Security Compliance Program Manager (Contract)

Kaizen LabsNew York, NY
$95 - $140Remote

About The Position

Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. Our platform reaches 55 million Americans across 50+ agencies. We are building toward something much larger — the software layer that powers how Americans access any government service. Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back. The Role Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function and hiring for it permanently. This engagement builds the operating machinery in the meantime: the register, the calendar, the submissions, and the evidence trail. This is hands-on production work rather than advisory.

Requirements

  • Direct experience submitting in federal portals, SPRS and PIEE specifically.
  • Has run a NIST 800-171 self-assessment or RMF package end to end, with personal accountability for the outcome.
  • Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it.
  • Hands-on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor.
  • Current on FedRAMP as it exists in 2026, and fluent in 20x specifically. Certification Classes, Key Security Indicators, machine-readable packages, continuous validation.
  • Knows where Rev 5 still binds. High remains a Rev 5 process and new Rev 5 certifications stop in June 2027.
  • Can reason about a shared authorization boundary: inherited versus shared versus application-specific controls, and what kind of change triggers a significant-change request.
  • Working knowledge of the DoD Cloud Computing SRG and how Impact Levels sit on FedRAMP baselines. The CSP and Mission Owner split matters here, and so does reading a hosting platform's ATO coverage against the agency doing the buying.
  • Has worked opposite a 3PAO or independent assessor on evidence requests and knows what they accept in practice.
  • Can read a contract for FAR and DFARS flowdowns and turn them into a tracked obligation register. Subcontract flowdown matrix experience is a strong signal.
  • Background in federal or defense contracting, agency-side, prime, or sub.
  • Comfortable being the only compliance person on an engagement, with a vCISO firm for advice and an engineering team for implementation.
  • US person, eligible for a Tier 3 background investigation.

Nice To Haves

  • Owned a FedRAMP authorization through to completion, on the provider or the assessor side.
  • Written OSCAL by hand, or stood up a trust center against live control indicators.
  • Military background in security, intelligence, or information security.
  • Hold a CMMC CCP or RP, or have worked in eMASS, Xacta, or Paramify.
  • Know the GovRAMP reciprocity path into FedRAMP Class A.
  • Done exactly this as a contract engagement before and can describe what made it work or fail.

Responsibilities

  • Own the operations side of FedRAMP: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor.
  • Own knowing the reciprocity map for DoD Impact Levels, reading a hosting platform's actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary.
  • Run the self-assessment against NIST 800-171 Rev 2 for CMMC, build a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries.
  • Prepare the SPRS package and the FCL readiness materials.
  • Create an obligation register covering every federal contractual and regulatory requirement Kaizen carries, with its source, cadence, and owner. This includes reading contracts and subcontracts for FAR and DFARS flowdowns, employee notices, required training, prohibited technology, EEO and labor reporting, and OCI alongside the control work.
  • Stand up a monthly POA&M process, with the first cycle assembled and submitted to our platform partner on schedule.
  • Create an obligation calendar covering every recurring deadline, each with a named owner and an escalation path.
  • Complete a NIST 800-171 self-assessment and score it, with the SPRS package staged for a company official to affirm and every gap carrying a dated POA&M entry.
  • Develop a control-to-evidence mapping, version one, with inherited controls separated from shared and from application-specific.
  • Assemble certification application materials, including a machine-readable package that validates.
  • Create a corporate CUI system security plan scoped to a named group of users, separate from the product SSP.
  • Ensure federal paperwork is current: DD Form 2345 and JCP registration, DD 254, PIEE and SPRS administration, SAM.gov.
  • Evaluate and select an identity verification vendor against FedRAMP-aligned screening requirements.
  • Write four plans: configuration management, incident response, contingency, supply chain risk management.
  • Document and run continuous monitoring and log retention.
  • Ensure agency security questionnaires are answered without executive involvement.
  • Stage FCL readiness package.

Benefits

  • 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam — all fully covered for employees, with 100% coverage for dependents.
  • $100,000 in fully paid life insurance.
  • FSA and Dependent Care FSA.
  • One Medical membership, on us — same-day primary care, 24/7 virtual visits, and offices all over the city.
  • Fertility and family-building support through Carrot.
  • 401(k) through Guideline, with a 2% company match.
  • 16 weeks of fully paid parental leave for birthing parents.
  • 10 weeks fully paid for non-birthing parents.
  • Unlimited PTO, with a two-week minimum.
  • Closed for all federal holidays.
  • Company-wide winter break the week of Christmas.
  • Company offsites throughout the year.
  • Up to $750 one-time home office or desk setup stipend for NYC-based employees. $500 for remote employees.
  • $50/month commuter benefit (company contribution).
  • Expensed lunch while in the office.
  • Company-provided laptop of your choice.
  • Fully covered gym membership at Grindhouse — right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement.
  • $100/month utility stipend.
  • $500/year professional development.
  • $250/year recreation.
  • $300/quarter pet care stipend.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service