Experience supporting the FedRAMP Authorization to Operate process. * Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP. * Relevant security or compliance ...
New
Experience supporting the FedRAMP Authorization to Operate process. * Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP. * Relevant security or compliance ...
New
Experience supporting the FedRAMP Authorization to Operate process. * Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP. * Relevant security or compliance ...
New
$140K - $181K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
$140K - $181K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
$140K - $181K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
Quick apply
$140K - $181K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
Boston, MA · On-site +1
$140K - $181K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
Boston, MA · On-site +1
$140K - $181K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
$140K - $182K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
$140K - $182K/yr
S. public sector compliance programs. This is a high-impact, cross-functional role responsible for driving FedRAMP and similar regulatory processes, keeping the authorized system operating ...
Spring, TX · On-site
$130K - $205K/yr
The role manages its workstreams in support of the SOX program and monitors performance against the ... FedRAMP Compliance • Governance Risk and Compliance • Information Technology Audit • ...
Spring, TX · On-site
$130K - $205K/yr
The role manages its workstreams in support of the SOX program and monitors performance against the ... FedRAMP Compliance • Governance Risk and Compliance • Information Technology Audit • ...
$130K - $205K/yr
The role manages its workstreams in support of the SOX program and monitors performance against the ... FedRAMP Compliance Governance Risk and Compliance Information Technology Audit Information ...
$130K - $205K/yr
The role manages its workstreams in support of the SOX program and monitors performance against the ... FedRAMP Compliance Governance Risk and Compliance Information Technology Audit Information ...
$144K - $180K/yr
You'll build, implement, and scale Spellbook's US compliance program across government, healthcare, ... NICE TO HAVES • Experience supporting or implementing TX-RAMP, GovRAMP, FedRAMP, or other public ...
$144K - $180K/yr
You'll build, implement, and scale Spellbook's US compliance program across government, healthcare, ... NICE TO HAVES • Experience supporting or implementing TX-RAMP, GovRAMP, FedRAMP, or other public ...
Collaborate and communicate Federal Compliance requirements to a wide range of stakeholders ... Support the FedRAMP program and ensuring program milestones are hit * Develop and maintain System ...
Collaborate and communicate Federal Compliance requirements to a wide range of stakeholders ... Support the FedRAMP program and ensuring program milestones are hit * Develop and maintain System ...
Jersey City, NJ · On-site
$45K - $59K/yr
This is your opportunity to play a pivotal role in shaping how a leading global financial institution governs and advances its FedRAMP compliance program. As a Vice President, Tech Risk & Controls ...
Jersey City, NJ · On-site
$45K - $59K/yr
This is your opportunity to play a pivotal role in shaping how a leading global financial institution governs and advances its FedRAMP compliance program. As a Vice President, Tech Risk & Controls ...
Jersey City, NJ · On-site
$45K - $59K/yr
This is your opportunity to play a pivotal role in shaping how a leading global financial institution governs and advances its FedRAMP compliance program. As a Vice President, Tech Risk & Controls ...
Jersey City, NJ · On-site
$45K - $59K/yr
This is your opportunity to play a pivotal role in shaping how a leading global financial institution governs and advances its FedRAMP compliance program. As a Vice President, Tech Risk & Controls ...
New York, NY · On-site
$140K - $190K/yr
Build and run the master compliance program covering FedRAMP High, IL5, CMMC Level 2, SOC 2, and adjacent public‑sector frameworks. * Drive the FedRAMP High ATO roadmap end‑to‑end, including ...
New York, NY · On-site
$140K - $190K/yr
Build and run the master compliance program covering FedRAMP High, IL5, CMMC Level 2, SOC 2, and adjacent public‑sector frameworks. * Drive the FedRAMP High ATO roadmap end‑to‑end, including ...
Demonstrated experience executing continuous monitoring or recurring compliance reporting programs (monthly cadence preferred). * Working knowledge of NIST 800-53 and FedRAMP concepts (POA&M ...
Demonstrated experience executing continuous monitoring or recurring compliance reporting programs (monthly cadence preferred). * Working knowledge of NIST 800-53 and FedRAMP concepts (POA&M ...
Develop architecture briefing documents to inform the Government FedRAMP program manager and CISO of CSP compliance with FedRAMP program requirements, technical capabilities, and any concerns noted ...
Develop architecture briefing documents to inform the Government FedRAMP program manager and CISO of CSP compliance with FedRAMP program requirements, technical capabilities, and any concerns noted ...
