APPLY TO SPEEDRUN
← Kaizen Labs
Kaizen Labs · Hiring

Security Compliance Program Manager

New York, NYHybridFull Time$145K – $190K • Offers Equity • Multiple Ranges

Government technology has failed citizens, public servants, and service members for decades.

Kaizen powers America’s application layer. We replace the legacy systems federal agencies run on with modern software, built with craft. The ticketing platform a resident uses to visit a presidential library. The marketplace DoW uses for counter-drone procurement to protect lives and critical infrastructure. The system a Veteran uses to access benefits. We build systems of record, of national consequence. Our AI-native modules and harness allow us to do so in weeks and months, not years.

This year, our revenue has grown 35x. Next year, our software will serve over 100 million Americans across dozens of federal agencies.

Founded in 2022 and based in New York City and DC, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital.

The Role

Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it. We are standing up a dedicated compliance function to own the obligations, the paperwork of record, and the accuracy of everything we submit.

You will build and run that function, working directly with the engineering lead, the incoming security engineer, and the executive team.

Location

New York, NY or Washington, D.C. (Hybrid). This is the permanent version of the role. We are also posting a contract equivalent for the same scope. The differences are that this one carries the authorization program long term, including the path from Moderate to High, and a path to holding the FSO designation yourself.

The Programs

FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. The change-control side of an authorization matters here as much as the initial package. You own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor. You also own the significant-change process, which is the mechanism that makes the model work.

DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer's or a partner's. This role owns knowing the reciprocity map cold, reading a hosting platform's actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary. Reciprocity is inconsistent, so it has to be verified per agency rather than assumed.

CMMC. A separate track from the product, and keeping the two separate is part of the job: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You run the self-assessment against NIST 800-171 Rev 2, own a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries. You drive the scoping decision, which is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident-reporting clauses matters here.

What You'll Do

What You'll Bring

Strong Candidates May Also...

Don't Apply If...

What Kaizen Offers

Health & Insurance

Family & Time Off

Office & Remote Setup

Wellness

Stipends

Interested in This Role?

Apply at Kaizen Labs

You'll head to Kaizen Labs's own careers page.