Port.io Logo

Port.io

GRC Program Manager (FedRAMP & Compliance)

Posted 10 Days Ago
Remote or Hybrid
Hiring Remotely in Boston, MA
Senior level
Remote or Hybrid
Hiring Remotely in Boston, MA
Senior level
Lead FedRAMP authorization efforts and manage compliance programs. Coordinate assessments and documentation while ensuring readiness across cross-functional teams.
The summary above was generated by AI

About Port

At Port.io, we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M Series C funding round, we are in a phase of rapid hypergrowth with strong enterprise momentum.

We act as the central nervous system for engineering, enabling platform teams to unify their stack and expose it as a governed layer through golden paths for developers and AI agents.

By combining rich engineering context, workflows, and actions, we help organizations transition from manual processes to autonomous, AI-assisted engineering workflows while maintaining control and accountability.

As a product-led company, we believe in building world-class platforms that fundamentally shape how modern engineering organizations operate.

Why we're looking for you:

We're looking for a GRC Program Manager to drive Port's FedRAMP authorization and oversee our broader compliance portfolio. You'll be the program's operational backbone - coordinating 3PAO assessments, managing documentation, and ensuring readiness across teams.

FedRAMP authorization is a strategic milestone for Port as we expand into enterprise and federal markets. This is a high-visibility initiative with executive sponsorship, requiring precise coordination across engineering, security, and product. We need a program manager who thrives in complex, cross-functional environments and can translate regulatory frameworks into clear execution plans while managing timelines, budgets, and stakeholder expectations.

Who you'll work with:

You'll report to the CISO and work closely with the Security team, Engineering, DevOps, IT, and Product teams. You'll manage relationships with external partners, including the 3PAO, FedRAMP consultants, and government agency sponsors. You'll also collaborate with Legal and Finance on contracts, budgets, and compliance obligations.

In addition, you'll support the US sales process, compliance and regulatory inquiries, RFIs/RFPs, and other related business processes. 

What you'll do:

  • Lead the FedRAMP project from kickoff through ATO: schedule, documentation, 3PAO engagement, and agency coordination.
  • Own the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and all readiness deliverables.
  • Manage the 3PAO relationship, coordinate assessments, and drive remediation efforts.
  • Build and maintain the compliance evidence repository and continuous monitoring program.
  • Manage cross-team milestones, track control implementation progress, and identify blockers.
  • Develop repeatable processes and frameworks to sustain compliance post-authorization.
  • Partner with Engineering, Security, IT, and Product to translate NIST 800-53 controls into technical implementations.
  • Lead internal readiness assessments and gap analysis. 
  • Assist and support GRC initiatives, other compliance frameworks, team processes and systems. 

What we're looking for:

  • Direct FedRAMP experience (managing an authorization from start to ATO) - Must have
  • 5+ years of experience managing compliance or GRC programs in SaaS or regulated environments.
  • Proven track record running complex audits or certification programs (FedRAMP, SOC 2, ISO, etc.).
  • Deep understanding of control frameworks (NIST 800-53, ISO 27001) and how they translate to technical implementations.
  • Exceptional project management and communication skills - ability to manage timelines, budgets, and complex dependencies.
  • Experience managing vendor relationships, including 3PAOs, consultants, and compliance tooling providers.
  • Strong stakeholder management skills - comfortable managing multiple workstreams and influencing across technical and non-technical teams.
  • Detail-oriented with strong documentation and organizational skills.

Nice to have:

  • Experience working with government agency sponsors and understanding FedRAMP agency workflows.
  • Hands-on experience with GRC automation platforms (Drata, Tugboat Logic, Vanta, OneTrust).
  • Risk Management. 
  • Background in technical security controls, cloud infrastructure, or DevSecOps.
  • CISSP, CISM, PMP, or FedRAMP-related certifications.
  • Experience with continuous monitoring and ongoing compliance management.

Top Skills

Fedramp
Grc Automation Platforms
Iso 27001
Nist 800-53
SaaS

Port.io Boston, Massachusetts, USA Office

33 Arch Street, Boston, MA, United States

Similar Jobs

4 Hours Ago
Remote or Hybrid
United States
142K-195K Annually
Senior level
142K-195K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead CFO-level advisory engagements for physician practices by modernizing finance operations, overseeing client teams, analyzing KPIs, building budgets/forecasts, driving process and technology improvements, collaborating cross-functionally, and mentoring staff.
Top Skills: Intacct,Quickbooks Online,Netsuite,Bill.Com
14 Hours Ago
Remote or Hybrid
USA
196K-245K Annually
Expert/Leader
196K-245K Annually
Expert/Leader
Edtech • Information Technology • Software
The VP of Global Professional Services strategizes and executes a services organization, leveraging AI and analytics to drive platform adoption and customer satisfaction. Responsibilities include overseeing service offerings, financial performance, delivery excellence, and leading a global team.
18 Hours Ago
Remote or Hybrid
United States
125K-159K Annually
Senior level
125K-159K Annually
Senior level
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Design, build, and maintain secure, scalable SecOps platforms using C++, Rust, and scripting. Implement CI/CD and DevOps practices, integrate systems via APIs/webhooks and AI-driven tools, architect cloud (AWS/Azure/GCP) environments, optimize Linux/kernel configurations, automate infrastructure, and collaborate with SecOps on monitoring, detection, and response to protect enterprise assets.
Top Skills: Scripting Languages,C++,Rust,Linux,Linux Kernel,Aws,Azure,Gcp,Apis,Webhooks,Ci/Cd,Devops,Ai-Driven Tools

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account