SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 215,000 - 230,000 / annual
Blitzy is an AI software development platform transforming how enterprises build software by autonomously executing 80% of software development work. The company is backed by tier-1 investors and serves Fortune 500 customers.
You will lead Blitzy's entry into the public sector market by owning the compliance and security authorization roadmap. Your primary mandate is to drive the platform from FedRAMP Moderate to FedRAMP High certification, which is the baseline for DoD SRG IL2, IL4, and IL5 accreditations required by federal agencies and the defense industrial base.
Key responsibilities include:
- Own the end-to-end roadmap and execution for FedRAMP Moderate to High, then DoD SRG IL4/IL5, including boundary definition, control implementation strategy, SSP quality, and assessment calendar management.
- Partner with go-to-market teams on every public sector opportunity: security reviews, agency and prime questionnaires, ATO strategy, and compliance narratives that convert blocked deals into closed and expanded ones.
- Transform point-in-time compliance into automated evidence collection, control monitoring, and drift detection so authorization becomes a byproduct of operations, not a project.
- Identify internal compliance and security primitives with external market value and work with product and engineering to productize them for the defense industrial base.
- Manage relationships with 3PAOs, sponsoring agencies, FedRAMP PMO, and DISA, representing Blitzy credibly with government security stakeholders.
- Own foundational security work: configuration baselines, vulnerability management, access control, incident response, and supply chain security. Make build-versus-buy decisions that control cost and dependencies.
- Translate compliance requirements into clear, automatable engineering specifications and provide go-to-market teams with actionable answers.
This is a compliance leadership role with direct revenue impact—every control you land unblocks, closes, or expands a deal. You will work in-person in Cambridge, MA with direct access to founders and the engineering team.
REQUIREMENTS:
- 8+ years in security, compliance, or GRC leadership, including end-to-end ownership of a federal authorization program.
- Hands-on experience taking a cloud system through FedRAMP authorization with direct familiarity of FedRAMP High and DoD SRG IL4/IL5 requirements beyond Moderate.
- Deep working fluency in NIST 800-53, FedRAMP baselines, DoD Cloud Computing SRG, and adjacent regimes such as CMMC.
- Track record managing 3PAOs, sponsoring agencies, and government security reviewers; demonstrated ability to extract decisions from them.
- Proven impact on revenue: personally unblocked, accelerated, or expanded deals where security and compliance were the obstacle.
- Technical depth sufficient to earn engineering respect—cloud architecture, infrastructure as code, CI/CD, and evidence automation are conversations you can lead.
- Excellent written communication skills for control narratives, agency responses, and customer-facing security documentation.
- Existing relationships and credibility across the defense industrial base, primes, or DoD program offices.