1

Fedramp Program Manager Jobs in Kentucky (NOW HIRING)

$80 - $100/hr

... and management for review before submission. Research & Program Support -- support the wider ... S. citizen (FedRAMP / federal customer). Preferred Qualifications * Security+, GRCP, CySA+, or ...

$200 - $250/hr

FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required ... Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ...

$150 - $200/hr

... and compliance programs. As a fast‑growing startup, we specialize in a wide range of GRC ... Analyze and apply NIST SP 800‑53 controls and FedRAMP Moderate and High baselines to ensure ...

$150 - $200/hr

Assesses and validates compliance with FedRAMP High architecture requirements, including security ... Performs other duties as assigned by management in support of SBG Technology Solutions contract ...

$100 - $125/hr

... client programs aligned. Who You Are * Federal compliance practitioner - bring 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management ...

$100 - $125/hr

... client programs aligned. Who You Are * Federal compliance practitioner - bring 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management ...

$150 - $200/hr

Partner with the customer's Office of the CIO and program management to plan capacity, budget, and ... Ensure infrastructure and platform operations comply with FISMA, NIST SP 800-53, and FedRAMP ...

$150 - $200/hr

Define differentiated FedRAMP messaging and value propositions for platform capabilities across ... programs. * Ensure consistency and clarity of AI platform-level messaging across all marketing ...

$125 - $150/hr

Direct experience supporting a FedRAMP authorization or continuous monitoring program * Cloud ... Configuration management experience with Ansible, Chef, or Puppet * Kubernetes certifications (CKA ...

$150 - $200/hr

... such as FedRAMP, CMMC, IRAP, SOC2 and ISO 27001, or similar. Additionally, familiarity with ... Lead and manage security assessments, audits, and certification processes, ensuring timely and ...

New

$125 - $150/hr

... FedRAMP-authorized and IRAP-assessed platforms hosted in Microsoft Azure ... This role is responsible for vulnerability management, security monitoring, compliance activities ...

$150 - $200/hr

... role on the program. You will own secure baseline configuration management as a sustained ... FedRAMP authorization experience, on either the agency or the cloud service provider side.

$80 - $100/hr

Experience with FedRAMP, NIST, DHS 4300A, and FISMA compliance * Experience with system monitoring ... Experience supporting access management workflows Certifications (Preferred): * AWS * Azure

$150 - $200/hr

Provide IA Management support to Program Management Offices (PMO) for emerging information systems ... FedRAMP * TS/SCI All qualified applicants will receive consideration for employment without regard ...

$150 - $200/hr

Deep familiarity with the public sector ecosystem, including Federal and SLED go-to-market motions and federal compliance programs, such as FedRAMP and CMMC. * 5+ years of people management ...

$150 - $200/hr

... program management experience with related experience as Manager for information technology ... Knowledge of security and compliance frameworks (NIST, FedRAMP, Zero Trust Architecture) * Cloud ...

$125 - $150/hr

We are looking for a Project Manager to support the VA's governance objectives. Position Summary ... Plan and conduct contract reviews for the determination of quality program requirements and review ...

$200 - $250/hr

You can talk mission with a warfighter and requirements with a program manager, in the same week ... Familiarity with FedRAMP and what it does and doesn't require of a vendor like ZeroFox Benefits:

$150 - $200/hr

Administer and scale our government-cloud AI environment (FedRAMP High / GovCloud-hosted models ... Program (EAP) * 100% Paid Basic Life and AD&D Insurance * 100% Paid Workers Compensation Insurance

$150 - $200/hr

... 53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their ... Architect identity and access management - implement least-privilege IAM using RBAC, ABAC ...

Showing results 21-40

Fedramp Program Manager information

What is a FedRAMP Program Manager?

A FedRAMP Program Manager is a professional responsible for overseeing and coordinating the process of achieving and maintaining Federal Risk and Authorization Management Program (FedRAMP) compliance for cloud service providers or government agencies. They manage documentation, security assessments, and communication with stakeholders to ensure all requirements are met according to federal standards. Their role is crucial for enabling secure cloud adoption within U.S. government agencies, as they guide the project through the FedRAMP authorization process from start to finish.

