Senior Public Sector Compliance Manager

Menlo Security Inc. · US - Distributed

Spotted 1h agoFullTime
AI Agent Apply · Ashby & Greenhouse

You find the fit. Your agent handles the form.

Choose a role or send your matches to the agent. It uses your original résumé and saved details, applies in the cloud, and keeps every result in one place.

Review with AI agent
Job description

About this role

Employer-provided description, formatted for easier reading.

Menlo Security is the leader in Browser Security for human and agentic workforces. Our mission is to enable humans and agents to connect, communicate, and collaborate securely, without compromise. The Menlo Browser Security Platform protects organizations from cyberattacks by stopping threats across the web, documents, and email before they reach the user.

With Menlo Agent Runtime Security (MARS), that protection now extends to the AI agents working alongside every employee. Menlo Security is trusted by major global businesses, including Fortune 500 companies and government agencies, to protect their most valuable asset, their data, and is backed by top-tier investors.

About the Role

We are seeking a detail-oriented FedRAMP Compliance Manager to support our organization's adherence to the Federal Risk and Authorization Management Program (FedRAMP) requirements. This role is critical to ensuring our cloud services maintain compliance with federal security standards and support continuous monitoring, authorization processes, and audits.

The ideal candidate will have experience with NIST SP 800-53, FedRAMP documentation, and working with cloud service providers in a regulatory context.

About Menlo Security

Menlo Security, a leader in cloud security, has raised $100 million in Series E funding, valuing the company at $800 million. The round was led by Vista Equity Partners (“Vista”), a leading global investment firm focused on enterprise software, data and technology-enabled businesses, with additional participation from Neuberger Berman funds, General Catalyst, JP Morgan, and other existing investors.

This new capital will further fuel market expansion and empower the company to scale go-to-market capabilities, as well as provide increased investment in engineering to accelerate product delivery and category expansion.

As businesses of all sizes embrace remote working and migrate to software as a service (SaaS), security is being completely re-architected to combat modern day threats such as phishing and ransomware. Traditional “detect and respond” approaches fail to provide the safety that users and businesses need. Menlo Security’s mission is to make internet use safe, seamless, and effective.

The Menlo Security Cloud SWG is an extensible security platform – built on a unique isolation core – that delivers on the promise of cloud security by:

  • Providing the most effective zero trust approach to preventing malicious attacks;
  • Offering a seamless experience for end users that allows for safe, uninterrupted work while accessing the internet, SaaS or private applications; and
  • Removing the significant operational burden for security operations teams.

Exciting things are happening at Menlo! We’re looking to grow in the next phase of our journey, and we need talented people to help us get there.

Our five core values are

Customer Empathy, Thinking Creatively, Stay Aligned, Get It Done, Help Each Other Out. If you want to make a real impact, solve new challenges and take ownership of your career, we encourage you to apply and join our team!

The company is headquartered in Mountain View, California. For more company information, visit http://www. menlosecurity.

com or @menlosecurity. To learn more about the product: https://try. menlosecurity.

com .

Responsibilities

  • Develop and govern a comprehensive compliance roadmap to maintain CMMC certification, mitigating risks across all internal and external systems.
  • Drive strategic initiatives for high-priority federal projects, ensuring all systems and processes meet the rigorous requirements for DoD Impact Level 6 (IL6) authorization.
  • Serve as the Subject Matter Expert (SME) for FedRAMP High standards.
  • Act as a key liaison to the Federal Sales Team, serving as a subject matter expert (SME) to ensure all business development activities align with federal regulatory standards and security compliance frameworks.
  • Support the FedRAMP Moderate authorization and reauthorization processes, including development, review, and maintenance of system security documentation (SSP, POA&M, SAP, SAR, etc.).
  • Map and analyze security controls against FedRAMP Moderate/High baselines and NIST SP 800-53 controls.
  • Assist in implementing and monitoring security controls for FedRAMP-authorized systems.
  • Coordinate with internal teams (engineering, operations, DevSecOps) to ensure security requirements are integrated into system design and operation.
  • Maintain continuous monitoring documentation and support periodic assessments (e.g., annual assessments, penetration tests, vulnerability scans).
  • Interface with Third Party Assessment Organizations (3PAOs), government customers, and internal stakeholders to support audits and assessments.
  • Track and manage Plan of Action and Milestones (POA&M) items to closure.
  • Manage the Administration, Training and Development of the FedRAMP platform and all associated monthly, quarterly, annual requirements as per the FedRAMP authorization process.
  • Provide compliance reporting, metrics, and risk analysis to management.
  • Stay up to date with changes in FedRAMP requirements, NIST guidance, and related compliance frameworks (e.g., FISMA, CMMC).

Required Qualifications

  • U.S. Citizenship (required for working in GovCloud environments).
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
  • 2–3 years of experience in information security compliance or risk management, preferably in a FedRAMP or FISMA-regulated environment.
  • Strong knowledge of NIST SP 800-53, FedRAMP Moderate/High baselines, and the FedRAMP authorization process.
  • Experience with security documentation (SSP, POA&M, SAR, SAP, etc.) and governance tools.
  • Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys) and interpreting security findings.
  • Eligibility to obtain security clearance is required.

Preferred Qualifications

  • Experience working with or in a 3PAO or federal agency.
  • FedRAMP or NIST security control implementation experience in AWS, Azure, or Google Cloud environments.

Security certifications such as:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Auditor (CISA)
  • Certified Authorization Professional (CAP)
  • CompTIA Security+ or equivalent

Soft Skills

  • Strong analytical and problem-solving skills.
  • Ability to work independently and manage multiple priorities in a fast-paced environment.
  • Effective written and verbal communication abilities.
  • Ability to collaborate across teams and explain technical issues to non-technical stakeholders.
  • Self-motivated with the ability to manage multiple priorities.

Follow us on LinkedIn !

Why Menlo?

At Menlo, we don't settle for the status quo — in our technology or our culture. How we think and act is just as important as what we build.

Our culture is defined by five core mindsets

Proactive Leadership , Straight Talk , United Impact , Elevated Talent , and Customer-Compelled . We take ownership and drive outcomes without waiting to be told. We communicate directly and seek hard truths.

We break down silos and win together. We hold a high bar for ourselves and the people around us. And we treat every customer interaction as mission-critical.

If you're someone who sees it, owns it, solves it, and does it — you'll thrive here.

All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability .

TO ALL AGENCIES

Please, no phone calls or emails to any employee of Menlo Security outside of the Talent organization. Menlo Security’s policy is to only accept resumes from agencies via Ashby (ATS). Agencies must have a valid services agreement executed and must have been assigned by the Talent team to a specific requisition.

Any resume submitted outside of this process will be deemed the sole property of Menlo Security. In the event a candidate submitted outside of this policy is hired, no fee or payment will be paid.

Interested in this role?Continue on Menlo Security Inc.'s careers page.
Apply on Menlo Security Inc.