Manager, Government Compliance & Authorization
Amwell · United States · 1 mo ago
RemoteRemoteLegal$126k–$154k/yrFull-time
About the role
The Manager of Government Compliance & Authorization will lead the strategy, implementation, and maintenance of Amwell’s federal and state authorization programs. This role focuses on achieving and sustaining FedRAMP High authorization while also architecting internal systems for CMMC (Level 2/3), CMS MARS-E, and StateRAMP requirements.
Responsibilities
- Lead the end-to-end authorization process for FedRAMP High, while concurrently driving alignment with CMMC Level 2/3 for DoD contracts and MARS-E 2.2 for CMS/Medicaid engagements
- Manage ongoing FedRAMP continuous monitoring requirements, including monthly deliverables, vulnerability management, and incident reporting to federal agencies
- Collaborate with engineering, security, and operations teams to develop a "comply once, satisfy many" strategy by mapping NIST SP 800-53 Rev 5 controls to CMMC (NIST SP 800-171) and MARS-E requirements to minimize redundant engineering efforts
- Own risk management of services provided to federal agencies, ensuring compliance with High-impact baseline
- Cook up security assessment and authorization (SA&A) activities, including annual assessments and significant change requests
- Develop and maintain FedRAMP authorization packages, including System Security Plans (SSP), Plans of Action and Milestones (POA&M), and Continuous Monitoring deliverables
- Serve as primary point of contact for federal agency customers regarding FedRAMP compliance questions and authorization boundary matters
- Monitor and interpret FedRAMP policy updates and guidance from the FedRAMP PMO, implementing necessary changes to maintain compliance
- Create and deliver training programs to ensure organizational awareness of FedRAMP requirements and responsibilities
- Build and lead a team of compliance analysts and security specialists focused on federal authorization requirements
- Manage relationships with federal authorizing officials, cloud service providers, and other stakeholders in the authorization process
Qualifications
- 7+ years of experience in information security, compliance, or risk management with at least 3 years specifically working with FedRAMP authorizations
- Demonstrated experience successfully achieving FedRAMP High authorization for a cloud service offering (CSO)
- Deep knowledge of NIST SP 800-53 Rev 5 security controls, FISMA, FedRAMP baselines, and federal security authorization processes
- Experience managing continuous monitoring activities and maintaining active FedRAMP ATOs
- 3+ years of people management experience, including hiring, developing, and leading compliance or security teams
- Strong understanding of cloud infrastructure security (AWS, Azure, or GCP) in FedRAMP environments
- Familiarity with healthcare compliance frameworks (HIPAA, HITRUST) and their intersection with federal requirements
- Pioneering project management skills with ability to coordinate complex, multi-stakeholder authorization efforts
- Experience working with 3PAOs and understanding of security assessment methodologies
- Excellent written and verbal communication skills with ability to translate technical security concepts for various audiences
- Relevant certifications such as CISSP, CISM, CAP, or FedRAMP-specific certifications preferred
- Bachelor's degree in Information Security, Computer Science, or related field required; Master's degree preferred
Benefits
- Flexible Personal Time Off (Vacation time)
- 401K match
- Competitive healthcare, dental and vision insurance plans
- Paid Parental Leave (Maternity and Paternity leave)
- Employee Stock Purchase Program
- Free access to Amwell’s Telehealth Services, SilverCloud and The Clinic by Cleveland Clinic’s second opinion program
- Free Subscription to the Calm App
- Tuition Assistance Program
- Pet Insurance