1

Fedramp Program Manager Jobs in Utah (NOW HIRING)

FedRAMP, StateRAMP, Canadian government compliance obligations Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs. * Assist with security efforts to meet ...

FedRAMP, StateRAMP, Canadian government compliance obligations Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs. * Assist with security efforts to meet ...

FedRAMP, StateRAMP, Canadian government compliance obligations Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs. * Assist with security efforts to meet ...

Drive planning, execution, issue management, reporting, and partner communications. * Own program ... FedRAMP, NIST, or similar regulatory and compliance requirements. * Experience driving multi ...

next page

Showing results 1-20

Fedramp Program Manager information

What are the key skills and qualifications needed to thrive as a FedRAMP Program Manager?

To thrive as a FedRAMP Program Manager, you need expertise in cloud security, risk management, compliance frameworks, and a solid understanding of FedRAMP requirements, usually backed by a degree in IT, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53 controls, and certifications such as CISSP or PMP is highly beneficial. Strong project management, stakeholder communication, and problem-solving skills set candidates apart in this role. These competencies are essential for guiding organizations through complex FedRAMP authorization processes and ensuring ongoing compliance with federal security standards.

What is a FedRAMP Program Manager?

A FedRAMP Program Manager is a professional responsible for overseeing and coordinating the process of achieving and maintaining Federal Risk and Authorization Management Program (FedRAMP) compliance for cloud service providers or government agencies. They manage documentation, security assessments, and communication with stakeholders to ensure all requirements are met according to federal standards. Their role is crucial for enabling secure cloud adoption within U.S. government agencies, as they guide the project through the FedRAMP authorization process from start to finish.

What are the main challenges a FedRAMP Program Manager faces when coordinating compliance efforts across multiple teams?

A FedRAMP Program Manager often navigates complex challenges such as aligning cross-functional teams—including IT, security, legal, and operations—to meet rigorous federal cloud security requirements and tight deadlines. Coordinating documentation, ensuring continuous monitoring, and responding to security assessments demand strong project management and communication skills. Additionally, managing evolving compliance standards and liaising with external auditors or government representatives can add to the complexity. Success in this role depends on the ability to facilitate collaboration, maintain meticulous records, and quickly adapt to regulatory updates.

What is the difference between Fedramp Program Manager vs Cloud Security Manager?

AspectFedramp Program ManagerCloud Security Manager
CertificationsFedRAMP certifications, PMP, CISSPCISSP, CCSP, Cloud Security certifications
Work EnvironmentFederal agencies, cloud service providers, government projectsPrivate sector, cloud service providers, enterprise security teams
Industry UsageFederal government compliance, cloud authorizationCloud security strategy, risk management

The Fedramp Program Manager primarily focuses on managing FedRAMP compliance and federal cloud authorization processes, often working within government or contractor environments. In contrast, the Cloud Security Manager oversees overall cloud security strategies and risk mitigation in private or enterprise settings. While both roles require cloud security knowledge and certifications like CISSP, their scope and industry focus differ significantly.

What are popular job titles related to Fedramp Program Manager jobs in Utah? For Fedramp Program Manager jobs in Utah, the most frequently searched job titles are:
What job categories do people searching Fedramp Program Manager jobs in Utah look for? The top searched job categories for Fedramp Program Manager jobs in Utah are:
What cities in Utah are hiring for Fedramp Program Manager jobs? Cities in Utah with the most Fedramp Program Manager job openings:
Infographic showing various Fedramp Program Manager job openings in Utah as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 17% Part Time, 1% Temporary, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Chief Information Security Officer - CISO

Jobtailor

Salt Lake City, UT • On-site

$180 - $240/hr

Other

Posted 10 days ago


Job description


  • Define and execute the company's enterprise security strategy, aligned with business objectives and compliance obligations (including FedRAMP).

  • Own security governance, policies, standards, and risk management practices across the organization.

  • Embed security-by-design principles across systems, applications, cloud infrastructure, and engineering workflows.

  • Set policy for access control, data protection, and secure development practices, partnering with Engineering to embed requirements into the SDLC without becoming a bottleneck.

  • Own data privacy and residency requirements across the regions where we operate infrastructure, including GDPR and other applicable cross-regional obligations.

  • Own the security and governance model for how AI and LLM tooling are used across engineering — controlling what data can reach which models and keeping regulated data inside trusted boundaries.

