Medical Information Technology Inc logo

Government Compliance Program Manager

Medical Information Technology Inc
  • Canton, MA
  • $70,200–$90,000 Per Year
9 days ago
Medical Information Technology Inc

Job Description

Apply

Job Type

Full-time

Description

As a Government Compliance Program Manager, you will be heavily involved in preparing our SaaS product and cloud operations for ITSG-33 and FedRAMP authorizations, as well as maintaining our broader data protection and privacy standards. Working under the direction of security leadership, you will serve as the operational bridge between technical teams and regulatory frameworks-writing security documentation, mapping control implementations, tracking remediation items, and facilitating auditor requests. As a member of our Cloud Services team, your job would involve:

  • Authoring, updating, and maintaining core government compliance packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), and supporting policy documents
  • Mapping operational controls across NIST SP 800-53 and CCCS Medium Cloud Profile to ensure clear alignment with engineering and IT workflows
  • Tracking control coverage and document evidence for identity management, access control, encryption standards, and monitoring routines
  • Coordinating day-to-day operations during third-party assessment (3PAOs) and government audits
  • Managing and updating the Plan of Action and Milestones (POA&M) register-working directly with Cloud/DevOps and Engineering teams to ensure timely remediation of vulnerabilities and findings
  • Collecting, organizing, and validating audit evidence to ensure smooth assessment lifecycles
  • Supporting the execution of the Continuous Monitoring program, including organizing monthly scan reviews, vulnerability logs, and quarterly deliverable packages
  • Assisting in conducting internal assessments, vendor risk evaluations, and data protection reviews for GDP/privacy compliance
  • Monitoring updates to federal standards (NIST, CCCS) and highlighting necessary operational updates to security leadership.

Requirements

  • Experience: 3+ years in Information Security, IT Compliance, or GRC, with direct experience participating in FedRAMP or ITSG-33 Protected B compliance efforts
  • Framework Knowledge: Practical understanding of NIST SP 800-53 controls and how they are implemented within cloud infrastructure (AWS GovCloud, Azure Government, or GCP)
  • Familiarity with general cloud architecture concepts, IAM, FIPS-compliant encryption, SIEM/logging platforms, and vulnerability management tools
  • Hands-on Artifact Creation: Demonstrated experience writing or maintaining compliance artifacts (SSPs, POA&Ms, Incident Response Plans)
  • Project Tracking: Strong organizational skills with experience tracking complex cross-functional deliverables across software and IT teams
  • Strong written communication skills-able to clearly explain technical controls in formal regulatory language
  • Collaborating effectively with software engineers, system admins, and external auditors
  • Certifications: CISA, CRISC, CISM, CAP/CGRC, or Security+ preferred
  • Clearance Eligibility: Ability to obtain or hold government security screening (e.g., PSPC Reliability/Secret in Canada, or US equivalent) is a strong plus.

Hiring salary range: $70,200- $90,000 per year.

Actual salary will be determined based on an individual's skills, experience, education, and other job-related factors permitted by law.

MEDITECH offers competitive employee benefits including but not limited to health, dental, & vision insurance; profit sharing trust and 401(k); tuition reimbursement, generous paid time off, sick days, personal time, and paid holidays.

This is a hybrid role which includes a blend of in-office and remote work as designated by the management team.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. MEDITECH will not sponsor applicants for work visas.

Numbers & Facts

LocationCanton, MA
IndustryComputer/IT Services
Salary$70,200–$90,000 Per Year
Company Size2,500 to 4,999 employees
Year Founded1969
Websitehttps://ehr.meditech.com/

About Company

Healthcare is long overdue for genuine disruption and innovation, and MEDITECH is leading the charge by helping care organizations to keep their patients and their business healthy. In countries all over the world, our solutions are empowering users to provide higher quality care, with greater efficiency, to more people, at a lower cost. We work with care organizations to help them overcome obstacles and achieve their goals, whether they're clinical, analytical, or financial. After nearly five decades of continuous growth and innovation, MEDITECH has never been more energized. We’re building the next generation of Electronic Health Record (EHR) leaders - we invite you to join us for the ride.

Skills

  • Access Controlunmatched
  • Amazon Web Services (AWS)unmatched
  • Auditingunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Cross-Functionalunmatched
  • Cryptographyunmatched
  • DevOpsunmatched
  • Document Managementunmatched
  • Documentationunmatched
  • External Auditunmatched
  • Federal Information Processing Standards (FIPS)unmatched
  • GCP (Good Clinical Practices)unmatched
  • Governmentunmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Leadershipunmatched
  • MEDITECHunmatched
  • Maintain Complianceunmatched
  • Microsoft Windows Azureunmatched
  • Operations Security (OPSEC)unmatched
  • Organizational Skillsunmatched
  • Privacy Controlsunmatched
  • Project Trackingunmatched
  • Project/Program Managementunmatched
  • Regulationsunmatched
  • Risk Analysisunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Software Engineeringunmatched
  • Software as a Service (SaaS)unmatched
  • Support Documentationunmatched
  • Systems Administration/Managementunmatched
  • Time Managementunmatched
  • Traceabilityunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vendor/Supplier Evaluationunmatched
  • Vision Planunmatched
  • Vulnerability Scannersunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder