Compliance Operations Lead

GovSignalsNew York, NY
$140,000 - $190,000Hybrid

About The Position

GovSignals is seeking a Compliance Operations Lead to establish and manage its security and compliance function. This role reports directly to the founding team and is responsible for the company's end-to-end security and compliance posture. The position involves architecting the program, automating evidence collection, collaborating with engineering, and serving as the primary point of contact for customers and auditors regarding trust and security. In the government contracting sector, compliance is a critical differentiator, with frameworks like FedRAMP High, IL5, CMMC Level 2, and SOC 2 being essential for serving key government entities. This is a product-oriented role where compliance must keep pace with aggressive engineering cadences, emphasizing automation in CI/CD pipelines over traditional GRC tools. The ideal candidate will be driven by achieving authorizations and unblocking customer deals, embracing ownership and a mission-driven approach.

Requirements

  • 3+ years of experience leading compliance or security programs in a high-growth technology or defense startup environment.
  • Demonstrated success in achieving and maintaining a FedRAMP High ATO or a comparable high-impact authorization, including building a compliance program from inception.
  • Deep working knowledge of IL5, CMMC Level 2, SOC 2 Type II, NIST 800-171, and the broader U.S. public-sector compliance landscape.
  • Proven ability to design and implement automated evidence collection, policy management, and vulnerability-tracking workflows.
  • Experience coordinating red-team, penetration-test, or bug-bounty programs and translating findings into actionable engineering tasks.
  • Ability to communicate effectively with both technical and executive audiences, including auditors and senior engineers.
  • Strong written and verbal communication skills, with comfort in owning customer security reviews.
  • Must be a U.S. citizen or U.S. Person due to government work.

Nice To Haves

  • Hands-on experience with Kubernetes, Terraform, JAMF, and modern DevSecOps toolchains.
  • Prior experience supporting Intelligence Community (IC) or Department of Defense (DoD) customer bases.
  • Background in government contracting, the military, or the intelligence community.

Responsibilities

  • Build and manage the master compliance program covering FedRAMP High, IL5, CMMC Level 2, SOC 2, and related public-sector frameworks, including maintaining a roadmap for future requirements.
  • Lead the FedRAMP High ATO roadmap from initiation to completion, including coordinating with third-party assessment organizations (3PAOs), navigating agency sponsorships, and managing continuous monitoring.
  • Oversee end-to-end evidence management, establishing automated policy checks, control evidence capture, and continuous monitoring tools to ensure daily audit readiness.
  • Manage quarterly and annual security documentation cycles, coordinate penetration tests and red-team engagements, and track remediation efforts.
  • Serve as the primary representative for enterprise security questionnaires and customer trust calls, participating in sales pitches and discovery calls, briefing prospects on the compliance roadmap, and representing GovSignals at industry forums.
  • Integrate secure-by-design practices with the engineering team, including CI/CD policy checks, infrastructure-as-code guardrails, and hardened deployment pipelines.
  • Monitor the evolving threat landscape and propose proactive hardening measures.

Benefits

  • Medical, vision, and dental insurance
  • Unlimited PTO
  • Meaningful equity stake in a well-funded, fast-growing startup
  • Base Salary: $140,000 – $190,000
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service