1

Fedramp Program Manager Jobs in California (NOW HIRING)

Senior DevSecOps Engineer

San Francisco, CA · Remote

$134K - $185K/yr

Support FedRAMP authorization activities: contribute to SSP documentation, NIST 800-53 control ... strategically managing programs and less time wrangling spreadsheets. We are disrupting the ...

... FedRAMP High / DoD IL5 / CMMC), and integration with both internal tools and third-party systems ... Partner with the Senior Director of Software Engineering and the Cybersecurity Program Manager to ...

... FedRAMP High / DoD IL5 / CMMC), and integration with both internal tools and third-party systems ... Partner with the Senior Director of Software Engineering and the Cybersecurity Program Manager to ...

Principal Engineer

Sunnyvale, CA · On-site

$180K - $230K/yr

... FedRAMP High / DoD IL5 / CMMC), and integration with both internal tools and third-party systems ... Partner with the Senior Director of Software Engineering and the Cybersecurity Program Manager to ...

VP, Information Security and Compliance

Irvine, CA · On-site

$135K - $182K/yr

FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required ... Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ...

... FedRAMP High / DoD IL5 / CMMC), and integration with both internal tools and third-party systems ... Partner with the Senior Director of Software Engineering and the Cybersecurity Program Manager to ...

Director Cybersecurity

Sunnyvale, CA · On-site

$200K - $260K/yr

Oversee risk management programs, including enterprise risk assessments and mitigation strategies. * Ensure compliance with government and public sector security requirements (e.g., FedRAMP, CJIS, or ...

Own independent audits and regulatory programs including ISO 42001, PCI DSS, NIST 800-53, FedRAMP ... management. * Design and operate automated compliance workflows using AI, infrastructure as code ...

Director Cybersecurity

Sunnyvale, CA · On-site

$200K - $260K/yr

Oversee risk management programs, including enterprise risk assessments and mitigation strategies. * Ensure compliance with government and public sector security requirements (e.g., FedRAMP, CJIS, or ...

FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required ... Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ...

VP, Information Security and Compliance

Irvine, CA · On-site

$135K - $181K/yr

FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required ... Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ...

Oversee risk management programs, including enterprise risk assessments and mitigation strategies. * Ensure compliance with government and public sector security requirements (e.g., FedRAMP, CJIS, or ...

Oversee risk management programs, including enterprise risk assessments and mitigation strategies. * Ensure compliance with government and public sector security requirements (e.g., FedRAMP, CJIS, or ...

Showing results 41-60

Fedramp Program Manager information

What is a FedRAMP Program Manager?

A FedRAMP Program Manager is a professional responsible for overseeing and coordinating the process of achieving and maintaining Federal Risk and Authorization Management Program (FedRAMP) compliance for cloud service providers or government agencies. They manage documentation, security assessments, and communication with stakeholders to ensure all requirements are met according to federal standards. Their role is crucial for enabling secure cloud adoption within U.S. government agencies, as they guide the project through the FedRAMP authorization process from start to finish.

What are the key skills and qualifications needed to thrive as a FedRAMP Program Manager?

To thrive as a FedRAMP Program Manager, you need expertise in cloud security, risk management, compliance frameworks, and a solid understanding of FedRAMP requirements, usually backed by a degree in IT, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53 controls, and certifications such as CISSP or PMP is highly beneficial. Strong project management, stakeholder communication, and problem-solving skills set candidates apart in this role. These competencies are essential for guiding organizations through complex FedRAMP authorization processes and ensuring ongoing compliance with federal security standards.

What are the main challenges a FedRAMP Program Manager faces when coordinating compliance efforts across multiple teams?

A FedRAMP Program Manager often navigates complex challenges such as aligning cross-functional teams—including IT, security, legal, and operations—to meet rigorous federal cloud security requirements and tight deadlines. Coordinating documentation, ensuring continuous monitoring, and responding to security assessments demand strong project management and communication skills. Additionally, managing evolving compliance standards and liaising with external auditors or government representatives can add to the complexity. Success in this role depends on the ability to facilitate collaboration, maintain meticulous records, and quickly adapt to regulatory updates.

What is the difference between Fedramp Program Manager vs Cloud Security Manager?

AspectFedramp Program ManagerCloud Security Manager
CertificationsFedRAMP certifications, PMP, CISSPCISSP, CCSP, Cloud Security certifications
Work EnvironmentFederal agencies, cloud service providers, government projectsPrivate sector, cloud service providers, enterprise security teams
Industry UsageFederal government compliance, cloud authorizationCloud security strategy, risk management

The Fedramp Program Manager primarily focuses on managing FedRAMP compliance and federal cloud authorization processes, often working within government or contractor environments. In contrast, the Cloud Security Manager oversees overall cloud security strategies and risk mitigation in private or enterprise settings. While both roles require cloud security knowledge and certifications like CISSP, their scope and industry focus differ significantly.