  • Implement guardrails for AI and agentic workflows to catch data leakage, prompt injection, and unsafe outputs before they reach production or customers.

  • Partner with Engineering leadership to make security a built-in part of our AI-driven SDLC tooling, not a gate bolted on afterward.

  • Evaluate and, where appropriate, pursue recognized AI governance frameworks (e.g., ISO 42001) to give customers confidence in how we govern AI use.

  • Help turn our AI security posture into a competitive advantage in customer conversations, in partnership with Sales and Compliance.

  • Own the enterprise risk assessment program: identify, quantify, and track risk across infrastructure, applications, vendors, and third parties.

  • Run and continuously improve a formal risk register with clear ownership, remediation timelines, and executive reporting.

  • Lead risk assessments for cloud infrastructure and key third-party dependencies (e.g., AWS, Azure), and for new products, features, or architecture changes before launch.

  • Translate technical risk into business terms for executive reporting.

  • Support Sales and Customer Success in customer security conversations, questionnaires, and due diligence reviews — working closely with the Compliance team, who own the customer relationship.

  • Maintain and mature our compliance posture (e.g., FedRAMP, SOC 2, ISO 27001 as applicable) in partnership with Compliance/Validation.

  • Contribute to customer-facing security collateral (architecture summaries, trust documentation) that scales beyond 1:1 conversations.

  • Be available for direct customer engagement when a deal or renewal requires executive-level security assurance.

  • Own the cybersecurity incident response program: detection, escalation, communication, and remediation.

  • Lead cross-functional incident response involving Legal, Engineering, and executive leadership as needed.

  • Ensure continuous monitoring, threat intelligence integration, penetration testing, and vulnerability management.

  • Mature our detection and response capability (SIEM, monitoring, managed detection/response) to steadily reduce mean-time-to-detect.

  • Drive post-incident reviews and continuous improvement.

  • Build, lead, and develop the security team (or oversee the security function, depending on current staffing).

  • Represent security at the executive/leadership table; advise the CEO/CTO on risk posture and security investment priorities.

  • Set and manage the security budget and tooling stack.


Requirements

  • 8-10 years in security leadership, with direct experience owning risk assessment programs (enterprise, product, and/or third-party risk).

  • Hands-on experience securing cloud environments on AWS and/or Azure.

  • Experience governing the security of AI/LLM usage — data boundaries, guardrails against prompt injection and data leakage, and secure use of AI in engineering workflows.

  • Deep working knowledge of at least one major compliance framework (FedRAMP, SOC 2, ISO 27001, or similar).

  • Experience with data privacy and cross-regional compliance requirements (e.g., GDPR) for organizations operating infrastructure in multiple regions.

  • Experience building or maturing a formal risk register and executive risk reporting.

  • Strong written and verbal communication — able to translate technical security concepts for customers and executives, and to work cross-functionally with Sales, Compliance, and Engineering.

  • Track record of leading incident response for a SaaS or cloud-based product.


Core Competencies

Demonstrates expertise in defining and executing enterprise security strategies, managing risk assessment programs, and ensuring compliance with frameworks such as FedRAMP and GDPR. Proven ability to lead incident response efforts and integrate security into AI-driven engineering workflows.


Highest-signal resume keywords

  • Enterprise Security Strategy

  • Risk Assessment Programs

  • Cloud Security (AWS, Azure)

  • Compliance Frameworks (FedRAMP, SOC 2, ISO 27001)

  • Incident Response Leadership


ATS Optimization Keywords
Hard Skills

  • Risk Management

  • Data Protection

  • Security Governance

  • AI Governance

  • Security Incident Response

  • Vulnerability Management

  • Penetration Testing

  • Threat Intelligence

  • Security Policy Development

  • Secure Development Practices


Soft Skills

  • Strong Communication

  • Cross-Functional Collaboration

  • Executive Reporting

  • Customer Engagement

  • Team Leadership


Certifications & Qualifications

  • FedRAMP

  • SOC 2

  • ISO 27001


Industry Keywords

  • Data Privacy

  • GDPR

  • Risk Register

  • Security Posture

  • Compliance Obligations


Tools & Technologies

  • SIEM

  • Monitoring Tools

  • Managed Detection/Response

  • Cloud Infrastructure

  • AI/LLM Tooling

#J-18808-Ljbffr