FedRAMP Program Manager; On-Site
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Full Time Technical Centreville, VA, US
Salary Range: $ To $ Annually
Job Summary:Neumo is seeking an experienced FedRAMP Program Manager to lead the company's end-to-end pursuit of FedRAMP High authorization. This role owns the authorization program from readiness assessment through Authority to Operate (ATO) and into steady-state continuous monitoring, and is accountable for keeping the effort on schedule, on budget, and audit-ready. Because FedRAMP High remains available only through the traditional agency-sponsored authorization path this role will also manage the agency sponsor relationship and Third-Party Assessment Organization (3
PAO) engagement directly.
This is a highly cross-functional role. Success requires close, sustained collaboration with Engineering, IT, Product, Legal, Finance, and HR to translate NIST 800-53 High-baseline control requirements into practical engineering and business decisions, and to hold each function accountable for its share of the authorization package. The FedRAMP Program Manager reports to the CISO and serves as the single point of accountability for getting Neumo through a successful, well-documented certification process.
Duties and Responsibilities:- Own and drive the overall FedRAMP High authorization program plan, including scope, schedule, budget, milestones, dependencies, and executive-level status reporting.
- Serve as primary liaison to the sponsoring federal agency, the FedRAMP PMO, and the selected 3
PAO throughout readiness assessment, security assessment, and authorization decision. - Coordinate development and maintenance of the System Security Plan (SSP), Plan of Action and Milestones (POA&M), Security Assessment Plan/Report (SAP/SAR), and supporting control implementation evidence in partnership with Engineering and IT.
- Partner with Engineering and IT leadership to close control gaps against the NIST SP 800-53 High baseline, including boundary definition, FIPS-validated encryption, logging/monitoring, and incident response capabilities.
- Work with Product to align roadmap decisions, environment/architecture choices, and feature rollout timing with authorization requirements and change-control obligations.
- Coordinate with Legal on agency sponsorship agreements, contractual FedRAMP obligations, data handling/CUI requirements, and third-party/subcontractor risk.
- Partner with Finance to build and manage the FedRAMP program budget, including 3
PAO assessment costs, tooling, staff augmentation, and multi-year continuous monitoring costs. - Work with HR to define staffing needs, support role-based access and personnel security requirements, and build FedRAMP/security-awareness training for affected teams.
- Stand up and facilitate a recurring cross-functional governance cadence (steering committee, working sessions, risk reviews) to keep all stakeholders aligned and unblocked.
- Manage and track risks, issues, and open POA&M items to closure; elevate blockers to the CISO and executive sponsors with clear options and recommendations.
- Select and manage GRC/compliance tooling used to track controls, evidence, and continuous monitoring artifacts.
- Lead the transition from initial ATO into steady-state continuous monitoring, including annual assessments, significant change request (SCR) management, and ongoing 3
PAO and agency relationship management. - Prepare and deliver regular program updates to executive leadership
- Perform other duties as assigned.
- Bachelor's degree in Information Security, Computer Science, Business, Public Administration, or related field; equivalent experience considered.
- 7+ years of experience in security compliance, GRC, or IT audit program management; 3+ years directly managing a FedRAMP High authorization effort.
- Demonstrated experience taking a system through 3
PAO assessment and agency (or JAB) authorization to an ATO. - Working knowledge of NIST SP 800-53, NIST SP 800-37 (Risk Management Framework), FedRAMP Rev5 requirements, and awareness of the evolving FedRAMP 20x program structure.
- Experience managing complex, cross-functional programs involving Engineering, IT, Legal, Finance, and HR stakeholders.
- PMP, CISSP, CISA, CAP, or similar certification preferred.
- Prior experience with agency sponsorship processes and federal customer engagement strongly preferred.
- Hands-on experience with AWS Gov Cloud and/or Microsoft Azure Government environments, including standing up or operating within FedRAMP-authorized boundaries, strongly preferred.
Skills and Abilities
- Deep working knowledge of NIST 800-53 High-baseline controls and the FedRAMP authorization lifecycle.
- Working knowledge of AWS Gov Cloud and Azure Government service offerings, boundary/architecture models, and their respective FedRAMP compliance implications.
- Strong program and project management skills, including schedule, budget, risk,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).