Director, Public Sector Compliance

Posted 6 Hours Ago
Be an Early Applicant
Cambridge, MA, USA
In-Office
215K-230K Annually
Senior level
Artificial Intelligence • Software • Generative AI • Automation
The Role
Owns Blitzy’s public-sector compliance and authorization roadmap, advancing the platform from FedRAMP Moderate to High and DoD SRG IL4/IL5. The role leads control implementation, SSP quality, assessments, automated evidence, continuous monitoring, and government stakeholder relationships. It partners with sales on security reviews and ATO strategies, supports engineering with automatable requirements, manages 3PAOs and agencies, and identifies compliance capabilities that can become products for the defense industrial base.
Summary Generated by Built In

Blitzy is a Cambridge, MA based AI software development platform on a mission to revolutionize the software development life cycle by autonomously building custom software to unlock the next industrial revolution. We're transforming how enterprises build software, turning enterprise requirements into enterprise grade code with an agentic software development platform that can autonomously execute 80% of the quantum of software development work. We're backed by multiple tier 1 investors, and have proven success as founders of previous start-ups.

Our Culture

Who we are:

Led by two pioneering co-founders we are one of the fastest growing companies in the U.S., creating our own category of enterprise autonomous software development. We automate thousands of hours of software development for our customers, which includes strong representation within the Fortune 500.

How we work:

  • We move Blitzy Fast: Time is both our company’s and our clients’ most precious asset. We move quickly and decisively to innovate internally and deliver exceptional software externally.

  • Championship Mindset: We operate like a professional sports team. We win as a team by holding ourselves and each other to high standards, collaborating in-person, and remaining focused on the mission.

  • Passion for Invention: We’re pushing the frontier of what’s possible, requiring constant innovation and iteration.

  • We Work for the Customer: We focus on delivering outsized value to the customers we work with and expanding those relationships into deep, meaningful partnerships.

About the Role

Compliance is the single biggest blocker between Blitzy and the public sector market - and, handled correctly, one of our biggest product opportunities. Federal agencies, the defense industrial base, and the integrators who serve them want what our enterprise customers already have: an agentic platform that turns requirements into production-ready code. Getting there is an accreditation problem, and we’re hiring the leader who will own it.

The near-term mandate is clear. Drive Blitzy from FedRAMP Moderate to FedRAMP High as quickly as we can defensibly get there, because High is the baseline for DoD SRG IL2, IL4, and IL5. National security mission and business systems at the unclassified level — Advana among them — require IL5, and we intend to operate there.

The longer-term mandate is more interesting. Static authorization packages and POA&M bookkeeping are giving way to proactive, continuous security. You’ll build our posture that way from the start, and then help productize the internal primitives you create as part of the broader Blitzy Proactive Insights portfolio, aligned to the cyber security needs of the DIB.

This is a compliance title attached to a revenue mandate. Every control you land unblocks, closes, or expands a deal. You’ll work in person in Cambridge, MA with direct access to the founders and the engineers building the platform.

Responsibilities
  • Own the roadmap and execution from FedRAMP Moderate to High, then to DoD SRG IL4/IL5 — boundary definition, control implementation strategy, SSP quality, and the assessment calendar.

  • Partner with GTM on every public sector opportunity: security reviews, agency and prime questionnaires, ATO strategy, and the compliance narrative that turns a blocked deal into a landed and expanded one.

  • Replace point-in-time compliance with automated evidence, control monitoring, and drift detection so authorization is a byproduct of how we operate, not a project we run.

  • Identify which internal compliance and security primitives have external value, and work with product and engineering to bring them to market for the defense industrial base.

  • Manage 3PAO, sponsoring agency, FedRAMP PMO, and DISA engagement — and represent Blitzy credibly with government security stakeholders.

  • Own the unglamorous foundations — configuration baselines, vulnerability management, access control, incident response, supply chain — and make build-versus-buy calls that keep cost and dependency in check.

  • Give engineering clear, automatable requirements instead of compliance homework, and give GTM answers they can use on their own.

 
Qualifications
  • 8+ years in security, compliance, or GRC leadership, including ownership of a federal authorization program end to end.

  • Hands-on experience taking a cloud system through FedRAMP authorization, and direct familiarity with what FedRAMP High and DoD SRG IL4/IL5 actually require beyond Moderate.

  • Deep working fluency in NIST 800-53, the FedRAMP baselines, the DoD Cloud Computing SRG, and adjacent regimes such as CMMC.

  • Track record of managing 3PAOs, sponsoring agencies, and government security reviewers — and of getting decisions out of them.

  • Demonstrated impact on revenue: you’ve personally unblocked, accelerated, or expanded deals where security and compliance were the obstacle.

  • Technical depth sufficient to earn engineering’s respect — cloud architecture, infrastructure as code, CI/CD, and evidence automation are conversations you can hold your own in.

  • Excellent written communication. Control narratives, agency responses, and customer-facing security documentation are all writing problems.

  • Existing relationships and credibility across the defense industrial base, primes, or DoD program offices.

Salary Range: $215,000-$230,000 Bonus + Equity

Blitzy is an equal opportunity employer committed to building a diverse and inclusive team. We believe different perspectives make us stronger. Base salary ranges are determined by country, role, level, experience, and skills. The range displayed on each job posting reflects Blitzy’s good faith determination of the minimum and maximum targets for new hire salaries across all ocations. Individual pay is determined by related factors, including job skills, experience, and relevant education or training, which may impact a final offer. Your Talent Partner can share more about the specific salary range during the hiring process.

Skills Required

  • 8+ years in security, compliance, or GRC leadership
  • End-to-end ownership of a federal authorization program
  • Hands-on experience taking a cloud system through FedRAMP authorization
  • Direct familiarity with FedRAMP High and DoD SRG IL4/IL5 requirements
  • Deep working knowledge of NIST 800-53, FedRAMP baselines, DoD Cloud Computing SRG, and adjacent regimes such as CMMC
  • Experience managing 3PAOs, sponsoring agencies, and government security reviewers
  • Track record of unblocking, accelerating, or expanding revenue opportunities through security and compliance
  • Technical depth in cloud architecture, infrastructure as code, CI/CD, and evidence automation
  • Excellent written communication for control narratives, agency responses, and customer-facing security documentation
  • Existing relationships and credibility across the defense industrial base, primes, or DoD program offices
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Year Founded: 2023

What We Do

Blitzy is an autonomous software development platform that enables development teams to transform six-month software projects into six-day turnarounds. By leveraging an agentic platform with thousands of specialized AI agents and 'System 2 Thinking,' Blitzy automates over 80% of the software development lifecycle for enterprise codebases, delivering high-quality, production-ready code with precision and speed.

Similar Jobs

NinjaOne Logo NinjaOne

Software Engineer

Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Remote or Hybrid
18 Locations
2000 Employees
150K-230K Annually

NinjaOne Logo NinjaOne

Senior Release Manager

Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Remote or Hybrid
18 Locations
2000 Employees
110K-170K Annually

Zapier Logo Zapier

Automation Strategist, Customer Success

Artificial Intelligence • Productivity • Software • Automation
In-Office or Remote
3 Locations
800 Employees
158K-238K Annually

STR Logo STR

Program Manager

Machine Learning • Security • Software • Analytics • Defense
Easy Apply
In-Office
Woburn, MA, USA
800 Employees
147K-200K Annually

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account