Jobs · Project Management

Principal Technical Program Manager

Oracle · United States · Yesterday
RemoteRemoteProject Management$98k–$210k/yrFull-time

About the role

Oracle Health is seeking a Principal Technical Program Manager to establish and lead the Product Authorization Team responsible for FedRAMP assessment readiness, authorization strategy, and continuous security assurance for cloud service offerings. This role combines principal-level technical program leadership with deep cloud security and compliance-engineering expertise. You will create the operating model that turns federal security requirements into sustainable engineering practices, trusted evidence, measurable security outcomes, and clear executive decisions. You will work at the intersection of cloud architecture, security engineering, product delivery, and federal authorization. Success requires the ability to move comfortably between architecture and control discussions, third-party assessment strategy, remediation execution, and senior-leadership tradeoffs. This is a hands-on leadership role. You will not serve as the independent assessor; however, you must have sufficient security-engineering depth to challenge design assumptions, assess evidence quality, identify material gaps, and drive practical remediation with technical teams.

Responsibilities

  • Stand up the Oracle Health Product Authorization FedRAMP Team and define its charter, service model, roles, intake and prioritization process, governance cadences, quality standards, metrics, and escalation paths.
  • Own the multi-year FedRAMP authorization and certification roadmap for assigned cloud offerings, including scope, sequencing, authorization-path recommendations, dependencies, reuse opportunities, investment needs, and transition to continuous assurance.
  • Establish a scalable assessment operating model for readiness reviews, authorization-boundary definition, evidence planning, package development, 3PAO engagement, testing, findings management, remediation validation, and post-authorization monitoring.
  • Partner with architecture and security-engineering teams to evaluate service boundaries, data flows, interconnections, multi-tenancy, identity, encryption, logging, resilience, supply-chain dependencies, control inheritance, and customer-responsible controls.
  • Translate FedRAMP, NIST, and federal risk-management requirements into owned, testable, time-bound engineering and operational deliverables; set acceptance criteria for evidence, security decisions, and remediation plans.
  • Design reusable evidence and assurance patterns using security telemetry, infrastructure as code, CI/CD controls, configuration validation, GRC workflows, machine-readable data, and automation where appropriate.
  • Lead strategic engagement with 3PAOs, FedRAMP and agency stakeholders, federal customers, advisors, and critical suppliers; resolve escalations involving scope, testing, evidence, findings, or schedule.
  • Drive material risks, findings, and plans of action through root-cause analysis, prioritization, remediation, validation, risk acceptance, and closure; ensure decisions are documented and traceable.
  • Establish executive dashboards and operating reviews that show authorization readiness, critical-path dependencies, evidence quality, open findings, vulnerability and change posture, staffing needs, and decisions required.
  • Embed authorization obligations into secure software delivery, vulnerability management, incident response, change management, configuration management, contingency planning, and cloud operations.
  • Create a continuous-monitoring and ongoing-certification model that keeps authorization information current, supports required reporting, and enables agencies to make informed risk decisions.
  • Mentor TPMs and security partners, publish playbooks and reusable patterns, and raise the organization's capacity to deliver federal authorizations consistently without weakening security outcomes.

Minimum Qualifications

  • Bachelor's degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related discipline, or equivalent practical experience.
  • Seven or more years of experience in technical program management, security program leadership, cloud delivery, compliance engineering, security engineering, or a related technology field, including responsibility for complex cross-organizational programs.
  • Demonstrated experience leading an end-to-end FedRAMP certification or authorization, federal Authority to Operate, or comparably complex regulated cloud-assurance program from strategy or readiness through assessment, remediation, decision, and ongoing monitoring.
  • Deep working knowledge of FedRAMP authorization and certification processes; NIST SP 800-53 Rev. 5; FIPS 199; federal risk management; control implementation and assessment; control inheritance; significant change; vulnerability management; remediation; and continuous monitoring.
  • Strong technical understanding of SaaS and IaaS architecture, including authorization boundaries, multi-tenancy, identity and access management, network segmentation, encryption and key management, logging and monitoring, secure software delivery, resilience, and supply-chain dependencies.
  • Demonstrated ability to define operating models, governance, roadmaps, metrics, and executive decision mechanisms across Security, Engineering, Product, Operations, Compliance, Legal, and business organizations.
  • Experience assessing technical evidence and communicating concrete security requirements to engineering teams, including cloud configuration, vulnerability, identity, logging, encryption, change, and incident-response evidence.
  • Experience leading engagements and resolving complex issues with independent assessors, agencies, authorizing stakeholders, federal customers, or comparable external oversight bodies.
  • Exceptional written, verbal, and executive communication skills, including the ability to translate technical and regulatory complexity into clear business risk, investment choices, and recommendations.
  • Proven ability to influence senior leaders and technical teams, resolve competing priorities, and drive accountable decisions without direct organizational authority.

Preferred Qualifications

  • Experience establishing or materially scaling a FedRAMP, product authorization, GRC, security-assessment, or continuous-assurance function.
  • Experience with multiple FedRAMP Moderate or High authorizations, FedRAMP 20x certifications, authorization reuse, or a portfolio of federal cloud services.
  • Experience designing compliance-as-code, automated evidence, persistent validation, Security Decision Records, Key Security Indicators, or machine-readable assurance programs integrated with engineering systems.
  • Experience with OSCAL, GRC platforms, cloud security posture management, infrastructure as code, CI/CD security, security data analytics, or automated control validation.
  • Strong hands-on experience in cloud and platform security across OCI, AWS, Azure, or another hyperscale cloud platform; working familiarity with Kubernetes or container security is highly desirable.
  • Relevant certifications such as CISSP, CCSP, CISM, CRISC, PMP, a cloud security certification, or equivalent demonstrated experience.
  • Experience supporting U.S. federal customers or cloud services subject to federal security, privacy, records-management, or health-data requirements.

Pay

US: Hiring Range in USD from: $97,500 – $209,500 per year. May be eligible for bonus and equity. Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Benefits

  • Medical, dental, and vision insurance, including expert medical opinion
  • Short term disability and long term disability
  • Life insurance and AD&D
  • Supplemental life insurance (Employee/Spouse/Child)
  • Health care and dependent care Flexible Spending Accounts
  • Pre-tax commuter and parking benefits
  • 401(k) Savings and Investment Plan with company match
  • Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
  • 11 paid holidays
  • Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
  • Paid parental leave
  • Adoption assistance
  • Employee Stock Purchase Plan
  • Financial planning and group legal
  • Voluntary benefits including auto, homeowner and pet insurance

Similar jobs