Government Compliance Program Manager

Posted Yesterday
Be an Early Applicant
Canton, MA, USA
In-Office
70K-90K Annually
Mid level
Healthtech • Information Technology • Software • Consulting
The Role
Manage government compliance programs supporting FedRAMP and ITSG-33 authorizations. Create and maintain SSPs, SCTMs, POA&Ms, incident response plans, and audit evidence. Map NIST and CCCS controls to cloud operations, coordinate third-party assessments and government audits, track remediation, support continuous monitoring, conduct vendor risk and privacy reviews, and monitor regulatory updates. Collaborate with engineering, cloud, IT, security leadership, and external auditors.
Summary Generated by Built In

Description

As a Government Compliance Program Manager, you will be heavily involved in preparing our SaaS product and cloud operations for  ITSG-33 and FedRAMP authorizations, as well as maintaining our broader data protection and privacy standards. Working under the direction of security leadership, you will serve as the operational bridge between technical teams and regulatory frameworks—writing security documentation, mapping control implementations, tracking remediation items, and facilitating auditor requests. As a member of our Cloud Services team, your job would involve:

  • Authoring, updating, and maintaining core government compliance packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), and supporting policy documents
  • Mapping operational controls across NIST SP 800-53 and CCCS Medium Cloud Profile to ensure clear alignment with engineering and IT workflows
  • Tracking control coverage and document evidence for identity management, access control, encryption standards, and monitoring routines
  • Coordinating day-to-day operations during third-party assessment (3PAOs) and government audits
  • Managing and updating the Plan of Action and Milestones (POA&M) register—working directly with Cloud/DevOps and Engineering teams to ensure timely remediation of vulnerabilities and findings
  • Collecting, organizing, and validating audit evidence to ensure smooth assessment lifecycles
  • Supporting the execution of the Continuous Monitoring program, including organizing monthly scan reviews, vulnerability logs, and quarterly deliverable packages
  • Assisting in conducting internal assessments, vendor risk evaluations, and data protection reviews for GDP/privacy compliance
  • Monitoring updates to federal standards (NIST, CCCS) and highlighting necessary operational updates to security leadership.

Requirements

  • Experience: 3+ years in Information Security, IT Compliance, or GRC, with direct experience participating in FedRAMP or ITSG-33 Protected B compliance efforts
  • Framework Knowledge: Practical understanding of NIST SP 800-53 controls and how they are implemented within cloud infrastructure (AWS GovCloud, Azure Government, or GCP)
  • Familiarity with general cloud architecture concepts, IAM, FIPS-compliant encryption, SIEM/logging platforms, and vulnerability management tools
  • Hands-on Artifact Creation: Demonstrated experience writing or maintaining compliance artifacts (SSPs, POA&Ms, Incident Response Plans)
  • Project Tracking: Strong organizational skills with experience tracking complex cross-functional deliverables across software and IT teams
  • Strong written communication skills—able to clearly explain technical controls in formal regulatory language
  • Collaborating effectively with software engineers, system admins, and external auditors
  • Certifications: CISA, CRISC, CISM, CAP/CGRC, or Security+ preferred
  • Clearance Eligibility: Ability to obtain or hold government security screening (e.g., PSPC Reliability/Secret in Canada, or US equivalent) is a strong plus.

Hiring salary range: $70,200- $90,000 per year.

Actual salary will be determined based on an individual's skills, experience, education, and other job-related factors permitted by law.

MEDITECH offers competitive employee benefits including but not limited to health, dental, & vision insurance; profit sharing trust and 401(k); tuition reimbursement, generous paid time off, sick days, personal time, and paid holidays. 

This is a hybrid role which includes a blend of in-office and remote work as designated by the management team.


In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. MEDITECH will not sponsor applicants for work visas.

Skills Required

  • 3+ years of experience in information security, IT compliance, or GRC
  • Direct experience participating in FedRAMP or ITSG-33 Protected B compliance efforts
  • Practical understanding of NIST SP 800-53 controls and implementation within cloud infrastructure
  • Familiarity with AWS GovCloud, Azure Government, or Google Cloud Platform
  • Familiarity with cloud architecture, IAM, FIPS-compliant encryption, SIEM/logging platforms, and vulnerability management tools
  • Experience creating or maintaining compliance artifacts such as SSPs, POA&Ms, and Incident Response Plans
  • Experience tracking complex cross-functional deliverables across software and IT teams
  • Strong written communication skills for explaining technical controls in formal regulatory language
  • Ability to collaborate with software engineers, system administrators, and external auditors
  • CISA, CRISC, CISM, CAP/CGRC, or Security+ certification
  • Ability to obtain or hold government security screening, such as PSPC Reliability/Secret or a US equivalent

MEDITECH Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about MEDITECH and has not been reviewed or approved by MEDITECH.

  • Healthcare Strength — Health, dental, and vision insurance are standard, with company‑paid life/AD&D and long‑term disability also provided. Medical coverage is consistently characterized as strong.
  • Leave & Time Off Breadth — PTO, paid holidays, sick time, parental leave/adoption assistance, and Massachusetts Paid Family & Medical Leave are explicitly offered. Time‑off options and flexibility are repeatedly highlighted as strengths.
  • Retirement Support — A 401(k) is available alongside a company‑funded profit‑sharing trust that fully vests after five years. This structure can deliver meaningful value for longer tenure.

MEDITECH Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Westwood, MA
3,108 Employees
Year Founded: 1969

What We Do

One #EHR, no limits. Welcome to the new vision of #healthcare. #Expanse #Greenfield https://ehr.meditech.com/

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Commercial No Fault PIP/ Med Pay Adjuster - Claims Specialist II

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
9 Locations
40000 Employees
61K-113K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
17 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

Integration Engineer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
8 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

Data Modernization [Health Services-Payer]-Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
66 Locations
370000 Employees
124K-280K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account