Sr. Security Program Manager, Commercial & Federal Compliance
Apply for this position → Go ad-free with PremiumAt Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.
What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.
Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.
Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!
We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams — driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701, Cyber Essentials, TISAX). The ideal candidate is a skilled program leader who can translate complex, multi-jurisdictional regulatory requirements into actionable roadmaps, manage cross-functional execution, and communicate risk and progress clearly to senior leadership.
Your Impact
- Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
- Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle.
- Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans.
- Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market's requirements.
- Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks.
- Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans).
- Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business.
- Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed.
- Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
- Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups.
- Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs.
Your Qualifications
- Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
- 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs.
- Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) is required.
- Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks).
- Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53).
- Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines.
- Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders.
- Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements.
- Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC, or similar).
- Must be a U.S. Citizen or U.S. Person residing in the U.S. (FedRAMP Moderate/High requirement).
Nice to Haves
- PMP, PgMP, or equivalent program management certification.
- ISO 27001 Lead Auditor or Lead Implementer certification.
- HITRUST Certified CSF Practitioner (CCSFP).
- CISSP, CISA, or CISM.
- Experience supporting a FedRAMP JAB or Agency authorization from initiation through ATO, including familiarity with OSCAL and continuous monitoring deliverables.
- Experience operating in multiple international markets and navigating varying regional compliance/certification requirements.
#LI-Remote
Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)
We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day!
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.
Fraud Recruitment Disclaimer
It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.
Anaplan does not:
- Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person.
- Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication.
All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to people@anaplan.com before taking any further action in relation to the correspondence.
Similar Jobs
Program Manager - Security GRC
Stripe · USA
Federal Program Manager (Profit-share)
Blueprint Creative Group · USA
Senior Professional Services Project Manager
GitLab · USA
AI Transformation Owner, CRO
GitLab · USA
Privacy Operations Program Manager
Stripe · USA
Sr. Security Program Manager, Commercial & Federal Compliance
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.
What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.
Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.
Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!
We are seeking an experienced Senior Program Manager to lead and coordinate compliance initiatives spanning both commercial and federal business lines. This role serves as the connective tissue between legal, security, contracts, engineering, and operational teams — driving programs that ensure the company meets its obligations under federal frameworks such as FedRAMP and CMMC, as well as commercial and international market certifications such as ISO 27001, SOC 2, HITRUST, and other regional/industry-specific standards (e.g., ISO 27701, Cyber Essentials, TISAX). The ideal candidate is a skilled program leader who can translate complex, multi-jurisdictional regulatory requirements into actionable roadmaps, manage cross-functional execution, and communicate risk and progress clearly to senior leadership.
Your Impact
- Own end-to-end program management for compliance initiatives across commercial and federal contracts, from planning through execution and audit readiness.
- Lead FedRAMP authorization and continuous monitoring efforts (Moderate/High baselines), coordinating with 3PAOs, agency sponsors, and internal engineering/security teams through the full ATO lifecycle.
- Partner with Legal, Security, IT, and Business Development to interpret federal compliance requirements (FedRAMP, CMMC, NIST 800-171/800-53) and translate them into program plans.
- Lead international and commercial certification programs including ISO 27001, ISO 27701, SOC 2 Type I/II, HITRUST CSF, and other regional market-access certifications (e.g., TISAX, ENS, Cyber Essentials), tailoring approach to each market's requirements.
- Develop and maintain program roadmaps, schedules, and program risk registers; proactively identify and mitigate project risks and schedule slippage across concurrent certification tracks.
- Serve as the primary point of coordination for internal and external audits, assessments, and certifications, ensuring evidence collection, stakeholder readiness, and timely remediation of findings (POA&Ms, corrective action plans).
- Support the establishment and refinement of governance processes, policies, and standard operating procedures to support sustainable, scalable compliance across federal, commercial, and international lines of business.
- Build and manage relationships with external auditors, 3PAOs, certification bodies, regulators, and government program offices as needed.
- Track and report program status, risks, and KPIs to executive leadership and agency stakeholders.
- Manage a portfolio of compliance-related projects simultaneously, balancing competing priorities and deadlines across multiple certification frameworks and stakeholder groups.
- Stay current on evolving federal and commercial regulations, FedRAMP program updates, and international regulatory/certification standards, assessing impact on ongoing programs.
Your Qualifications
- Bachelor's degree in Business, Information Security, Public Administration, or related field (equivalent experience considered).
- 6+ years of program or project management experience, including at least 3–5 years directly leading compliance, security, or risk programs.
- Hands-on experience with FedRAMP (authorization process, continuous monitoring, working with 3PAOs and agency sponsors) is required.
- Demonstrated experience managing ISO 27001, SOC 2, and HITRUST CSF certification/audit cycles, plus exposure to other international market-access certifications (e.g., ISO 27701, TISAX, or regional data protection frameworks).
- Working knowledge of federal contracting requirements (CMMC, NIST 800-171/800-53).
- Strong track record managing complex, cross-functional programs with multiple stakeholders and competing deadlines.
- Excellent written and verbal communication skills, including experience presenting to senior executives, auditors, and government stakeholders.
- Strong analytical and risk-assessment skills, with the ability to translate regulatory language into practical operational requirements.
- Proficiency with program/project management tools (e.g., Wrike, SharePoint, Confluence, Jira) and GRC platforms (e.g., Archer, Vanta, ServiceNow GRC, or similar).
- Must be a U.S. Citizen or U.S. Person residing in the U.S. (FedRAMP Moderate/High requirement).
Nice to Haves
- PMP, PgMP, or equivalent program management certification.
- ISO 27001 Lead Auditor or Lead Implementer certification.
- HITRUST Certified CSF Practitioner (CCSFP).
- CISSP, CISA, or CISM.
- Experience supporting a FedRAMP JAB or Agency authorization from initiation through ATO, including familiarity with OSCAL and continuous monitoring deliverables.
- Experience operating in multiple international markets and navigating varying regional compliance/certification requirements.
#LI-Remote
Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)
We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day!
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.
Fraud Recruitment Disclaimer
It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.
Anaplan does not:
- Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person.
- Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication.
All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to people@anaplan.com before taking any further action in relation to the correspondence.
Similar Jobs
Program Manager - Security GRC
Stripe · USA
Federal Program Manager (Profit-share)
Blueprint Creative Group · USA
Senior Professional Services Project Manager
GitLab · USA
AI Transformation Owner, CRO
GitLab · USA
Privacy Operations Program Manager
Stripe · USA