Logo for RSI Security

Compliance Program Manager

Role overview

Qualifications

  • Strong knowledge of compliance frameworks and regulatory requirements
  • Experience in program and product management
  • Ability to manage cross-functional teams and projects
  • Excellent communication and documentation skills

Responsibilities

  • Own the organization-wide compliance framework calendar and track regulatory changes
  • Drive internal readiness for authorizations and accreditations
  • Evaluate emerging frameworks for market opportunities and develop business cases
  • Maintain the offering portfolio and collaborate with Finance and Sales on new offerings

Key facts

Hard skills

Other skills

  • Program Management
  • Problem Solving
  • Communication
  • Time Management

About the company

RSI Security logo

RSI Security

Cybersecurity

RSI Security is a cybersecurity-focused technology company that helps private and public sector organizations in highly regulated industries effectively manage risk. RSI Security provides cyber engineering, assessment, advisory services, and technical testing to amp up clients' security posture while mitigating business risk. We have experts for every cybersecurity and compliance need– PCIDSS, CMMC and NIST, MSSP, IT Security, HITRUST, HIPAA / HITECH, CCPA, GDPR, threat detection, security awareness training, and much more. Our team members come from diverse backgrounds and specialties. Our team members include published authors, open-source developers, industry researchers, and conference presenters. For more information, visit rsisecurity.com

Company details

Company typeSME
IndustryCybersecurity
Company size11-50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Compliance Program ManagerDepartment / Seat Name: Compliance
Reports To (LMA): Keith Sipmann
Location: Remote (Role is open to only U.S.-based, U.S.-citizen-only)
Salary: $105,000-$145,000

Role Summary
The Compliance Program Manager owns the full lifecycle of compliance frameworks across the
organization, from regulatory monitoring and internal program readiness through to the
productization and launch of new service offerings. This role is the single accountable owner
for knowing what is changing in the regulatory and framework landscape, determining what the
organization must do about it internally, and converting qualifying frameworks into repeatable,
sellable, deliverable service lines.

This is a hybrid compliance and product role. Approximately half the seat is program
management: tracking framework requirements, owning internal compliance obligations,
maintaining authorization and accreditation readiness, and driving remediation to closure. The
other half is product management: business case development, scoping, methodology design,
pricing input, enablement, and launch coordination for new offerings.
The role is not a people management position but carries cross-functional accountability
across PMO, TAC, Sales, RFP, Marketing, and Finance.

Role Purpose
● To ensure the organization is never surprised by a compliance change, never out of
compliance with the frameworks and authorizations it operates under, and never late to
market with a new offering that the changing landscape creates demand for.

Core Responsibilities

● Compliance Program Ownership
● Own the organization-wide compliance framework calendar, tracking rule changes,
standard revisions, program updates, and authorization requirements across all
frameworks the company operates under or delivers against
● Maintain a current obligations register mapping each external requirement to an internal
owner, control, artifact, and evidence location
● Drive internal readiness for new and renewing authorizations, accreditations, and
program approvals, including document production, gap closure, and submission
coordination
● Coordinate internal audits, surveillance activities, and external assessment cycles,
including scheduling, evidence collection, corrective action tracking, and closure
verification
● Track and drive corrective actions, nonconformities, and findings to documented
closure with defined owners and due dates
● Monitor regulatory and standards bodies for changes affecting the organization's
authorizations, delivery methodologies, or service eligibility, and issue timely impact
analyses to leadership
● Maintain the compliance obligations documentation set, ensuring version control,
currency, and traceability
● Serve as the internal subject matter expert on framework requirements, providing
authoritative interpretation to delivery, sales, and leadership teams
● Escalate impartiality, independence, conflict of interest, and eligibility questions to the
appropriate authority rather than resolving them unilaterally

Productization and Offering Ownership
● Evaluate emerging and revised frameworks for market opportunity, producing a written
business case covering demand signal, competitive landscape, required capability,
margin profile, and go/no-go recommendation
● Own the end-to-end productization of approved offerings, including scope definition,
deliverable set, methodology, work breakdown structure, level of effort model, and
quality gates
● Partner with Finance and Sales leadership to develop pricing, rate card entries, and
margin targets for new offerings
● Build and maintain the delivery artifact set for each offering, document templates,
evidence requirements, and reporting formats
● Partner with TAC and delivery leadership to define staffing requirements, required
credentials, and technical readiness for each new offering
● Develop and deliver enablement materials for Sales, RFP, and delivery teams, including
positioning, qualification criteria, and scoping guidance
● Own the launch plan and post-launch review for each new offering
● Maintain the offering portfolio, identifying offerings that should be revised, repriced,
consolidated, or retired
● Partner with Marketing on messaging accuracy and technical claim review for all
compliance-related content

These are tracked weekly or monthly via the Scorecard:
● Percentage of tracked frameworks with a current obligations mapping
● Open corrective actions past due
● Average days to close a corrective action
● Authorization and accreditation milestones met on schedule
● Regulatory change impact analyses issued within the defined SLA
● Number of framework evaluations completed
● Number of offerings launched per quarter against plan
● Days from go decision to first sellable offering
● Days from go decision to first delivered engagement
● Revenue attributable to offerings launched in the trailing four quarters
● Enablement completion rate across Sales and delivery teams for each launched offering
● Internal audit and surveillance findings attributable to program management gaps
Right Mindset & Cultural Fit

This role requires someone who consistently demonstrates:
● You read primary sources rather than relying on summaries, vendor blogs, or
secondhand interpretation
● You are comfortable owning an outcome without owning the people who produce it
● You bring a recommendation, not just a problem, and you can defend it with evidence
● You are equally comfortable in a requirements document and in a pricing model
● You move quickly on market opportunity without cutting corners on compliance
obligations
● You escalate independence and impartiality questions early rather than working around
them
● You write clearly enough that a salesperson, a project manager, and an assessor can all
act on the same document
● You align with RSI's Core Values and commitment to quality

Misalignment Indicators
This seat is considered vacant or at risk if the person:
● Learns about a framework or regulatory change after the market or a client does
● Allows corrective actions, findings, or obligations to sit open without escalation
● Produces offerings that Sales cannot sell or that delivery cannot execute profitably
● Treats productization as documentation work rather than as owning a commercial
outcome
● Defers framework interpretation questions upward instead of developing authoritative
command of the requirements
● Launches offerings without pricing, staffing, delivery templates, and enablement in
place
● Resolves impartiality or independence questions unilaterally rather than routing them to
the appropriate authority
● Cannot establish credibility with delivery leads, assessors, or client-facing teams

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Program Manager Related jobs

Other jobs at RSI Security

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.