refresh

Trending Companies

Trending

Jobs

JobsRamp

Senior Security Program Manager | Public Sector

Ramp

Senior Security Program Manager | Public Sector

Ramp

New York, NY (HQ)

·

On-site

·

Full-time

·

2w ago

Benefits & Perks

Healthcare

401(k)

Flexible Hours

Parental Leave

Pet Insurance

Home Office Stipend

Mental Health

Healthcare

401k

Flexible Hours

Parental Leave

Pet Insurance

Home Office

Mental Health

Required Skills

Information Security

Compliance Management

Risk Assessment

Documentation

Stakeholder Management

ABOUT RAMP

At Ramp, we’re rethinking how modern finance teams function in the age of AI. We believe AI isn’t just the next big wave. It’s the new foundation for how business gets done. We’re investing in that future — and in the people bold enough to build it.

Ramp is a financial operations platform designed to save companies time and money. Our all-in-one solution combines payments, corporate cards, vendor management, procurement, travel booking, and automated bookkeeping with built-in intelligence to maximize the impact of every dollar and hour spent. More than 50,000 businesses, from family-owned farms to e-commerce giants to space startups, have saved $10B and 27.5M hours with Ramp. Founded in 2019, Ramp powers the fastest-growing corporate card and bill payment platform in America, and enables over $100 billion in purchases each year.

Ramp’s investors include Lightspeed Venture Partners, Thrive Capital, Sands Capital, General Catalyst, Founders Fund, Khosla Ventures, Sequoia Capital, Greylock, Redpoint, and ICONIQ, as well as over 100 angel investors who were founders or executives of leading companies. The Ramp team comprises talented leaders from leading financial services and fintech companies—Stripe, Affirm, Goldman Sachs, American Express, Mastercard, Visa, Capital One—as well as technology companies such as Meta, Uber, Netflix, Twitter, Dropbox, and Instacart.

Ramp has been named to Fast Company’s Most Innovative Companies https://www.fastcompany.com/91038883/ramp-most-innovative-companies-2024 list and LinkedIn’s Top U.S. Startups https://www.linkedin.com/pulse/linkedin-top-startups-2024-50-us-companies-rise-linkedin-news-hxote/?trackingId=uBI29YlAOxikbTI7cdvG4g%3D%3D for more than 3 years, as well as the Forbes Cloud 100 https://www.forbes.com/sites/richardnieva/2024/08/06/ramp-cloud-100/, CNBC Disruptor 50 https://www.cnbc.com/2024/05/14/ramp-cnbc-disruptor-50.html, and TIME Magazine’s 100 Most Influential Companies https://time.com/collection/time100-companies-2023/6285147/ramp/.

ABOUT THE ROLE:

We are seeking a skilled and detail-oriented Senior Security Program Manager, Public Sector to lead and enhance our organization’s adherence to U.S. government cybersecurity risk management frameworks, including but not limited to FedRAMP and GovRAMP. In this role, you will play a key part in guiding compliance strategies for our public sector initiatives, working cross-functionally to ensure effective security practices and successful authorizations across jurisdictions.

WHAT YOU’LL DO:

  • Lead all aspects of the compliance lifecycle across multiple public sector frameworks (e.g., FedRAMP, GovRAMP), including risk assessments, continuous monitoring, audits, and authorization management

  • Drive complex cross-functional program management efforts involving teams across security, legal, engineering, infrastructure, and product functions.

  • Serve as a subject matter expert on risk management and regulatory compliance for federal, state, and local government environments.

  • Develop and maintain comprehensive security documentation aligned with applicable frameworks, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and data flow diagrams.

  • Monitor compliance with control requirements (e.g., NIST 800-53, GovRAMP Baselines) and coordinate the implementation of technical and procedural safeguards.

  • Engage with third-party assessors (3PAOs or independent assessors), government sponsors, and internal teams to support assessments and audits.

  • Lead readiness assessments and support the prioritization of remediation activities across teams.

  • Manage timely tracking and closure of vulnerabilities and findings; ensure reporting and documentation obligations are met.

  • Provide risk-informed compliance recommendations that influence infrastructure and product development decisions.

  • Collaborate with legal and government affairs teams to ensure compliance with emerging federal and state regulatory requirements.

  • Stay informed on evolving threats, compliance trends, and guidance updates across FedRAMP, GovRAMP, NIST, and other frameworks.

WHAT YOU NEED:

  • 5+ years of experience in information security or compliance, with a focus on government and public sector regulatory frameworks (e.g., FedRAMP, GovRAMP, FISMA, NIST RMF).

  • Knowledge of NIST SP 800-53 and experience mapping controls across frameworks.

  • Experience with cloud environments like AWS Gov Cloud or Azure Government, including implementation of compliant architectures.

  • Proven ability to manage large-scale compliance programs across diverse stakeholder groups.

  • Demonstrated success developing and maintaining regulatory documentation and audit evidence.

  • Experience leading engagements with internal teams, assessors, and government partners.

  • Strong written and verbal communication skills, including translating between technical and executive audiences.

  • Excellent organizational skills and the ability to manage multiple initiatives with competing priorities.

  • Self-starter with strong problem-solving abilities in ambiguous, fast-moving environments.

NICE-TO-HAVES

  • Relevant certifications: CISSP, CISA, CRISC, CCAK, CGRC (formerly CAP).

  • Experience with automation platforms for GRC and security monitoring (e.g., Wiz, Paramify).

  • Familiarity with other public sector compliance programs (CJIS, IRS 1075, DoD IL5, etc.).

  • Experience supporting product or infrastructure teams through ATO processes.

  • Experience with FedRAMP 20x initiatives.

  • Leadership experience or management of small security/GRC teams.

BENEFITS (FOR U.S.-BASED FULL-TIME EMPLOYEES)

  • 100% medical, dental & vision insurance coverage for you

  • Partially covered for your dependents

  • One Medical annual membership

  • 401k (including employer match on contributions made while employed by Ramp)

  • Flexible PTO

  • Fertility HRA (up to $10,000 per year)

  • Parental Leave

  • Unlimited AI token usage

  • Pet insurance

  • Centralized home-office equipment ordering for all employees

  • Health and Wellness stipend

  • In-office perks: lunch, snacks, drinks, and more

  • Budget for intra-office travel

  • Relocation support to NYC or SF (as needed)

REFERRAL INSTRUCTIONS

If you are being referred for the role, please contact that person to apply on your behalf.

OTHER NOTICES

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Ramp Applicant Privacy Notice https://ramp.com/legal/applicant-privacy-notice

Total Views

0

Apply Clicks

0

Mock Applicants

0

Scraps

0

About Ramp

Ramp

Ramp

Series C

The corporate card that helps you spend less.

501-1,000

Employees

New York City

Headquarters

$8.1B

Valuation

Reviews

4.2

15 reviews

Work Life Balance

3.8

Compensation

4.2

Culture

3.5

Career

3.7

Management

3.5

70%

Recommend to a Friend

Pros

High total compensation packages

Strong equity/RSU offerings

Good career growth potential

Cons

Uncertain liquidity timeline for equity

Limited information about company culture

Unclear career advancement paths

Salary Ranges

348 data points

L4

Mid/L4

Senior/L5

L4 · Product Manager

0 reports

$296,333

total / year

Base

-

Stock

-

Bonus

-

$251,883

$340,783

Interview Experience

3 interviews

Difficulty

3.0

/ 5

Duration

14-28 weeks

Interview Process

1

Application Review

2

Recruiter Screen

3

Technical Phone Screen

4

Coding Interview

5

Onsite/Virtual Interviews

6

Offer

Common Questions

Coding/Algorithm

Technical Knowledge

Behavioral/STAR

System Design

Past Experience