Technical Program Manager - FedRAMP
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more sustainable, more inclusive world.
About The Job You're Considering
Capgemini is seeking a seasoned Program Manager to lead the creation, authorization, and continuous governance of a FedRAMP-compliant Azure Government tenant underpinning government payment transaction services. You will own the end-to-end program—system boundary definition, documentation, ATO readiness, , and continuous monitoring—ensuring sustained compliance at FedRAMP High The ideal candidate blends rigorous compliance leadership with strong cloud security and platform enablement skills and has demonstrated success in -system subject to federal compliance.
Your Role
Key Responsibilities
- Program Leadership and Governance
- Own the multi-year FedRAMP roadmap for an Azure Government tenant supporting government transactions; define milestones, risks, dependencies, and decision gates.
- Establish governance forums and operating mechanisms across engineering, cloud platform, information security, risk/compliance, legal, payment operations, and 3PAOs.
- Maintain program OKRs/KPIs: POA&M closure velocity, control coverage, vulnerability SLAs, ConMon completeness, audit readiness, and
- Drive disciplined change control, evidence management, , and control attestation workflows aligned to FedRAMP requirements.
- Manage external partners and 3PAO activities (readiness, assessments, remediation)
- FedRAMP Authorization (ATO) Readiness
- Lead authoring and maintenance of FedRAMP artifacts: SSP and associated FedRAMP appendices, POA&M, policies/standards/procedures, boundary diagrams, and data flows tailored to Azure Government/GCC High constructs.
- Define and maintain the system boundary and data categorization supporting payment transactions; align to FedRAMP High baseline.
- Coordinate control implementation across all FedRAMP control families. .
- Conduct gap analyses against NIST SP 800-53 controls; drive remediation plans and ensure traceability from control narratives to technical and process evidence.
- Continuous Monitoring & Operations
- Stand up and run Continuous Monitoring, in alignment with FedRAMP High guidelines, for the Azure Government tenant: scanning cadence, patch cycles, configuration baseline monitoring, control effectiveness checks, incident handling, and change compliance.
- Own POA&M lifecycle: triage findings, prioritize by risk, execute corrective actions, validate closure, reporting outstanding actions, and update artifacts.
- Maintain real-time dashboards and reporting for control posture, exceptions, residual risk, and operational health across payment services and shared services.
- Ensure SSP and supporting documentation are promptly updated to reflect material changes to boundary, services, configurations, or controls.
- Coordinate security incident response processes with SOC teams and act as interface with the client throughout the incident lifecycle including root cause analysis and closure.
- Audit, Stakeholder, and External Engagement
- Serve as the primary contact for internal/external audits, 3PAO assessments, and authorizing officials; coordinate evidence collection and subject matter responses.
- Prepare teams for assessments; lead walkthroughs, demos, and artifact reviews; shepherd remediation and risk acceptance processes as appropriate.
- Enable engineering, operations, and payment teams with training and lightweight process embeds to sustain day-to-day FedRAMP compliance.
- Risk Management and Issue Resolution
- Maintain a program risk register spanning control gaps, architectural changes, data flows, vendor dependencies, and operational risks in payment services.
- Escalate issues with quantified impact; drive compensating controls or risk acceptance decisions in partnership with risk/compliance.
Your Skills And Experience
Required Qualifications
- 7+ years of program management in regulated cloud environments; 3+ years directly owning FedRAMP programs, artifacts, and Continuous Monitoring.
- Hands-on oversight, authorship, maintenance and response experience with SSP, POA&M, SAP/SAR; proven track record achieving/maintaining ATO for cloud services.
- Deep knowledge of NIST SP 800-53 control families, FedRAMP Moderate/High baselines, ConMon processes, and 3PAO engagements.
- Strong familiarity with Azure Government or GCC High and core security capabilities: identity/access, logging/monitoring, encryption, policy enforcement, landing zone patterns.
- Demonstrated success orchestrating cross-functional teams (security, cloud/platform, payments, operations, compliance, legal) to deliver complex regulatory programs.
- Exceptional communication skills: executive reporting, control narratives, audit responses, and stakeholder management.
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or related field; equivalent experience considered.
Preferred Qualifications
- Direct experience enabling government payment transactions on cloud platforms and aligning control implementations to transactional risk profiles.
- Azure-focused security experience (Defender for Cloud, Sentinel, Azure Policy/Blueprints, Key Vault, Private Link, Purview).
- Prior experience collaborating with federal agencies, sponsoring organizations, or authorizing officials for ATOs.
- Experience with security compliance to IRS 1075 requirements
- Certifications: PMP, CISSP, CCSP, CISM, Azure Security Engineer Associate, or equivalent.
Key Competencies
- Ownership and disciplined execution across multi-workstream, cross-functional programs.
- Ability to translate regulatory requirements into practical, testable technical and process controls.
- Risk-based decision-making with clear prioritization and measurable outcomes.
- Influencing and stakeholder leadership; driving alignment without formal authority.
- Documentation rigor and audit readiness; maintaining high-quality, current artifacts.
- Continuous improvement mindset; leveraging metrics to improve control posture and operational efficiency.
Work Arrangement and Location
- Flexible work arrangements may be available in accordance with company policies and applicable role requirements.
- Limited travel may be required for assessments, audits, or stakeholder workshops.
Program KPIs (example targets; customizable)
- POA&M closure: ≤ 30 calendar days average for High findings; ≤ 60 for Moderate.
- Continuous Monitoring: 100% monthly reporting completeness across in-scope services.
- Configuration drift: ≤ 5% variance from baseline across evaluated resources per month.
- Vulnerability remediation: Meet or exceed FedRAMP timelines by severity category.
Audit readiness: “Green” status across evidence completeness and control demonstration prior to 3PAO assessments.
The base compensation range for this role in the posted location is: $70,176- $170,040.
Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.
The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.
These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.
It is not typical for candidates to be hired at or near the top of the posted compensation range.
In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.
Capgemini offers a comprehensive, non-negotiable benefits package to all regular, full-time employees. In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include:
- Paid time off based on employee grade (A-F), defined by policy: Vacation: 12-25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave
- Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
- Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
- Life and disability insurance
- Employee assistance programs
- Other benefits as provided by local policy and eligibility
Important Notice: Compensation (including bonuses, commissions, or other forms of incentive pay) is not considered earned, vested, or payable until it becomes due under the terms of applicable plans or agreements and is subject to Capgemini’s discretion, consistent with applicable laws. The Company reserves the right to amend or withdraw compensation programs at any time, within the limits of applicable legislation.
Disclaimers
Capgemini is an Equal Opportunity Employer encouraging inclusion in the workplace. Capgemini also participates in the Partnership Accreditation in Indigenous Relations (PAIR) program which supports meaningful engagement with Indigenous communities across Canada by promoting fairness, accessibility, inclusion and respect. We value the rich cultural heritage and contributions of Indigenous Peoples and actively work to create a welcoming and respectful environment. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.
This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodation does not pose an undue hardship. Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.
Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.
Click the following link for more information on your rights as an Applicant in the United States. http://www.capgemini.com/resources/equal-employment-opportunity-is-the-law
Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.
New York, NY, US Tampa, FL, US Berwyn, PA, US
Nearest Major Market: Manhattan
Nearest Secondary Market: New York City