Freshworks

Freshworks

Director, FedRAMP Program

San Mateo, CA, United States · Director

Sponsorship not specified$53k-$800kDetected 34 days ago
AWSAzureCloud PlatformsCybersecurityPenetration TestingSOC OperationsIncident ResponseComplianceSAPSupply ChainProcurementCustomer SuccessCustomer SupportHIPAALeadershipCommunication

About the role

  • Company Description Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives.
  • Software is a choice that can make or break a business.
  • Business software has become a blocker instead of ways to get work done.

Responsibilities

  • Own and lead the company's FedRAMP program from readiness (FW has completed RADD for Moderate) through ATO and continuous monitoring.
  • Develop the overall FedRAMP ATO strategy, roadmap, execution plan, work breakdown structure, milestone plan, and executive reporting model.
  • Lead the company through FedRAMP Moderate authorization, with a path to FedRAMP High for future ATO.
  • Define and manage the FedRAMP authorization boundary for the cloud service offering.
  • Partner with Security, Engineering, Product, IT, Legal, Privacy, Compliance, and GTM teams to align FedRAMP requirements with business and customer needs.
  • Maintain executive-level visibility into program status, risks, decisions, blockers, and funding needs.
  • Own the development, maintenance, and quality of the FedRAMP authorization package, including the SSP, SAP, SAR, POA&M, control implementation narratives, policies, standards, procedures, control inheritance documentation, architecture diagrams, data flow diagrams, boundary documentation, and supporting operational evidence.
  • Build a durable evidence repository and repeatable evidence collection process.
  • Serve as the primary internal program owner for external FedRAMP partners, including advisors, consultants, 3PAOs, and agency stakeholders.
  • Manage 3PAO engagement timelines, dependencies, artifacts, and issue resolution.

Requirements

  • 10+ years of experience in cybersecurity, compliance, GRC, cloud security, audit, risk management, or security program leadership.
  • Strong working knowledge of the FedRAMP authorization lifecycle, NIST SP 800-53, FedRAMP Rev.
  • Strong knowledge of SaaS/cloud architecture, preferably AWS, Azure, or multi-cloud environments.
  • Strong understanding of technical security domains, including IAM, vulnerability management, logging/monitoring, encryption, incident response, secure SDLC, change management, and cloud infrastructure security.
  • Ability to communicate clearly with both technical teams and executive stakeholders.
  • Partner with Engineering, Cloud Infrastructure, and Cybersecurity teams to implement FedRAMP-required security controls in a SaaS cloud environment.
  • Help engineering teams understand not just what is required, but why it matters and how to implement it sustainably.

Nice to have

  • Experience leading or supporting FedRAMP High authorization.
  • Experience with both agency authorization and legacy JAB-style authorization expectations.
  • Experience working directly with FedRAMP advisors, 3PAOs, agency sponsors, and federal customer security teams.
  • Experience with AWS GovCloud, Azure Government, or other government cloud environments.
  • Experience with adjacent and additive frameworks such as CMMC, ITAR, SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, StateRAMP, IRAP, or ISMAP.
  • Experience supporting federal go-to-market, RFP responses, security questionnaires, and customer trust programs.
  • Certifications such as CISSP, CISM, CISA, CRISC, PMP, CCSP, or equivalent experience.
  • Experience in standing up a new FedRAMP program from scratch.

Skills

  • Compensation is based on a variety of factors, including but not limited to location, experience, job-related skills, and level.

Compensation

  • The annual base salary range for this position is $205,000 - $255,000.

Benefits

  • With a fresh vision for how the world works.

Company info

  • We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant, richer environment that boosts the goals of our employees, communities, and business.

Visa & Work Authorization

  • icer and owns the end-to-end FedRAMP journey, from readiness and authorization planning through 3PAO assessment, agency sponsor coordination, Authorization to Operate (ATO), and post-authorization continuous monitoring

This listing is sourced directly from Freshworks's careers page and normalized into a canonical job model.