FlexHired LogoFlexHired
Logo of Ramp

Ramp

Senior Security Program Manager, Public Sector

Job Summary

The Senior Security Program Manager, Public Sector will lead compliance efforts related to U.S. government cybersecurity frameworks such as FedRAMP and GovRAMP. They will oversee risk assessments, audits, and authorization processes while coordinating across security, legal, engineering, and product teams. The role requires expertise in government security regulations, documentation, and managing large-scale compliance programs. Strong communication skills and experience with cloud environments like AWS GovCloud are essential, along with the ability to develop and execute security strategies in a fast-paced environment.

Required Skills

Problem Solving
Leadership
Regulatory Compliance
Cybersecurity
Cloud Security
Risk Management
Security Documentation
Security Frameworks
Cross-functional Program Management
Audit and Assessment
Technical Safeguards
Third-party Management
Vulnerability Tracking
Federal and State Regulations
Written and Verbal Communication

Benefits

Parental Leave
Flexible Paid Time Off
Medical Insurance
Dental Insurance
Vision Insurance
401k Retirement Plan
Relocation Support
Pet Insurance
Wellness Stipend
Home Office Stipend
Fertility Benefits
Dependent Coverage

Job Description

About Ramp

Ramp is a financial operations platform designed to save companies time and money. Our all-in-one solution combines payments, corporate cards, vendor management, procurement, travel booking, and automated bookkeeping with built-in intelligence to maximize the impact of every dollar and hour spent. More than 40,000 businesses, from family-owned farms to e-commerce giants to space startups, have saved $10B and 27.5M hours with Ramp. Founded in 2019, Ramp powers the fastest-growing corporate card and bill payment platform in America, and enables over $80 billion in purchases each year.


Ramp’s investors include Thrive Capital, Sands Capital, General Catalyst, Founders Fund, Khosla Ventures, Sequoia Capital, Greylock, and Redpoint, as well as over 100 angel investors who were founders or executives of leading companies. The Ramp team comprises talented leaders from leading financial services and fintech companies—Stripe, Affirm, Goldman Sachs, American Express, Mastercard, Visa, Capital One—as well as technology companies such as Meta, Uber, Netflix, Twitter, Dropbox, and Instacart.


Ramp has been named to Fast Company’sMost Innovative Companies list and LinkedIn’sTop U.S. Startups for more than 3 years, as well as the ForbesCloud 100, CNBCDisruptor 50, and TIME Magazine’s 100Most Influential Companies.


About the Role

We are seeking a skilled and detail-orientedSenior Security Program Manager, Public Sector to lead and enhance our organization’s adherence to U.S. government cybersecurity risk management frameworks, including but not limited to FedRAMP and GovRAMP. In this role, you will play a key part in guiding compliance strategies for our public sector initiatives, working cross-functionally to ensure effective security practices and successful authorizations across jurisdictions.

Preference for candidates based in the DC Metro area, though this is not a requirement.

What You’ll Do

  • Lead all aspects of the compliance lifecycle across multiple public sector frameworks (e.g., FedRAMP, GovRAMP), including risk assessments, continuous monitoring, audits, and authorization management

  • Drive complex cross-functional program management efforts involving teams across security, legal, engineering, infrastructure, and product functions.

  • Serve as a subject matter expert on risk management and regulatory compliance for federal, state, and local government environments.

  • Develop and maintain comprehensive security documentation aligned with applicable frameworks, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and data flow diagrams.

  • Monitor compliance with control requirements (e.g., NIST 800-53, GovRAMP Baselines) and coordinate the implementation of technical and procedural safeguards.

  • Engage with third-party assessors (3PAOs or independent assessors), government sponsors, and internal teams to support assessments and audits.

  • Lead readiness assessments and support the prioritization of remediation activities across teams.

  • Manage timely tracking and closure of vulnerabilities and findings; ensure reporting and documentation obligations are met.

  • Provide risk-informed compliance recommendations that influence infrastructure and product development decisions.

  • Collaborate with legal and government affairs teams to ensure compliance with emerging federal and state regulatory requirements.

  • Stay informed on evolving threats, compliance trends, and guidance updates across FedRAMP, GovRAMP, NIST, and other frameworks.

What You Need

  • 5+ years of experience in information security or compliance, with a focus on government and public sector regulatory frameworks (e.g., FedRAMP, GovRAMP, FISMA, NIST RMF).

  • Knowledge of NIST SP 800-53 and experience mapping controls across frameworks.

  • Experience with cloud environments like AWS GovCloud or Azure Government, including implementation of compliant architectures.

  • Proven ability to manage large-scale compliance programs across diverse stakeholder groups.

  • Demonstrated success developing and maintaining regulatory documentation and audit evidence.

  • Experience leading engagements with internal teams, assessors, and government partners.

  • Strong written and verbal communication skills, including translating between technical and executive audiences.

  • Excellent organizational skills and the ability to manage multiple initiatives with competing priorities.

  • Self-starter with strong problem-solving abilities in ambiguous, fast-moving environments.

Nice-to-Haves

  • Relevant certifications: CISSP, CISA, CRISC, CCAK, CGRC (formerly CAP).

  • Experience with automation platforms for GRC and security monitoring (e.g., Wiz, Paramify).

  • Familiarity with other public sector compliance programs (CJIS, IRS 1075, DoD IL5, etc.).

  • Experience supporting product or infrastructure teams through ATO processes.

  • Leadership experience or management of small security/GRC teams.

Benefits (for U.S.-based full-time employees)

  • 100% medical, dental & vision insurance coverage for you

    • Partially covered for your dependents

    • One Medical annual membership

  • 401k (including employer match on contributions made while employed by Ramp)

  • Flexible PTO

  • Fertility HRA (up to $5,000 per year)

  • WFH stipend to support your home office needs

  • Wellness stipend

  • Parental Leave

  • Relocation support to NYC or SF

  • Pet insurance

Other notices

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Ramp Applicant Privacy Notice

Interested in this job?

Application deadline: Open until filled

Logo of Ramp

Ramp

Make expense management easy with Ramp's spend management platform. Combine global corporate cards, travel, expenses and accounts payable to automate finance operations and improve efficiency.

See more jobs
Date PostedJune 10th, 2025
Job TypeFull Time
LocationRemote (US)
Salary$160,400 - $259,200
Exciting remote opportunity (requires residency in United States) for a Senior Security Program Manager, Public Sector at Ramp. Offering $160,400 - $259,200 (full time). Explore more remote jobs on FlexHired!

Safe Remote Job Search Tips

Verify Employer Thoroughly

Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.

Never Pay to Get a Job

Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.

Safeguard Your Personal Information

Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.

Scrutinize Communication & Interviews

Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.

Beware of Unrealistic Offers

If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.

Insist on a Formal Contract

Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.

Subscribe Newsletter

Never miss a remote job opportunity. Subscribe to our newsletter today and receive exclusive job alerts, career advice, and industry insights delivered straight to your inbox.