Program Manager, IT Governance and Compliance

True Anomaly
Denver, CO, United States
1 day ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$135,000.0 - $215,000.0
Working hours
Regular working hours

Tech stack

Agile Methodology Confluence JIRA Microsoft Azure Cyber Security Information Systems Information Technology Operations Information Systems Security Architecture Professional Project Management Software Microsoft Project Scrum Methodology Cloud Platform System
+3 more
Documentation System Atlassian Tools RSA Archer Platform

Job description

  • Lead GRC-related program tracking from inception through delivery across multiple frameworks (e.g., DoD RMF IL5 and IL6, CMMC).
  • Build and maintain program dashboards and executive reports using tools such as Jira, Confluence, GRC platforms (e.g., Diligent), and MS Project to provide transparency across teams and to leadership.
  • Coordinate and manage timelines, resources, and deliverables across security operations, product compliance, IT operations, and external consultants.
  • Track program status against milestones, identify risks and dependencies, and drive timely mitigation plans and course correction as needed.
  • Define and monitor Key Performance Indicators (KPIs) for compliance programs and team performance, ensuring successful execution of tasks and ongoing audit readiness.
  • Serve as the primary point of contact for internal stakeholders, executive leadership, and external assessors or certification bodies.
  • Support compliance readiness activities including pre-assessment readiness, audit facilitation, evidence collection, and post-audit remediation planning.
  • Continuously improve project workflows, team coordination, and reporting processes for scalable and repeatable program management.

Requirements

We are seeking an experienced Senior Program Manager to lead and coordinate cross-functional GRC initiatives across our organization. The ideal candidate will have demonstrated success in managing certification programs such as DoD RMF IL5 and IL6, CMMC and other compliance frameworks, while overseeing program delivery through structured KPI tracking, cross-team milestone management, and dashboard-driven reporting.

The candidate must be comfortable operating in fast-paced, regulated environments and be able to drive alignment across engineering, security, legal, compliance, and business operations teams. This is a critical role that ensures successful execution and continuous visibility of compliance initiatives for both internal leadership and external partners, including government and commercial stakeholders., * 7+ years of program or project management experience in technology or cybersecurity-related roles, with at least 5 years in GRC or compliance environments.

  • PMP (Project Management Professional)
  • Proven experience managing certification initiatives involving CMMC, DoD RMF IL5 and IL6.
  • Demonstrated ability to manage multi-disciplinary teams and complex project interdependencies across business and technical stakeholders.
  • Strong proficiency in program management and documentation tools:
  • Jira and Confluence (Atlassian suite)
  • MS Project or similar PM software
  • Excellent communication and stakeholder management skills, with a strong ability to simplify complexity and drive results across levels of the organization.

Preferred Qualifications

  • Professional certifications such as:
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified ScrumMaster (CSM) or Agile PM certification
  • Certified Information Systems Security Professional (CISSP)
  • Experience with cloud environments (e.g., Azure Government) and understanding of government cloud authorization processes.
  • Familiarity with Agile/Scrum and hybrid project delivery models.
  • GRC platforms (e.g., Diligent), * Ability to maintain or obtain TS//SCI clearance

Benefits & conditions

Be an Early Applicant In-Office Denver, CO, USA 135K-215K Annually Senior level In-Office Denver, CO, USA 135K-215K Annually Senior level Lead cross-functional governance, risk, and compliance programs involving CMMC and DoD RMF IL5/IL6. Manage timelines, resources, milestones, KPIs, dashboards, audit readiness, evidence collection, stakeholder alignment, and remediation planning across security, IT, legal, engineering, consultants, executives, and external assessors. The summary above was generated by AI

Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.

OUR MISSION

True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors - enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.

OUR VALUES

  • Be the offset. We create asymmetric advantages with creativity and ingenuity.
  • What would it take? We challenge assumptions to deliver ambitious results.
  • It’s the people. Our team is our competitive advantage and we are better together., * Base Salary: Denver - $135,000 to $185,000, Long Beach - $140,000 to $195,000, Washington, DC - $140,000 to $195,000, SF Bay Area - $155,000 to $215,000 *

  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave

Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education and experience., * Work Location: this role will be onsite at our facilities in Centennial, CO, Long Beach, CA, or Washington, DC.

  • Work environment is in a standard office, working at a desk or in a production factory.
  • Physical demands may include frequent standing, sitting, walking, bending, and lifting or carrying items up to 20lbs.

This position will be open until it is successfully filled. To submit your application, please follow the directions below. #LI-Onsite

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (IT

  1. AR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

We value diversity of experience, knowledge, backgrounds and perspectives and harness these qualities to create extraordinary impact. True Anomaly is committed to equal employment opportunity regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy, maternity or related condition (including breastfeeding) or any other basis as protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Expanding enterprise search integrations with Jira, Confluence, and GitHub

Prashanth Chandrasekar Prashanth Chandrasekar · World Congress 2024

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

Videos

See all

Related articles

See all