Develop architecture briefing documents to inform the Government FedRAMP program manager and CISO of CSP compliance with FedRAMP program requirements, technical capabilities, and any concerns noted ...
New
Develop architecture briefing documents to inform the Government FedRAMP program manager and CISO of CSP compliance with FedRAMP program requirements, technical capabilities, and any concerns noted ...
New
Alexandria, VA · Hybrid
$59.50 - $79.75/hr
ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business ... for Program Support on a Exempt W2: No Overtime Pay Basis located in the Mid Atlantic Region and ...
Quick apply
Alexandria, VA · Hybrid
$59.50 - $79.75/hr
ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business ... for Program Support on a Exempt W2: No Overtime Pay Basis located in the Mid Atlantic Region and ...
Alexandria, VA · Hybrid
$59.50 - $79.75/hr
ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business ... for Program Support on a Exempt W2: No Overtime Pay Basis located in the Mid Atlantic Region and ...
Alexandria, VA · Hybrid
$59.50 - $79.75/hr
ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business ... for Program Support on a Exempt W2: No Overtime Pay Basis located in the Mid Atlantic Region and ...
Security & Compliance Program Ownership ... Own end-to-end program execution for LVT's FedRAMP authorization effort and related regulatory ...
New
Security & Compliance Program Ownership ... Own end-to-end program execution for LVT's FedRAMP authorization effort and related regulatory ...
New
The Opportunity We are seeking a Government Compliance Manager who is highly motivated, delivery ... for FedRAMP and GovRAMP programs. * Lead FedRAMP and GovRAMP Readiness Assessments: Lead gap ...
The Opportunity We are seeking a Government Compliance Manager who is highly motivated, delivery ... for FedRAMP and GovRAMP programs. * Lead FedRAMP and GovRAMP Readiness Assessments: Lead gap ...
$116K - $177K/yr
Enterprise Compliance Maintenance ... Serves as the FedRAMP Program Manager * Work with various IT groups to ensure that IT systems ...
$116K - $177K/yr
Enterprise Compliance Maintenance ... Serves as the FedRAMP Program Manager * Work with various IT groups to ensure that IT systems ...
$31.5K - $47.5K
10% of jobs
$60.4K is the 25th percentile. Wages below this are outliers.
$47.5K - $63.5K
19% of jobs
$63.5K - $79.5K
19% of jobs
The median wage is $81.5K / yr.
$79.5K - $95.5K
17% of jobs
$106.4K is the 75th percentile. Wages above this are outliers.
$95.5K - $111.5K
15% of jobs
$111.5K - $127.5K
6% of jobs
$127.5K - $143.5K
5% of jobs
$143.5K - $159.5K
3% of jobs
$159.5K - $175.5K
2% of jobs
$175.5K - $191.5K
2% of jobs
$191.5K - $207.5K
1% of jobs
$31.5K
$98.9K
$207.5K
A FedRAMP Compliance Program job involves managing and ensuring that cloud service providers (CSPs) follow the Federal Risk and Authorization Management Program (FedRAMP) requirements. This includes coordinating security assessments, working with Third-Party Assessment Organizations (3PAOs), and maintaining continuous monitoring to meet federal cybersecurity standards. Professionals in this role collaborate with internal teams and government agencies to navigate the authorization process, remediate security findings, and ensure compliance with evolving regulations. They also develop policies, documentation, and risk management frameworks to support a CSP’s adherence to FedRAMP guidelines.
As a FedRAMP Compliance Program manager, your daily tasks often involve coordinating security assessments, reviewing documentation for accuracy, and ensuring continuous monitoring requirements are met. You’ll work closely with IT, security, and legal teams to interpret federal regulations and implement necessary controls in cloud environments. Regular communication with cloud service providers, third-party assessment organizations, and federal agencies is common to address compliance gaps and maintain certification status. This role requires diligent tracking of project timelines and staying current with evolving FedRAMP requirements. Being proactive and detail-oriented can help you successfully navigate the unique challenges of federal cloud security compliance.
To excel in a FedRAMP Compliance Program role, you need a solid understanding of IT security frameworks, risk management, and compliance standards, often backed by a degree in information security or related certifications such as CISSP, CISA, or FedRAMP Assessor. Familiarity with cybersecurity tools, GRC (Governance, Risk, and Compliance) platforms, and cloud security technologies is typically required. Strong project management, attention to detail, and excellent communication skills help in coordinating with stakeholders and interpreting complex requirements. These competencies are essential to ensure cloud service providers meet federal compliance standards and successfully navigate the FedRAMP authorization process.