What are the key skills and qualifications needed to thrive as a FedRAMP Program Manager?

To thrive as a FedRAMP Program Manager, you need expertise in cloud security, risk management, compliance frameworks, and a solid understanding of FedRAMP requirements, usually backed by a degree in IT, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53 controls, and certifications such as CISSP or PMP is highly beneficial. Strong project management, stakeholder communication, and problem-solving skills set candidates apart in this role. These competencies are essential for guiding organizations through complex FedRAMP authorization processes and ensuring ongoing compliance with federal security standards.

What are the main challenges a FedRAMP Program Manager faces when coordinating compliance efforts across multiple teams?

A FedRAMP Program Manager often navigates complex challenges such as aligning cross-functional teams—including IT, security, legal, and operations—to meet rigorous federal cloud security requirements and tight deadlines. Coordinating documentation, ensuring continuous monitoring, and responding to security assessments demand strong project management and communication skills. Additionally, managing evolving compliance standards and liaising with external auditors or government representatives can add to the complexity. Success in this role depends on the ability to facilitate collaboration, maintain meticulous records, and quickly adapt to regulatory updates.

What is the difference between Fedramp Program Manager vs Cloud Security Manager?

AspectFedramp Program ManagerCloud Security Manager
CertificationsFedRAMP certifications, PMP, CISSPCISSP, CCSP, Cloud Security certifications
Work EnvironmentFederal agencies, cloud service providers, government projectsPrivate sector, cloud service providers, enterprise security teams
Industry UsageFederal government compliance, cloud authorizationCloud security strategy, risk management

The Fedramp Program Manager primarily focuses on managing FedRAMP compliance and federal cloud authorization processes, often working within government or contractor environments. In contrast, the Cloud Security Manager oversees overall cloud security strategies and risk mitigation in private or enterprise settings. While both roles require cloud security knowledge and certifications like CISSP, their scope and industry focus differ significantly.

What are popular job titles related to Fedramp Program Manager jobs in Kentucky?

For Fedramp Program Manager jobs in Kentucky, the most frequently searched job titles are:

Infographic showing various Fedramp Program Manager job openings in Kentucky as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.
NextgenID
Software Development • 11 - 50 employees

$80 - $100/hr

Other

Posted 15 days ago


Key responsibilities

  • Maintain and organize control documentation, policies, procedures, and evidence repositories, including migration into Vanta.

  • Support the operational aspects of FedRAMP, UK DVS, and Kantara assessments by preparing documentation, coordinating assessments, and tracking remediation efforts.

  • Produce and track vulnerability and POA&M reports, ensuring timely remediation and maintaining evidence logs.


Job description

Location: Onsite - Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer)

Type: Full Time

NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL3) for federal agencies and enterprises, so evidence, documentation, and audit support are constant, real work. You maintain our control documentation and evidence, run the operational side of our FedRAMP, Kantara, and UK digital‑identity efforts, keep the POA&M and vulnerability tracking current, and complete the security questionnaires our customers send. You report to the GRC Lead. Salary Range: $75,000-$95,000

Role Fit & Non‑Negotiables
  • Onsite at our Fairfax, VA headquarters. This role is hands‑on and evidence‑heavy.
  • U.S. citizen, required for FedRAMP and federal‑customer obligations.
  • Two or more years in GRC, security compliance, audit support, or a closely related role.
  • Comfortable owning documentation, evidence, and trackers to a deadline.
  • Detail‑oriented and discreet with sensitive security information.
What You Will Own (90 to 180 Day Outcomes)
  • Current, well‑organized control documentation and evidence repositories, moving from SharePoint into Vanta.
  • The operational FedRAMP evidence effort: control documentation, gap‑finding tracking, and Trust Center content drafts.
  • A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure.
  • Completed, consistent security questionnaires delivered on time for GRC Lead review.
  • The UK DVS documentation package and Kantara assessment materials kept current and submission‑ready.
Core Responsibilities

Compliance Documentation & Evidence — keep the record current and audit‑ready.

