ID.me is seeking a Staff Security Assurance Controls Manager to lead the development, implementation, and ongoing operation of our internal control program for external security and privacy frameworks including FedRAMP, ISO 27001, and SOC 2.
Requirements
- Framework Ownership: Serve as the day-to-day owner for one or more frameworks (e.g., NIST 800-63, FedRAMP, ISO 27001, SOC 2), ensuring alignment between framework requirements and internal controls.
- Control Lifecycle Management: Collaborate with control owners to design, implement, document, and monitor controls. Define control objectives, implementation guidance, and assurance requirements.
- Audit & Assessment Readiness: Coordinate internal and external audits by developing audit plans, preparing walkthroughs, and managing evidence collection activities.
- Continuous Monitoring: Maintain a recurring schedule of control validations based on framework-specific frequency requirements (e.g., FedRAMP ConMon). Track control health and remediation actions.
- Gap Analysis & Risk Assessments: Lead gap analyses between new framework requirements and existing control coverage. Facilitate Security Impact Assessments (SIAs) to assess compliance implications of changes and identify risks.
- Compliance Documentation: Manage organizational policies. Ensure up-to-date, reviewer-approved documentation exists for policies, procedures, and implementation statements. Lead annual reviews and updates.
- Control Remediation & POA&M Management: Partner with control owners to define corrective actions, manage Plans of Action & Milestones (POA&Ms), and track resolution through closure. Propose and coordinate the design of controls to mitigate risks.
- Stakeholder Engagement: Act as a trusted partner to engineering, product, infrastructure, and customer-facing teams. Provide clear guidance on what controls are required, why, and how to satisfy them.
- Tooling & Metrics: Support the use of GRC and data pipelines to automate evidence collection, track control status, and generate metrics for reporting.
Benefits
- Comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with company match, parental leave, ability to participate in unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays, short and long-term disability insurance, accident and critical illness insurance, referral bonus policy, employee assistance program, pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates, and a learning and development benefit