SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kaizen Labs is a government technology company founded in 2022 and based in New York City that partners with local, state, and federal agencies to replace legacy systems with modern, AI-native software. The company has raised $35 million from top-tier investors (NEA, a16z, Accel) and reaches 55 million Americans across 50+ agencies.
You will build and run a dedicated compliance function as the Security Compliance Program Manager, reporting directly to the engineering lead, incoming security engineer, and executive team. This permanent role owns federal authorization obligations, regulatory paperwork, and submission accuracy across multiple compliance tracks.
Key responsibilities include:
**FedRAMP Certification**: Own the operations side of FedRAMP certification under the current Certification Class framework in a government cloud region. Manage control implementation status, inherited-versus-owned splits, Plans of Action and Milestones (POA&M) currency, continuous monitoring, Key Security Indicators, machine-readable packages, marketplace status, and evidence flow to the independent assessor. Own the significant-change process that enables the authorization model to function.
**DoD Impact Levels**: Manage reciprocity mapping across multiple impact levels in various hosting environments (company-operated, customer, or partner). Verify hosting platform authorization coverage against specific agencies and obtain control-responsibility matrices from boundary holders.
**CMMC Compliance**: Run NIST 800-171 Rev 2 self-assessments, maintain the corporate CUI system security plan, compute and maintain SPRS scores, manage annual senior-official affirmations, and own POA&M entries. Drive scoping decisions and manage DFARS safeguarding and incident-reporting obligations.
**Federal Contract Management**: Manage all federal contract and agency paperwork including DD Forms 254 and 2345, JCP registration, PIEE and SPRS portal administration, SAM.gov registration, agency security questionnaires, and DFARS flowdowns. Track contractual SLAs from incident notification through periodic reviews and annual affirmations.
**Obligation Register**: Read every federal contract and subcontract to identify actual obligations, including FAR and DFARS flowdowns. Maintain a register tracking security, employee notices, required training, prohibited technology, EEO and labor reporting, OCI, and business ethics requirements.
**Control-to-Evidence Mapping**: Build and maintain mappings so any control's status is quickly answerable without extensive investigation.
**Personnel Security**: Own US-person verification, background screening at federal-aligned tiers, onboarding/offboarding access controls, and quarterly access reviews.
**FCL Readiness**: Lead Federal Contractor Facility Clearance readiness including FSO vendor selection, key personnel clearance sequencing, SF 328 disclosures, and NISS submission, with a path to holding the FSO designation yourself.