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 2 days ago
8.9
Based on 19 frontline employees who took The Breakroom Quiz
16th of 427 rated business services
Are you ready to help secure the trusted technology that powers mission-critical decisions across government and highly regulated industries?
At Thomson Reuters, our technology supports customers who depend on secure, reliable, and compliant platforms to deliver essential outcomes. We are seeking aLead Governance & Compliance Analystto join ourOperations and Technologyorganization, supporting ourfederal government portfolio, including FedRAMP-authorized and in-process platforms for products such asLegal ResearchandRisk & Fraud.
This role is central to sustaining and evolving the FedRAMP compliance posture of Thomson Reuters' federal-facing products. As a senior technical and governance leader, you will help ensure our cloud environments remain continuously compliant, secure, audit-ready, and aligned with federal requirements. You will partner closely with engineering, product, operations, security, federal agencies, the FedRAMP PMO, and third-party assessment organizations to support authorization activities, strengthen security practices, and help maintain customer trust.
Please note:This position requires access to U.S. Federal Government systems and data under a federal government contract. In accordance with contractual requirements, applicants must beU.S. citizens. This requirement applies only to this role and is mandated by the applicable government contract; it is not a general company policy. Thomson Reuters is an equal opportunity employer.
In this opportunity asLead Governance & Compliance Analyst, you will:
Serve as a primary liaison with federal agencies, the FedRAMP PMO, third-party assessment organizations, consultants, and internal stakeholders to support ongoing authorization and compliance activities.
Lead FedRAMP Continuous Monitoring activities, including POA&M management, vulnerability reporting, monthly deliverables, and recurring agency reporting requirements.
Maintain and update the System Security Plan, risk documentation, assessment artifacts, and other required FedRAMP documentation to ensure ongoing audit readiness.
Manage vulnerability, risk, and incident response processes in alignment with FedRAMP, NIST RMF, and NIST SP 800-53 Rev. 5 requirements.
Support annual security assessments, including planning, scope definition, SAP preparation, security testing coordination, SAR development, POA&M updates, and project closure.
Partner with engineering, product, operations, and security teams to drive risk mitigation, compliance improvements, and secure delivery of federal-facing cloud solutions.
Educate and guide internal stakeholders on FedRAMP security requirements, continuous monitoring expectations, significant change processes, and compliance best practices.
You're a fit for the role ofLead Governance & Compliance Analystif your background includes:
5+ years of experience in cloud security architecture, security engineering, governance, risk, compliance, or related roles supporting federal or highly regulated workloads.
Demonstrated expertise with FedRAMP, NIST Risk Management Framework, and NIST SP 800-53 Rev. 5 security controls.
Experience supporting FedRAMP Continuous Monitoring, including vulnerability management, POA&M tracking, evidence collection, reporting, and control monitoring.
Experience conducting or supporting risk assessments, vulnerability scans, incident analysis, and remediation activities within a FedRAMP or regulated environment.
Strong communication skills with the ability to engage effectively with federal agencies, auditors, third-party assessors, technical teams, and senior stakeholders.
Ability to analyze security and compliance data, identify trends or risks, and produce clear reports for leadership, agencies, and audit partners.
Bachelor's degree in cybersecurity, information security, computer science, or a related discipline, or equivalent professional experience.
Experience with cloud environments such as AWS, Azure, or Google Cloud Platform.
Experience supporting the FedRAMP Authorization to Operate process.
Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP.
Relevant security or compliance certifications such as CISSP, CISM, CISA, CCSP, Security+, or similar credentials.
#LI-LP2
What's in it For You?
Hybrid Work Model: We've adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.
Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow's challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
Making a Real-World Impact:We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.
About Us
Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.
We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.
As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.
Thomson Reuters makes reasonable accommodations for applicants with disabilities, including veterans with disabilities, and for sincerely held religious beliefs in accordance with applicable law. If you reside in the United States and require an accommodation in the recruiting process, you may contact our Human Resources Department atHR.Leave-Expert@thomsonreuters.com. Disability accommodations in the recruiting process may include things like a sign language interpreter, making interview rooms accessible, providing assistive technology, or other relevant accommodations. Please note this email is not intended for general recruitment questions and we will promptly respond to inquiries regarding accommodations. More information on requesting an accommodation here.
Learn more on how to protect yourself from fraudulent job postings here.
More information about Thomson Reuters can be found on thomsonreuters.com
Get the full story on Breakroom