Senior Security Assurance Technical Program Manager
ID.meAbout the role
Company Overview
ID.me is the next-generation digital identity network that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly log in across websites without having to create a new login or verify their identity again. 130 million members experience streamlined login and identity verification with ID.me at 16 federal agencies, 30 states, and 56 healthcare organizations. More than 600 consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships.
ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.
Role Overview
We are seeking a highly skilled Senior Security Assurance Technical Program Manager to join our compliance and security team. This role is critical in designing, implementing, and managing security and compliance programs that align with external regulatory requirements. The ideal candidate will be responsible for ensuring compliance with SOX, FedRAMP, ISO 27001, and SOC 2 Type II frameworks, while also leading internal assessments, evidence collection, and audit readiness efforts. This role will work closely with internal teams to validate compliance, manage assurance activities, and maintain our Governance, Risk, and Compliance (GRC) tool.
Responsibilities:
- Develop and implement a SOX compliance program, ensuring alignment with regulatory requirements.
- Contribute to the ongoing maintenance and enhancement of FedRAMP, ISO 27001, and SOC 2 Type II compliance programs.
- Work cross-functionally with teams to design, implement, and monitor the status of security controls that meet compliance requirements.
- Manage audit readiness efforts, ensuring timely and accurate collection of evidence for external and internal audits.
- Collaborate with stakeholders to create system-specific evidence requests and validate compliance with established controls.
- Lead and perform internal control assessments to verify the effectiveness of security measures and compliance efforts.
- Interview internal teams to assess control effectiveness, identify gaps, and document findings.
- Ensure quality assurance of deliverables produced by other team members, maintaining consistency and accuracy.
- Provide clear and detailed explanations of controls to auditors to facilitate successful audits.
- Develop and manage schedules for compliance validation, continuous monitoring, and reporting.
- Maintain and improve the organization’s GRC tool, ensuring accurate tracking and reporting of compliance activities, and enabling automated control evidence collection and measurement.
Required Qualifications:
- Bachelor's degree in information technology, accounting, or a related field, or equivalent experience.
- 8 to 12 years of experience in compliance program management, including audit readiness, internal/external audit, control validation, and regulatory reporting.
- Strong knowledge of SOX, FedRAMP, ISO 27001, and SOC 2 Type II compliance frameworks.
- Proven ability to design and implement internal control programs aligned with regulatory requirements.
- Experience conducting internal compliance assessments and audits, including interviews and evidence collection.
- Proficiency in using GRC tools to track, manage, and report on compliance activities.
- Ability to communicate compliance concepts effectively to both technical and non-technical audiences.
- Strong project management skills, including planning, work tracking, and stakeholder coordination.
The role will:
- Manage workstreams to monitor control implementation status.
- Conduct compliance and security impact assessments to identify and prescribe controls to mitigate risks.
- Maintain CISSP, CISA, or other relevant security/compliance certifications.
- Have experience accession cloud environments
- Prepare concise and effective written and verbal communications both internally and externally, with customers, regulators, and management.
This is an exciting opportunity for a compliance professional looking to take ownership of high-impact security and compliance initiatives in a dynamic and growing organization. If you have a passion for security, compliance, and audit readiness, we encourage you to apply!
The annual base salary list
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s