What are popular job titles related to Fedramp Program Manager jobs in California?

For Fedramp Program Manager jobs in California, the most frequently searched job titles are:

What job categories do people searching Fedramp Program Manager jobs in California look for?

The top searched job categories for Fedramp Program Manager jobs in California are:

What cities in California are hiring for Fedramp Program Manager jobs?

Cities in California with the most Fedramp Program Manager job openings:

Infographic showing various Fedramp Program Manager job openings in California as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Senior DevSecOps Engineer

Hyperproof

San Francisco, CA • Remote

$134K - $185K/yr

Full-time

Re-posted 8 days ago


Job description

Senior DevSecOps Engineer (Remote-based role that requires US-citizenship)

About us

Hyperproof is on a mission to transform the Governance, Risk, and Compliance (GRC) world with a powerful new software platform. With Hyperproof, companies can save time and money while also operating their programs at a much higher level of effectiveness and accountability. We envision a world where organizations we depend on are truly trustworthy - and Hyperproof is the platform that will get them there.

We have a great team and culture - picture yourself in a highly collaborative startup environment where you can make a real impact on something truly important. It's an exciting time to be at Hyperproof; we raised our Series B round in 2023, validating our teamwork and company vision, and we continue to grow rapidly.

As we continue to grow, we are seeking a talented Senior DevSecOps Engineer to join our team and lead our efforts in supporting our multi-region, FedRAMP-authorized infrastructure.

WHO YOU ARE:

You are a seasoned Senior DevSecOps Engineer with a passion for ensuring the reliability, scalability, and security of cloud-based infrastructure. You thrive in dynamic environments and possess a deep understanding of Azure technologies. Your expertise in DevOps methodologies and security practices, and federal compliance standards makes you an invaluable asset to any team.

You excel at collaborating with cross-functional teams and are dedicated to driving innovation and continuous improvement. You understand that compliance and developer velocity are not opposing forces — and you know how to architect systems that deliver both.

WHAT YOU WILL DO:

As a Senior DevSecOps Engineer, you will lead the management and optimization of Hyperproof's Azure-based infrastructure across commercial and FedRAMP regions. Your responsibilities will include:

  • Develop and execute DevOps strategy tailored to all Hyperproof regions, including our FedRAMP-authorized environments.
  • Own and evolve our Terraform/Terragrunt IaC pipeline for multi-subscription promotion, including continuous monitoring
  • Architect secure, scalable platform infrastructure including GitHub Actions, GitLab, and ADO CI/CD pipelines with security gates, Kubernetes environments, observability systems, and compliance automation that enables developer velocity while maintaining continuous compliance posture.
  • Support FedRAMP authorization activities: contribute to SSP documentation, NIST 800-53 control implementations, 3PAO coordination, and readiness assessments while establishing repeatable processes.
  • Establish security and compliance architecture patterns across encryption, network segmentation, secrets management, supply chain security, and incident response.
  • Drive technical decisions and technology selection for cloud platforms, compliance tooling, and security controls.
  • Mentor and raise the technical bar across engineering teams through architecture reviews, design discussions, and establishing FedRAMP best practices.
  • Partner with security, product, and business leadership to translate federal customer requirements into technical architecture and deliver measurable improvements in security posture and operational efficiency.
  • Monitor, triage, and remediate CVEs and security vulnerabilities across infrastructure, container images, and dependencies — maintaining compliance with FedRAMP continuous monitoring requirements.

WHAT YOU WILL BRING:
Required:

  • U.S. citizenship, residing and working from within the United States.*
  • BS in Computer Science, Engineering, or a related field (or equivalent experience).
  • 5+ years of extensive experience in SRE, DevSecOps or Platform engineering roles, with a focus on managing Azure-based infrastructure.
  • Demonstrated knowledge and interest in applying AI technologies towards fully or partially automating compliance & security workflows
  • Strong programming skills (Python, Bash, Go, or Node.js) and demonstrated ability to drive complex technical initiatives from architecture through production.
  • Expertise in modern platform technologies: Kubernetes security, infrastructure-as-code (Terraform/Terragrunt), GitOps (Helm/ArgoCD/Flux), Ansible, CI/CD security, observability systems, and secrets management.
  • Familiarity with compliance standards and regulations, particularly NIST 800-53 and FedRAMP.
  • Excellent communication and collaboration skills, with the ability to work effectively in a cross-functional team environment.
  • A positive attitude and a willingness to learn, adapt, collaborate, and grow in a dynamic environment.

