Director, Public Sector Compliance

BlitzyCambridge, MA
$215,000 - $230,000Onsite

About The Position

Compliance is the single biggest blocker between Blitzy and the public sector market - and, handled correctly, one of our biggest product opportunities. Federal agencies, the defense industrial base, and the integrators who serve them want what our enterprise customers already have: an agentic platform that turns requirements into production-ready code. Getting there is an accreditation problem, and we’re hiring the leader who will own it. The near-term mandate is clear. Drive Blitzy from FedRAMP Moderate to FedRAMP High as quickly as we can defensibly get there, because High is the baseline for DoD SRG IL2, IL4, and IL5. National security mission and business systems at the unclassified level — Advana among them — require IL5, and we intend to operate there. The longer-term mandate is more interesting. Static authorization packages and POA&M bookkeeping are giving way to proactive, continuous security. You’ll build our posture that way from the start, and then help productize the internal primitives you create as part of the broader Blitzy Proactive Insights portfolio, aligned to the cyber security needs of the DIB. This is a compliance title attached to a revenue mandate. Every control you land unblocks, closes, or expands a deal. You’ll work in person in Cambridge, MA with direct access to the founders and the engineers building the platform.

Requirements

  • 8+ years in security, compliance, or GRC leadership, including ownership of a federal authorization program end to end.
  • Hands-on experience taking a cloud system through FedRAMP authorization, and direct familiarity with what FedRAMP High and DoD SRG IL4/IL5 actually require beyond Moderate.
  • Deep working fluency in NIST 800-53, the FedRAMP baselines, the DoD Cloud Computing SRG, and adjacent regimes such as CMMC.
  • Track record of managing 3PAOs, sponsoring agencies, and government security reviewers — and of getting decisions out of them.
  • Demonstrated impact on revenue: you’ve personally unblocked, accelerated, or expanded deals where security and compliance were the obstacle.
  • Technical depth sufficient to earn engineering’s respect — cloud architecture, infrastructure as code, CI/CD, and evidence automation are conversations you can hold your own in.
  • Excellent written communication. Control narratives, agency responses, and customer-facing security documentation are all writing problems.

Nice To Haves

  • Existing relationships and credibility across the defense industrial base, primes, or DoD program offices.

Responsibilities

  • Own the roadmap and execution from FedRAMP Moderate to High, then to DoD SRG IL4/IL5 — boundary definition, control implementation strategy, SSP quality, and the assessment calendar.
  • Partner with GTM on every public sector opportunity: security reviews, agency and prime questionnaires, ATO strategy, and the compliance narrative that turns a blocked deal into a landed and expanded one.
  • Replace point-in-time compliance with automated evidence, control monitoring, and drift detection so authorization is a byproduct of how we operate, not a project we run.
  • Identify which internal compliance and security primitives have external value, and work with product and engineering to bring them to market for the defense industrial base.
  • Manage 3PAO, sponsoring agency, FedRAMP PMO, and DISA engagement — and represent Blitzy credibly with government security stakeholders.
  • Own the unglamorous foundations — configuration baselines, vulnerability management, access control, incident response, supply chain — and make build-versus-buy calls that keep cost and dependency in check.
  • Give engineering clear, automatable requirements instead of compliance homework, and give GTM answers they can use on their own.

Benefits

  • Bonus + Equity
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service