1

Fedramp Program Manager Jobs in Wisconsin (NOW HIRING)

WI · On-site

$180 - $260/hr

... management. * Drive the FedRAMP High authorization effort and the parallel GovRAMP pursuit -- both multi‑year, high‑cost programs (FedRAMP High alone typically runs 12-24 months and $500K-$1M ...

Compliance Lead

Milwaukee, WI · On-site

$154K/yr

Experience supporting global audit and certification programs, including coordination across ... FedRAMP, and/or CMMC. * Experience using AuditBoard, including CrossComply, for audit management ...

Compliance Lead

Milwaukee, WI · On-site

$154K/yr

Experience supporting global audit and certification programs, including coordination across ... FedRAMP, and/or CMMC. * Experience using AuditBoard, including CrossComply, for audit management ...

Fedramp Program Manager information

What are the key skills and qualifications needed to thrive as a FedRAMP Program Manager, and why are they important?

To thrive as a FedRAMP Program Manager, you need expertise in cloud security, risk management, compliance frameworks, and a solid understanding of FedRAMP requirements, usually backed by a degree in IT, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53 controls, and certifications such as CISSP or PMP is highly beneficial. Strong project management, stakeholder communication, and problem-solving skills set candidates apart in this role. These competencies are essential for guiding organizations through complex FedRAMP authorization processes and ensuring ongoing compliance with federal security standards.

What is a FedRAMP Program Manager?

A FedRAMP Program Manager is a professional responsible for overseeing and coordinating the process of achieving and maintaining Federal Risk and Authorization Management Program (FedRAMP) compliance for cloud service providers or government agencies. They manage documentation, security assessments, and communication with stakeholders to ensure all requirements are met according to federal standards. Their role is crucial for enabling secure cloud adoption within U.S. government agencies, as they guide the project through the FedRAMP authorization process from start to finish.

What are the main challenges a FedRAMP Program Manager faces when coordinating compliance efforts across multiple teams?

A FedRAMP Program Manager often navigates complex challenges such as aligning cross-functional teams—including IT, security, legal, and operations—to meet rigorous federal cloud security requirements and tight deadlines. Coordinating documentation, ensuring continuous monitoring, and responding to security assessments demand strong project management and communication skills. Additionally, managing evolving compliance standards and liaising with external auditors or government representatives can add to the complexity. Success in this role depends on the ability to facilitate collaboration, maintain meticulous records, and quickly adapt to regulatory updates.

What is the difference between Fedramp Program Manager vs Cloud Security Manager?

AspectFedramp Program ManagerCloud Security Manager
CertificationsFedRAMP certifications, PMP, CISSPCISSP, CCSP, Cloud Security certifications
Work EnvironmentFederal agencies, cloud service providers, government projectsPrivate sector, cloud service providers, enterprise security teams
Industry UsageFederal government compliance, cloud authorizationCloud security strategy, risk management

The Fedramp Program Manager primarily focuses on managing FedRAMP compliance and federal cloud authorization processes, often working within government or contractor environments. In contrast, the Cloud Security Manager oversees overall cloud security strategies and risk mitigation in private or enterprise settings. While both roles require cloud security knowledge and certifications like CISSP, their scope and industry focus differ significantly.

What are popular job titles related to Fedramp Program Manager jobs in Wisconsin? For Fedramp Program Manager jobs in Wisconsin, the most frequently searched job titles are:
What cities in Wisconsin are hiring for Fedramp Program Manager jobs? Cities in Wisconsin with the most Fedramp Program Manager job openings:

VP, Deputy Chief Information Security Officer (Remote)

Neumo

WI • On-site

$180 - $260/hr

Other

Posted 14 days ago


Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

VP, Deputy Chief Information Security Officer (Remote)

Full Time TX, US

Job Summary: Neumo is building a unified Information Security program across five lines of business and three legacy environments — Avenu, ITI, and GovOS. The CISO sets strategy and owns the board and executive relationship; the VP, Deputy CISO owns execution. This is a distinct, operational mandate: you run the program day to day, lead the four functional teams, make the working‑level calls on tooling and process, and are personally accountable for the roadmap that gets us to SOC 1, SOC 2, PCI DSS, FedRAMP High, and GovRAMP. This role exists because compliance commitments at this scale don’t run on strategy alone — they run on someone who manages the leads, resolves the conflicts, and keeps evidence collection, scans, and assessments on schedule across three environments that don’t yet operate the same way.

Duties and Responsibilities
  • Directly manage the four functional leads — GRC, AppSec, Cloud/Vulnerability, and SecOps — setting priorities, removing blockers, and holding them accountable to delivery.
  • Run the operating cadence for the team: weekly leads sync, sprint/quarter planning, and performance management for direct reports.
  • Build a consistent operating model across the four functions so GRC, AppSec, Cloud/Vuln, and SecOps work from shared priorities rather than in silos.
Cross-Entity Execution
  • Resolve tooling and process decisions at the working level across Avenu, ITI, and GovOS.
  • Own the standardization roadmap that brings three legacy environments onto common tooling, control sets, and operating procedures.
  • Act as the escalation point when legacy entities disagree on approach; make the call and move the work forward.
Compliance Program Operations
  • Own the operational roadmap behind SOC 1 and SOC 2: continuous evidence collection, control owners, and audit readiness ahead of annual audits.
  • Own PCI DSS operations: the annual assessment cycle plus quarterly scan cadence, remediation tracking, and scope management.
  • Drive the FedRAMP High authorization effort and the parallel GovRAMP pursuit — both multi‑year, high‑cost programs (FedRAMP High alone typically runs 12–24 months and $500K–$1M+) — translating authorization requirements into workstreams, milestones, and owners.
  • Maintain a single rolling roadmap across all frameworks so audit cycles, scan windows, and authorization milestones are sequenced, resourced, and visible — and don’t collide.
  • Report program status, risks, and resourcing needs to the CISO with enough detail to support executive and board reporting.
  • Serve as the day-to-day owner of external audit and assessment relationships (e.g., compliance advisory firms, QSAs, 3PAOs), keeping evidence requests, timelines, and findings moving.
  • Manage tooling vendors supporting GRC, vulnerability management, and security operations, including renewal and consolidation decisions across the three legacy stacks.
Education and Experience
  • 10+ years in information security, with at least 4 years managing security teams or functional leads directly.
  • Direct experience operating through at least one SOC 2 or SOC 1 audit cycle and one PCI DSS assessment cycle as a control owner or program lead.
  • Experience with FedRAMP or GovRAMP authorization work — control implementation, SSP development, or 3PAO assessment support — strongly preferred.
  • Experience with vulnerability management platforms (e.g., Tenable) and WAF/cloud security tooling a plus.
Knowledge, Skills and Abilities
  • Track record of standardizing security tooling or process across multiple business units, products, or post‑merger environments.
  • Comfortable making and owning tooling/process decisions without escalating every call upward — this role is judged on throughput, not just judgment.
  • Working knowledge of NIST CSF 2.0 and how it maps to GRC, AppSec, Cloud/Vuln, and SecOps functions.
  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.
Physical Demands
  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

#J-18808-Ljbffr