Principal Technical Program Manager
Job in
Washington, District of Columbia, 20080, USA
Listed on 2026-08-31
Listing for:
Oracle
Full Time
position Listed on 2026-08-31
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
* Oracle Health is seeking a Principal Technical Program Manager to establish and lead the Product Authorization Team responsible for FedRAMP assessment readiness, authorization strategy, and continuous security assurance for cloud service offerings. This role combines principal-level technical program leadership with deep cloud security and compliance-engineering expertise.
You will create the operating model that turns federal security requirements into sustainable engineering practices, trusted evidence, measurable security outcomes, and clear executive decisions. You will work at the intersection of cloud architecture, security engineering, product delivery, and federal authorization. Success requires the ability to move comfortably between architecture and control discussions, third-party assessment strategy, remediation execution, and senior-leadership tradeoffs.
This is a hands-on leadership role. You will not serve as the independent assessor; however, you must have sufficient security-engineering depth to challenge design assumptions, assess evidence quality, identify material gaps, and drive practical remediation with technical teams.
** Responsibilities*
* + Stand up the Oracle Health Product Authorization Fed Ramp Team and define its charter, service model, roles, intake and prioritization process, governance cadences, quality standards, metrics, and escalation paths.
+ Own the multi-year FedRAMP authorization and certification roadmap for assigned cloud offerings, including scope, sequencing, authorization-path recommendations, dependencies, reuse opportunities, investment needs, and transition to continuous assurance.
+ Establish a scalable assessment operating model for readiness reviews, authorization-boundary definition, evidence planning, package development, 3
PAO engagement, testing, findings management, remediation validation, and post-authorization monitoring.
+ Partner with architecture and security-engineering teams to evaluate service boundaries, data flows, interconnections, multi-tenancy, identity, encryption, logging, resilience, supply-chain dependencies, control inheritance, and customer-responsible controls.
+ Translate FedRAMP, NIST, and federal risk-management requirements into owned, testable, time-bound engineering and operational deliverables; set acceptance criteria for evidence, security decisions, and remediation plans.
+ Design reusable evidence and assurance patterns using security telemetry, infrastructure as code, CI/CD controls, configuration validation, GRC workflows, machine-readable data, and automation where appropriate.
+ Lead strategic engagement with 3
PAOs, FedRAMP and agency stakeholders, federal customers, advisors, and critical suppliers; resolve escalations involving scope, testing, evidence, findings, or schedule.
+ Drive material risks, findings, and plans of action through root-cause analysis, prioritization, remediation, validation, risk acceptance, and closure; ensure decisions are documented and traceable.
+ Establish executive dashboards and operating reviews that show authorization readiness, critical-path dependencies, evidence quality, open findings, vulnerability and change posture, staffing needs, and decisions required.
+ Embed authorization obligations into secure software delivery, vulnerability management, incident response, change management, configuration management, contingency planning, and cloud operations.
+ Create a continuous-monitoring and ongoing-certification model that keeps authorization information current, supports required reporting, and enables agencies to make informed risk decisions.
+ Mentor TPMs and security partners, publish playbooks and reusable patterns, and raise the organization's capacity to deliver federal authorizations consistently without weakening security outcomes.
** Minimum Qualifications*
* + Bachelor's degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related discipline, or equivalent practical experience.
+ Seven or more years of experience in technical program management, security program leadership, cloud delivery, compliance engineering, security engineering, or a related technology field, including responsibility for complex cross-organizational programs.
+ Demonstrated experience leading an end-to-end FedRAMP certification or authorization, federal Authority to Operate, or comparably complex regulated cloud-assurance program from strategy or readiness through assessment, remediation, decision, and ongoing monitoring.
+ Deep working knowledge of FedRAMP authorization and certification processes; NIST SP 800-53 Rev. 5; FIPS 199; federal risk management; control implementation and assessment; control inheritance; significant change; vulnerability management; remediation; and continuous monitoring.
+ Strong technical understanding of SaaS and IaaS architecture, including authorization boundaries, multi-tenancy, identity and access management, network segmentation,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×