ForgeApply · Job listing
Security Compliance Program Manager
Kaizenlabs
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services.
Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service.
Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year.
Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back.
THE ROLE
Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function to own the obligations, the paperwork of record, and the accuracy of everything we submit.
You will build and run that function, working directly with the engineering lead, the incoming security engineer, and the executive team.
LOCATION
New York, NY or Washington, D.C. (Hybrid). This is the permanent version of the role. We are also posting a contract equivalent for the same scope. The differences are that this one carries the authorization program long term, including the path from Moderate to High, and a path to holding the FSO designation yourself.
THE PROGRAMS
FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. The change-control side of an authorization matters here as much as the initial package. You own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor. You also own the significant-change process, which is the mechanism that makes the model work.
DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer's or a partner's. This role owns knowing the reciprocity map cold, reading a hosting platform's actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary. Reciprocity is inconsistent, so it has to be verified per agency rather than assumed.
CMMC. A separate track from the product, and keeping the two separate is part of the job: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You run the self-assessment against NIST 800-171 Rev 2, own a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries. You drive the scoping decision, which is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident-reporting clauses matters here.
WHAT YOU'LL DO
- Own the POA&M end to end: keep it current, submit it to our hosting partner on the contractual cadence, and make sure what gets signed is accurate
- Run NIST 800-171 self-assessment workbooks to completion, maintain the SPRS score, and drive remediation items in priority order through to close
- Manage all federal contract and agency paperwork: DD Form 254, DD Form 2345, JCP registration, PIEE and SPRS portal administration, SAM.gov http://SAM.gov, agency security questionnaires, and DFARS security clause flowdowns
- Track every live contractual SLA, from incident notification through periodic reviews and annual affirmations, and prove we met them
- Own the obligation register. Read every federal contract and subcontract for what it actually binds us to, including FAR and DFARS flowdowns, and run the register that tracks it. This reaches well past security into employee notices, required training, prohibited technology, EEO and labor reporting, OCI, and business ethics. Much of it gets executed by People Ops, legal or IT, but one person has to hold the map
- Sit in on new federal contracts and subcontracts before signature and flag what we are agreeing to
- Build and maintain the control-to-evidence mapping so any control's status is a two-minute answer instead of an archaeology dig through tickets
- Own personnel security operations: US-person verification, background screening at federal-aligned tiers, onboarding and offboarding access controls, and quarterly access reviews
- Lead FCL readiness: FSO vendor selection, key personnel clearance sequencing, SF 328 disclosures, and NISS submission when sponsorship lands, with a path to holding the FSO designation yourself
WHAT YOU'LL BRING
- Direct experience submitting in federal portals, SPRS and PIEE specifically. "Supported" and "submitted" are different things
- Has run a NIST 800-171 self-assessment or RMF package end to end, with personal accountability for the outcome
- Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it
- Hands-on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor
- Current on FedRAMP as it exists in 2026, and fluent in 20x speci
Salary insight
The midpoint of this range ($153k) is about 13% below the median disclosed salary for New York roles listed on ForgeApply ($176k across 4,674 jobs).
See full Project Manager salary data for New York →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Kaizenlabs?
Apply in about a minuteSimilar jobs
- Security Compliance Program Manager (Contract) — Kaizenlabs · New York, NY
- Security and Compliance Manager — Sierra · San Francisco, CA
- Security and Compliance Manager — Clinicallyai · San Diego, CA
- Staff Security Risk & Compliance Program Manager - Access Management — Confluent · Remote
- Security Program Manager — Crusoe · San Francisco, CA - US
- Security & Compliance Operations Manager — Mintlify · San Francisco
- Information Security Program Manager — Ardentmc · Rockville, MD
- Regulatory & Security Compliance Manager — Rain · New York, NY
More like this: Project & Program Manager Jobs · Project & Program Manager Jobs in New York · More jobs at Kaizenlabs · Browse all jobs