  • Maintain control documentation, policies, and procedures, and migrate evidence into Vanta.
  • Gather and organize evidence from engineering, DevSecOps, and operations leads.
  • Convert implemented controls into machine‑readable (OSCAL / JSON) format for FedRAMP submission.

Authorization & Assessment Support — run the operational side of our certifications.

  • Refine and maintain the UK DVS / DIATF documentation package and scoping forms.
  • Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft.
  • Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads.

Vulnerability & POA&M Tracking — keep the remediation record honest.

  • Produce the monthly POA&M from Qualys findings using the FedRAMP template.
  • Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads.
  • Maintain vulnerability and vendor‑risk evidence logs (for example, the BeyondTrust remediation log).

Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk.

  • Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses.
  • Support third‑party and vendor risk assessments and evidence requests.
  • Route completed responses to the GRC Lead and management for review before submission.

Research & Program Support — support the wider compliance effort.

  • Provide compliance and privacy research to the document and product teams.
  • Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet).
  • Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated.
What You Must Have Already Done
  • Gathered and organized audit evidence and maintained compliance documentation to a deadline.
  • Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC 2) on real evidence or gap work.
  • Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams.
  • Completed a customer or vendor security questionnaire using documented evidence.
  • Kept a tracker, repository, or evidence log accurate across many moving items.
Required Qualifications
  • Two or more years in GRC, security compliance, audit support, or a closely related role.
  • Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2.
  • Experience gathering evidence and maintaining compliance documentation.
  • Experience with vulnerability or POA&M tracking and remediation coordination.
  • Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar).
  • Strong writing and documentation skills for policies, procedures, and questionnaire responses.
  • Highly organized and detail‑oriented, able to manage many concurrent items.
  • Discreet and reliable with sensitive security and compliance information.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).
Preferred Qualifications
  • Security+, GRCP, CySA+, or progress toward CISA.
  • Exposure to FedRAMP or FISMA continuous monitoring (ConMon) and 3PAO assessments.
  • Experience with Kantara / NIST 800-63 identity assurance or UK DIATF / DVS.
  • Familiarity with OSCAL or machine‑readable control formats.
  • Experience with security questionnaires (CAIQ, CCRA, customer InfoSec assessments).
  • Background in an IDaaS, cloud, or federal‑contractor environment.
  • You keep trackers and evidence current without being chased.
  • You read a control and know what evidence proves it.
  • You write clearly enough that your draft needs little rework before sign‑off.
  • You chase the last 10 percent of detail that makes evidence audit‑ready.
  • You handle sensitive information with discretion and never submit without review.
What Success Looks Like
  • Control documentation and evidence are current, organized, and audit‑ready in Vanta.
  • The monthly POA&M is produced on time and remediation is tracked to closure.
  • UK DVS and Kantara materials are submission‑ready ahead of each deadline.
  • Security questionnaires are completed accurately and on time for GRC Lead review.
  • Inherited workstreams from the departing analyst and intern continue without gaps.
Why NextgenID

NextgenID builds the compliance‑grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is the product’s license to operate, and the evidence you produce is what makes it real. As GRC Analyst, you will see your work in every certification we hold and every customer questionnaire we clear, and you will grow into deeper risk and program ownership. For the right person, this is the path to a senior GRC or GRC Lead role.

NextgenID focuses on improving the efficiency and speed of mission‑critical, high assurance identity enrollment and credentialing operations that are essential to hundreds of millions of users worldwide.

Our technologies are engineered to dramatically reduce the time and cost of capturing accurate data when creating a digital identity. Our industry‑neutral solutions revolve around "Supervised Remote‑Identity Proofing" to automatically, securely and "remotely" perform all proofing, enrollment and credentialing processes and workflows for our customers. The industry is taking notice as we are now working with some of the largest agencies in the US Defense, intelligence, Civil, State and Local government markets, as well as other national governments and commercial organizations throughout the world.

#J-18808-Ljbffr