Preferred:

  • Experience contributing to FedRAMP authorization efforts (Moderate or High), including SSP documentation, control implementation, or 3PAO coordination.
  • Experience with Azure networking, and security boundaries.
  • Experience with compliance automation, supply chain security (SBOM, image signing), or secrets management at scale.
  • Professional certifications: CISSP, Azure Security Specialty, CKS, or equivalent.
  • Familiarity with CMMC, OSCAL, or compliance-as-code practices.
  • Experience with vulnerability scanning and remediation tooling (e.g., Trivy, Snyk, Qualys, or Defender for Cloud).
  • Advanced degree in Computer Science or related field, or equivalent experience architecting secure, compliant platforms at scale.

LOCATION

Candidate must be a US-citizen but can be located anywhere within the US.

CANDIDATE EXPERIENCE

We respect your time and aim for transparency throughout the interview process. You can expect:

  • A 30-minute initial chat with our Principal People & Talent Partner.
  • A Take Home Assessment, which you will work on within GitHub.
  • Three 60-minute 1:1 interviews with members of our engineering team, one of them who will be the hiring manager.

This process allows both parties to ask questions and gauge fit for the team.
*Due to the nature of the work and participation in federal security and compliance programs, U.S. citizenship is required as a bona fide occupational qualification in accordance with federal government security and compliance regulations. This role requires physical presence within the United States while working — access to FedRAMP-authorized environments from outside U.S. borders is not permitted.

Full compensation packages are based on candidate experience and certifications.
WA pay input
$164,000—$200,000 USD
Full compensation packages are based on candidate experience and certifications.
CA pay input
$164,000—$200,000 USD
Full compensation packages are based on candidate experience and certifications.
NY pay input
$164,000—$200,000 USD
Full compensation packages are based on candidate experience and certifications.
USA pay input
$164,000—$200,000 USD

WHERE YOU'LL GO

  • Hyperproof also loves to see an internal transfer. If a linear career path is not what you're looking for, you can work with your manager and our people team to explore lateral moves to other parts of the organization as you continue to grow with us.

WHAT WE OFFER TO OUR EMPLOYEES

Please note: Benefits listed below are for employees in the United States; contractor roles or international positions may differ

  • Annual compensation reviews + equity
  • Unlimited PTO: strongly encouraged to unplug and recharge
  • Health: coverage for medical, dental, and vision - employee and dependents
  • 401K, which vests immediately, complete with a 4% company match
  • 12 weeks of Parental leave and 1 year free diapers and wipes with Honest
  • Annual company in-person events and quarterly in-person connects
  • $500 home office stipend - at the time of hire. Any additional home office needs are requested as needed.
  • $100 quarterly paid wellness stipend
  • Pet insurance discount
  • Slack channel notifications turn off after 5 pm based on your time zone
  • Two Hypercharge weeks of rest where we close company-wide (July & Dec)

It's an exciting time to be at Hyperproof — we recently raised $40 million in our Series B financing, further cementing Hyperproof as the emerging leader in the risk and compliance management space.

At Hyperproof's core are our passionate team members who focus on user experience, beautiful design, and evangelize a positive social impact of our cloud based platform. We help organizations streamline their risk and compliance workflows so our customers can spend more time strategically managing programs and less time wrangling spreadsheets.

We are disrupting the governance, risk, and compliance software space with our innovative platform by helping traditionally unsung heroes (compliance professionals) do the right things so the wrong things don't happen.

Learn more about the @hyperproof culture and how it all started.

A NOTE ABOUT OUR INTERVIEW PROCESS

We're committed to creating a fair, respectful, and secure hiring experience for everyone. As part of that commitment, we use standard verification steps throughout our interview process.

Here's what that means for you:

  • We may conduct routine verification checks during the hiring process.
  • You might be asked additional questions to better understand your experience and background.
  • For video interviews, we ask that candidates be on camera without filters or visual modifications.

These steps are applied consistently for all candidates and are designed to ensure an equitable experience for everyone.

EQUAL OPPORTUNITY EMPLOYER

Hyperproof is committed to a diverse and inclusive workplace — it's one of our core values! Hyperproof is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our company is dedicated to building a diverse, inclusive, and authentic workplace. If you're excited about this role, but your experience doesn't perfectly fit every qualification, we encourage you to apply anyway. You may be just the right person for this role or others.

To ensure a smooth interview process, all candidates will be required to provide a valid phone number that is not a VOIP (Voice Over Internet Protocol) number. This helps us maintain clear and reliable communication throughout your interview experience.