and compliance.

What You’ll Do
  • Write, maintain, and update the System Security Plan (SSP), Plan of Action & Milestones (POA & M), and all compliance documentation for FedRAMP authorization.
  • Develop and maintain security policies and procedures including access control, incident response, data classification, encryption, and acceptable use policies.
  • Lead evidence collection and audit readiness activities across multiple frameworks (FedRAMP, SOC 2, ISO 27001, GDPR).
  • Partner with Engineering, IT, and the GRC Manager to document technical control implementations and translate controls into clear policy language.
  • Support continuous monitoring activities, control testing, and remediation tracking.
  • Manage customer security questionnaires, RFPs, and Trust Center content to support sales and customer assurance efforts.
  • Maintain compliance tooling and dashboards (e.g., Drata, Tugboat Logic) for continuous visibility into control status.
  • Support internal and external audits with timely, complete evidence packages and coordinate with 3

    PAOs and auditors.
  • Build and maintain the compliance evidence repository and artifact management system.
  • Over time, evolve into a core GRC & Assurance leader supporting enterprise certifications and customer trust programs.
What We're Looking For
  • 5+ years in security compliance, audit, or assurance roles in SaaS or cloud environments.
  • Deep expertise in compliance frameworks (FedRAMP, SOC 2, ISO 27001) and control requirements.
  • Excellent technical writing and documentation skills – ability to translate complex technical controls into clear, comprehensive policies and procedures.
  • Hands‑on experience building and maintaining compliance evidence repositories and control testing programs.
  • Strong understanding of technical security controls (encryption, access management, logging, monitoring, network security).
  • Experience supporting audits and working with external assessors (3

    PAOs, SOC 2 auditors, ISO auditors).
  • Strong organizational skills and attention to detail with ability to manage multiple compliance work streams simultaneously.
  • Collaborative communication style – able to work effectively with technical and non‑technical stakeholders.
Nice to have
  • Direct FedRAMP authorization experience (SSP development, POA & M management, continuous monitoring).
  • Experience with customer‑facing security programs (Trust Center management, security questionnaires, vendor security assessments).
  • Hands‑on experience with GRC automation platforms (Drata, Tugboat Logic, Vanta, One Trust, Secureframe).
  • Background in technical security controls, risk management, or security engineering.
  • CISSP, CISA, CISM, or other security/compliance certifications.
  • Familiarity with GDPR, CCPA, or other privacy frameworks and regulations.
  • Experience in high‑growth SaaS or cloud infrastructure companies.
  • Technical background or ability to read/understand code and infrastructure configurations.
Senior level

Mid‑Senior level

Employment type

Full‑time

Job function

Accounting/Auditing and Finance

Industries

Technology, Information and Internet

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary