RSI Security Logo

Compliance Program Manager

💰 $105k-$145k

Job Description

Compliance Program Manager

Department / Seat Name: Compliance

Reports To (LMA): Keith Sipmann

Location: Remote (Role is open to only U.S.-based, U.S.-citizen-only)

Salary: $105,000-$145,000

Role Summary

The Compliance Program Manager owns the full lifecycle of compliance frameworks across the

organization, from regulatory monitoring and internal program readiness through to the

productization and launch of new service offerings. This role is the single accountable owner

for knowing what is changing in the regulatory and framework landscape, determining what the

organization must do about it internally, and converting qualifying frameworks into repeatable,

sellable, deliverable service lines.

This is a hybrid compliance and product role. Approximately half the seat is program

management: tracking framework requirements, owning internal compliance obligations,

maintaining authorization and accreditation readiness, and driving remediation to closure. The

other half is product management: business case development, scoping, methodology design,

pricing input, enablement, and launch coordination for new offerings.

The role is not a people management position but carries cross-functional accountability

across PMO, TAC, Sales, RFP, Marketing, and Finance.

Role Purpose

● To ensure the organization is never surprised by a compliance change, never out of

compliance with the frameworks and authorizations it operates under, and never late to

market with a new offering that the changing landscape creates demand for.

Core Responsibilities

● Compliance Program Ownership

● Own the organization-wide compliance framework calendar, tracking rule changes,

standard revisions, program updates, and authorization requirements across all

frameworks the company operates under or delivers against

● Maintain a current obligations register mapping each external requirement to an internal

owner, control, artifact, and evidence location

● Drive internal readiness for new and renewing authorizations, accreditations, and

program approvals, including document production, gap closure, and submission

coordination

● Coordinate internal audits, surveillance activities, and external assessment cycles,

including scheduling, evidence collection, corrective action tracking, and closure

verification

● Track and drive corrective actions, nonconformities, and findings to documented

closure with defined owners and due dates

● Monitor regulatory and standards bodies for changes affecting the organization’s

authorizations, delivery methodologies, or service eligibility, and issue timely impact

analyses to leadership

● Maintain the compliance obligations documentation set, ensuring version control,

currency, and traceability

● Serve as the internal subject matter expert on framework requirements, providing

authoritative interpretation to delivery, sales, and leadership teams

● Escalate impartiality, independence, conflict of interest, and eligibility questions to the

appropriate authority rather than resolving them unilaterally

Productization and Offering Ownership

● Evaluate emerging and revised frameworks for market opportunity, producing a written

business case covering demand signal, competitive landscape, required capability,

margin profile, and go/no-go recommendation

● Own the end-to-end productization of approved offerings, including scope definition,

deliverable set, methodology, work breakdown structure, level of effort model, and

quality gates

● Partner with Finance and Sales leadership to develop pricing, rate card entries, and

margin targets for new offerings

● Build and maintain the delivery artifact set for each offering, document templates,

evidence requirements, and reporting formats

● Partner with TAC and delivery leadership to define staffing requirements, required

credentials, and technical readiness for each new offering

● Develop and deliver enablement materials for Sales, RFP, and delivery teams, including

positioning, qualification criteria, and scoping guidance

● Own the launch plan and post-launch review for each new offering

● Maintain the offering portfolio, identifying offerings that should be revised, repriced,

consolidated, or retired

● Partner with Marketing on messaging accuracy and technical claim review for all

compliance-related content

These are tracked weekly or monthly via the Scorecard:

● Percentage of tracked frameworks with a current obligations mapping

● Open corrective actions past due

● Average days to close a corrective action

● Authorization and accreditation milestones met on schedule

● Regulatory change impact analyses issued within the defined SLA

● Number of framework evaluations completed

● Number of offerings launched per quarter against plan

● Days from go decision to first sellable offering

● Days from go decision to first delivered engagement

● Revenue attributable to offerings launched in the trailing four quarters

● Enablement completion rate across Sales and delivery teams for each launched offering

● Internal audit and surveillance findings attributable to program management gaps

Right Mindset & Cultural Fit

This role requires someone who consistently demonstrates:

● You read primary sources rather than relying on summaries, vendor blogs, or

secondhand interpretation

● You are comfortable owning an outcome without owning the people who produce it

● You bring a recommendation, not just a problem, and you can defend it with evidence

● You are equally comfortable in a requirements document and in a pricing model

● You move quickly on market opportunity without cutting corners on compliance

obligations

● You escalate independence and impartiality questions early rather than working around

them

● You write clearly enough that a salesperson, a project manager, and an assessor can all

act on the same document

● You align with RSI’s Core Values and commitment to quality

Misalignment Indicators

This seat is considered vacant or at risk if the person:

● Learns about a framework or regulatory change after the market or a client does

● Allows corrective actions, findings, or obligations to sit open without escalation

● Produces offerings that Sales cannot sell or that delivery cannot execute profitably

● Treats productization as documentation work rather than as owning a commercial

outcome

● Defers framework interpretation questions upward instead of developing authoritative

command of the requirements

● Launches offerings without pricing, staffing, delivery templates, and enablement in

place

● Resolves impartiality or independence questions unilaterally rather than routing them to

the appropriate authority

● Cannot establish credibility with delivery leads, assessors, or client-facing teams

Share this job:
Please let RSI Security know you found this job on Remote First Jobs 🙏

Explore more remote jobs

4025 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like RSI Security

Find your next opportunity with companies that specialize in Managed Security Services, Compliance & Advisory Services, Managed It Compliance, and It Security Solutions. Explore remote-first companies like RSI Security that prioritize flexible work and home-office freedom.

Coalfire Logo

Coalfire

Delivers cybersecurity and compliance services for technology, healthcare, and finance industries.

View company profile →
GuidePoint Security Logo

GuidePoint Security

Provides trusted cybersecurity expertise, solutions, and services to minimize risk for organizations.

View company profile →
Pondurance Logo

Pondurance

Managed Detection and Response (MDR) cybersecurity services powered by human intelligence.

View company profile →
VerSprite Cybersecurity Logo

VerSprite Cybersecurity

Provides threat modeling, penetration testing, and risk management services globally.

View company profile →
Check Point Software Logo

Check Point Software

Provides AI-powered cybersecurity solutions for organizations and governments globally.

View company profile →
CyBourn Logo

CyBourn

Provides Extended Detection and Response (XDR) and Managed Security Services to protect governments, businesses, and consumers.

View company profile →

Project: Career Search

Rev. 2026.9

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply