Senior Security Assurance Technical Program Manager
ID.meAbout the role
Company Overview
ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 140 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 44 state government agencies, and 66 healthcare organizations. More than 600 consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.
Role Overview
We are seeking a highly skilled Senior Security Assurance Technical Program Manager to join our compliance and security team with a significant focus on Sarbanes Oxley 404 compliance. This role is critical in designing, implementing, and managing security and compliance programs that align with external regulatory requirements. The ideal candidate will be responsible for ensuring compliance with SOX, FedRAMP, ISO 27001, and SOC 2 Type II frameworks, while also leading internal assessments, evidence collection, and audit readiness efforts. This role will work closely with internal teams to validate compliance, manage assurance activities, and maintain our Governance, Risk, and Compliance (GRC) tool.
This is an onsite position in one of our hub locations (Mountain View CA or McLean VA)
Responsibilities
- Develop and implement a SOX compliance program, ensuring alignment with regulatory requirements.
- Contribute to the ongoing maintenance and enhancement of FedRAMP, ISO 27001, and SOC 2 Type II compliance programs.
- Work cross-functionally with teams to design, implement, and monitor the status of security controls that meet compliance requirements.
- Manage audit readiness efforts, ensuring timely and accurate collection of evidence for external and internal audits.
- Collaborate with stakeholders to create system-specific evidence requests and validate compliance with established controls.
- Lead and perform internal control assessments to verify the effectiveness of security measures and compliance efforts.
- Interview internal teams to assess control effectiveness, identify gaps, and document findings.
- Ensure quality assurance of deliverables produced by other team members, maintaining consistency and accuracy.
- Driving the process to remediate control deficiencies and monitoring of remediation efforts.
- Maintain a list of baseline and unique controls
- Provide clear and detailed explanations of controls to auditors to facilitate successful audits.
- Develop and manage schedules for compliance validation, continuous monitoring, and reporting.
- Maintain and improve the organization’s GRC tool, ensuring accurate tracking and reporting of compliance activities, and enabling automated control evidence collection and measurement.
Basic Qualifications
- Bachelor's degree in information technology, accounting, or a related field, or equivalent experience.
- 8 to 12 years of experience in compliance program management, including working with technical and business stakeholders to design and prepare IT General Controls (ITGCs), Internal Controls over Financial Reporting (ICFRs), fraud and other financial controls, and regulatory reporting with technical and business stakeholders.
- 8 to 12 years of experience implementing the COSO framework
- 5 to 7 years of experience conducting internal compliance assessments and audits, including interviews and evidence collection.
- 3 to 5 years of experience managing a quality control system to ensure work products and internal processes meet audit standards.
- 2 to 3 years of experience using GRC tools to track, manage, and report on compliance activities.
Preferred Qualifications
- Experience designing and implementing 1 to 2 internal control programs aligned with regulatory requirements.
- Experience working at a big 4 accounting firm in the capacity of supporting SOX internal control programs and audits.
- 5 years of experience with NIST 800-53 requirements.
- CPA certification (active or inactive)
- Strong project management skills, including planning, work tracking, and st
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s