Freshworks
Director, FedRAMP Program
San Mateo, CA, United States · Director
Sponsorship not specified$53k-$800kDetected 34 days ago
AWSAzureCloud PlatformsCybersecurityPenetration TestingSOC OperationsIncident ResponseComplianceSAPSupply ChainProcurementCustomer SuccessCustomer SupportHIPAALeadershipCommunication
About the role
- Company Description Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives.
- Software is a choice that can make or break a business.
- Business software has become a blocker instead of ways to get work done.
Responsibilities
- Own and lead the company's FedRAMP program from readiness (FW has completed RADD for Moderate) through ATO and continuous monitoring.
- Develop the overall FedRAMP ATO strategy, roadmap, execution plan, work breakdown structure, milestone plan, and executive reporting model.
- Lead the company through FedRAMP Moderate authorization, with a path to FedRAMP High for future ATO.
- Define and manage the FedRAMP authorization boundary for the cloud service offering.
- Partner with Security, Engineering, Product, IT, Legal, Privacy, Compliance, and GTM teams to align FedRAMP requirements with business and customer needs.
- Maintain executive-level visibility into program status, risks, decisions, blockers, and funding needs.
- Own the development, maintenance, and quality of the FedRAMP authorization package, including the SSP, SAP, SAR, POA&M, control implementation narratives, policies, standards, procedures, control inheritance documentation, architecture diagrams, data flow diagrams, boundary documentation, and supporting operational evidence.
- Build a durable evidence repository and repeatable evidence collection process.
- Serve as the primary internal program owner for external FedRAMP partners, including advisors, consultants, 3PAOs, and agency stakeholders.
- Manage 3PAO engagement timelines, dependencies, artifacts, and issue resolution.
Requirements
- 10+ years of experience in cybersecurity, compliance, GRC, cloud security, audit, risk management, or security program leadership.
- Strong working knowledge of the FedRAMP authorization lifecycle, NIST SP 800-53, FedRAMP Rev.
- Strong knowledge of SaaS/cloud architecture, preferably AWS, Azure, or multi-cloud environments.
- Strong understanding of technical security domains, including IAM, vulnerability management, logging/monitoring, encryption, incident response, secure SDLC, change management, and cloud infrastructure security.
- Ability to communicate clearly with both technical teams and executive stakeholders.
- Partner with Engineering, Cloud Infrastructure, and Cybersecurity teams to implement FedRAMP-required security controls in a SaaS cloud environment.
- Help engineering teams understand not just what is required, but why it matters and how to implement it sustainably.
Nice to have
- Experience leading or supporting FedRAMP High authorization.
- Experience with both agency authorization and legacy JAB-style authorization expectations.
- Experience working directly with FedRAMP advisors, 3PAOs, agency sponsors, and federal customer security teams.
- Experience with AWS GovCloud, Azure Government, or other government cloud environments.
- Experience with adjacent and additive frameworks such as CMMC, ITAR, SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, StateRAMP, IRAP, or ISMAP.
- Experience supporting federal go-to-market, RFP responses, security questionnaires, and customer trust programs.
- Certifications such as CISSP, CISM, CISA, CRISC, PMP, CCSP, or equivalent experience.
- Experience in standing up a new FedRAMP program from scratch.
Skills
- Compensation is based on a variety of factors, including but not limited to location, experience, job-related skills, and level.
Compensation
- The annual base salary range for this position is $205,000 - $255,000.
Benefits
- With a fresh vision for how the world works.
Company info
- We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant, richer environment that boosts the goals of our employees, communities, and business.
Visa & Work Authorization
- icer and owns the end-to-end FedRAMP journey, from readiness and authorization planning through 3PAO assessment, agency sponsor coordination, Authorization to Operate (ATO), and post-authorization continuous monitoring
Apply directly at Freshworks →Create a free account for alerts like thisView Freshworks immigration profile
This listing is sourced directly from Freshworks's careers page and normalized into a canonical job model.