Security Compliance Program Manager

Kaizen LabsNew York, NY
$130,000 - $175,000Hybrid

About The Position

Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. Our platform reaches 55 million Americans across 50+ agencies. Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back. The Role Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function to own the obligations, the paperwork of record, and the accuracy of everything we submit. You will build and run that function, working directly with the engineering lead, the incoming security engineer, and the executive team.

Requirements

  • Direct experience submitting in federal portals, SPRS and PIEE specifically. "Supported" and "submitted" are different things
  • Has run a NIST 800-171 self-assessment or RMF package end to end, with personal accountability for the outcome
  • Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it
  • Hands-on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor
  • Current on FedRAMP as it exists in 2026, and fluent in 20x specifically. Certification Classes, Key Security Indicators, machine-readable packages, continuous validation. We are building on 20x, so experience that stops at Rev 5 documentation will be working against the grain here
  • Knows where Rev 5 still binds. High remains a Rev 5 process and new Rev 5 certifications stop in June 2027. Knowing which parts of a roadmap that constrains is more useful to us than depth in either framework alone
  • Can reason about a shared authorization boundary: which controls are inherited, which are shared, which stay application-specific, and what kind of change triggers a significant-change request
  • Working knowledge of the DoD Cloud Computing SRG and how Impact Levels sit on FedRAMP baselines. The CSP and Mission Owner split matters here, and so does reading a hosting platform's ATO coverage against the agency doing the buying
  • Has worked opposite a 3PAO or independent assessor on evidence requests and knows what they accept in practice
  • Can read a contract for FAR and DFARS flowdowns and turn them into a tracked obligation register. If you have run a subcontract flowdown matrix, say so
  • Background in federal or defense contracting (agency-side, prime, or sub) where you owned a compliance function rather than a slice of one
  • Has been the only compliance person at an organization; you know how to close a loop without a team behind you
  • US person, eligible for a Tier 3 background investigation; DC-based or NYC-based with regular in-office presence
  • An active or recently held clearance is a meaningful accelerant. Existing investigations don't convert, and a Tier 3 takes roughly five months

Nice To Haves

  • Have owned a FedRAMP authorization through to completion, on the provider or the assessor side. This is the most valuable thing on this list and it moves our offer
  • Have written OSCAL by hand, or stood up a trust center against live control indicators
  • Bring a military background in security, intelligence, or information security (unit security manager, SSO, S2/G2, cyber operations, or similar)
  • Hold a CMMC CCP or RP, or have direct experience with eMASS, Xacta, Paramify, or equivalent GRC tools in a federal context
  • Know the GovRAMP reciprocity path into FedRAMP Class A
  • Come from a GovTech or SaaS company actively pursuing FedRAMP or CMMC, rather than one that already holds it

Responsibilities

  • Own the POA&M end to end: keep it current, submit it to our hosting partner on the contractual cadence, and make sure what gets signed is accurate
  • Run NIST 800-171 self-assessment workbooks to completion, maintain the SPRS score, and drive remediation items in priority order through to close
  • Manage all federal contract and agency paperwork: DD Form 254, DD Form 2345, JCP registration, PIEE and SPRS portal administration, SAM.gov, agency security questionnaires, and DFARS security clause flowdowns
  • Track every live contractual SLA, from incident notification through periodic reviews and annual affirmations, and prove we met them
  • Own the obligation register. Read every federal contract and subcontract for what it actually binds us to, including FAR and DFARS flowdowns, and run the register that tracks it. This reaches well past security into employee notices, required training, prohibited technology, EEO and labor reporting, OCI, and business ethics. Much of it gets executed by People Ops, legal or IT, but one person has to hold the map
  • Sit in on new federal contracts and subcontracts before signature and flag what we are agreeing to
  • Build and maintain the control-to-evidence mapping so any control's status is a two-minute answer instead of an archaeology dig through tickets
  • Own personnel security operations: US-person verification, background screening at federal-aligned tiers, onboarding and offboarding access controls, and quarterly access reviews
  • Lead FCL readiness: FSO vendor selection, key personnel clearance sequencing, SF 328 disclosures, and NISS submission when sponsorship lands, with a path to holding the FSO designation yourself

Benefits

  • 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam — all fully covered for employees, with 100% coverage for dependents.
  • $100,000 in fully paid life insurance.
  • FSA and Dependent Care FSA.
  • One Medical membership, on us — same-day primary care, 24/7 virtual visits, and offices all over the city.
  • Fertility and family-building support through Carrot.
  • 401(k) through Guideline, with a 2% company match.
  • 16 weeks of fully paid parental leave for birthing parents.
  • 10 weeks fully paid for non-birthing parents.
  • Unlimited PTO, with a two-week minimum
  • Closed for all federal holidays.
  • Company-wide winter break the week of Christmas.
  • Company offsites throughout the year.
  • Up to $750 one-time home office or desk setup stipend for NYC-based employees. $500 for remote employees.
  • $50/month commuter benefit (company contribution).
  • Expensed lunch while in the office.
  • Company-provided laptop of your choice.
  • Fully covered gym membership at Grindhouse — right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement.
  • $100/month utility stipend.
  • $500/year professional development.
  • $250/year recreation.
  • $300/quarter pet care stipend.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service