What you'll do at Persona
- FedRAMP Strategy & Execution
- Lead the development, implementation, and continuous improvement of the company’s FedRAMP compliance program.
- Own the end-to-end process of obtaining and maintaining a FedRAMP Authority to Operate (ATO), including liaising with 3PAOs, the Joint Authorization Board (JAB), and agency sponsors.
- Coordinate internal and external audits, assessments, and penetration tests.
- Documentation & Policy Management
- Draft, maintain, and continuously refine required FedRAMP documentation, including the System Security Plan (SSP), POA&M, Incident Response Plan, and contingency plans.
- Ensure that documentation is consistent, thorough, and audit-ready.
- Cross-Functional Compliance Leadership
- Partner with engineering and DevOps teams to implement required security controls (e.g., logging, access controls, vulnerability management).
- Provide training and guidance to internal stakeholders on FedRAMP obligations and security best practices.
- Continuous Monitoring & Reporting
- Oversee the Continuous Monitoring (ConMon) process, including the submission of monthly, quarterly, and annual reports to government agencies.
- Track and respond to emerging federal compliance requirements, and adapt policies and practices accordingly.
- Risk & Incident Management
- Lead risk assessments and gap analyses to identify compliance deficiencies.
- Drive the incident response lifecycle in coordination with the security team to ensure timely and compliant resolution of security incidents.
What you'll bring to Persona
- Experience & Expertise
- 3+ years of experience in federal IT compliance, cybersecurity compliance, or related areas.
- 2+ years of hands-on experience specifically with FedRAMP and related NIST frameworks (e.g., NIST 800-53, 800-171).
- Successful experience leading a company through FedRAMP ATO or JAB certification is strongly preferred.
- Knowledge & Skills
- Deep knowledge of federal IT compliance and risk management concepts, including FISMA, CISA guidance, and cloud service provider security models.
- Familiarity with cloud platforms such as AWS, GCP, or Azure in a regulated context.
- Strong understanding of technical security controls, vulnerability management, access controls, and secure system design.
- Communication & Leadership
- Exceptional communication, organizational, and project management skills.
- Ability to translate complex compliance requirements into clear, actionable items for technical and non-technical audiences.
- Certifications (Preferred)
- CISSP, CISA, CISM, or Certified FedRAMP Practitioner.
Similar Jobs
What We Do
Persona helps businesses manage KYC/AML/KYB programs, fight fraud, and build trust by automating any identity-related use case with our flexible identity infrastructure. For example, we help Branch automate their KYC process and Coursera verify learners’ identities before delivering course credentials. Beyond securely collecting and verifying user information such as PII, government IDs, and biometric selfies, our platform also provides flexible case review and orchestration tools to help businesses streamline and automate their identity operations — from setting custom rules to ingesting third-party data and triggering external actions.
Why Work With Us
Persona's a leader in identity verification, offering unmatched flexibility to meet diverse business needs. With customizable building blocks, our product adapts to various industries, use cases, and risk levels. Our core value of having a People-first culture thrives on new perspectives that enrich the workplace and support our mission and value.
Gallery









