--- title: 'Senior FedRamp Program Manager at Agiloft' canonical: 'https://feeny.ai/job/senior-fedramp-program-manager-agiloft-united-states-zpbvqrvetzwd' type: 'job' last_seen: '2026-09-25' --- # Senior FedRamp Program Manager at Agiloft - **Company:** Agiloft - **Location:** United States - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-09-22 - **Last confirmed live:** 2026-09-25 - **Apply:** https://jobs.lever.co/agiloft/0f63819a-69e7-4686-a94a-bb02358cc44c ## Job description As the most trusted global leader in data-first contract lifecycle management (CLM) software, Agiloft helps organizations manage the end-to-end process of proposing, negotiating, signing, and leveraging contracts using our flexible Data-first Agreement Platform (DAP). With contract data as the foundation, customers quickly and collaboratively reach agreement and leverage contract visibility to thrive with competitive advantage. Employing powerful, pragmatic artificial intelligence as a legal force multiplier, and robust integration capabilities as a data liberator, organizations around the world trust Agiloft’s certified implementers to deliver connected, intelligent, and autonomous solutions across the entire contract lifecycle. Top analysts like Gartner, Forrester, and IDC agree, all showing Agiloft as a leader in the CLM space. Our no code platform is easily managed and administered by business users, which is why Agiloft is the contract you keep: nearly a full 100% of new customers are satisfied with their initial implementations, and some 97% of customers renew every year. Ours is a growing, vibrant, successful company that is at the forefront of a market that is becoming a must-have for all organizations. We believe that the way to build the strongest, most vibrant place to work is to bring in individuals from all walks of life, and to support them in bringing their authentic selves to their day, every day. Our working philosophy is that “EX = CX”: when employee experience is excellent, so is customer experience. We support multiple Employee Resource Groups (ERGs), and offer a working environment that supports healthy work/life balance, including floating holidays and a quarterly, no-questions-asked wellness day. Position Overview The FedRAMP Program Manager serves as the day-to-day owner of the company’s responsibilities within a partner-managed FedRAMP environment. This individual translates FedRAMP, NIST SP 800-53, assessment, and external-partner requirements into clear internal actions; coordinates evidence and remediation activities across functional teams; manages deadlines and shared-responsibility dependencies; and independently evaluates whether company work, remediation responses, and evidence are sufficiently complete and responsive for submission to external FedRAMP partners, assessors, or other stakeholders. The role works with limited day-to-day supervision under the direction of the Director of Security and Compliance, establishes the operating structure needed to keep the program moving, and provides timely visibility into program status, risks, blockers, and required decisions. This is an individual-contributor program execution and subject-matter-expert role; it does not perform engineering implementation or technical remediation. Strong performance in this role results in a FedRAMP program that remains organized, assessment-ready, and on schedule, with clear ownership, reliable evidence, timely remediation, and emerging risks addressed before they become compliance blockers. Job Responsibilities FedRAMP Program Execution - Own day-to-day execution of the company side of the FedRAMP program, including milestones, dependencies, risks, deadlines, and internal follow-through. - Translate FedRAMP requirements, findings, partner requests, and service-level commitments into clear internal actions with defined owners, due dates, evidence expectations, and acceptance criteria. - Maintain an authoritative view of program status and proactively identify work that may threaten assessment, remediation, continuous-monitoring, or other FedRAMP deadlines. - Assess overall program readiness and proactively identify systemic gaps in controls, evidence, ownership, processes, or dependencies that could jeopardize FedRAMP objectives - Operate independently within established direction by determining required next actions, establishing priorities and deadlines, resolving routine program and ownership issues, and escalating material risks, disputed requirements, risk-acceptance decisions, missed commitments, or matters requiring management, partner, or specialized technical intervention. - Leverage approved AI-enabled tools and automation to improve the efficiency and quality of program activities while independently validating outputs against authoritative requirements and program context Evidence, Controls, and Remediation Coordination - Coordinate implementation and ongoing operation of organizational and procedural controls retained by the company, including identifying and working with appropriate internal control owners. - Coordinate company inputs into partner-managed FedRAMP records, including control narratives, evidence, remediation information, and other required program documentation. - Collect and review evidence for completeness, accuracy, relevance, currency, traceability to applicable controls or findings, and consistency with documented FedRAMP and partner requirements before submission. - Act as the company-side quality gate for evidence and remediation responses, independently rejecting incomplete or inadequate submissions and requiring correction before external submission while escalating interpretation disputes or questions of external acceptance when appropriate. - Track findings from initial assessments, continuous monitoring, and other authorized testing through assignment, remediation, evidence submission, and closure. - Establish internal remediation deadlines, with management input as appropriate, based on external deadlines, service-level requirements, risk, and program dependencies. Cross-Functional and Partner Coordination - Serve as the primary operational interface with the company’s external FedRAMP infrastructure and compliance partner. - Participate in partner-led continuous-monitoring meetings and ensure resulting actions, findings, requests, and decisions are communicated, assigned, tracked, and completed internally. - Work closely with Software Engineering and Cloud Engineering to communicate technical compliance requirements, remediation expectations, deadlines, and required evidence without performing the technical remediation directly. - Coordinate with Security, IT, Support, Operations, Product, Legal, and leadership on organizational controls, process changes, customer or contractual considerations, and other FedRAMP-related obligations. - Drive commitments across teams that do not report directly to the role through clear requirements, follow-through, escalation, and accountability. - Engage appropriate technical or functional subject-matter experts when specialized validation is required and ensure their conclusions are reflected in the program record. Scope, Change, and Program Governance - Maintain clarity over FedRAMP-in-scope users, systems, workflows, integrations, organizational processes, control inheritance, and shared-responsibility boundaries. - Maintain clear understanding of which obligations are retained by the company versus operated, inherited, or evidenced by external partners. - Coordinate review of proposed product, infrastructure, operational, or process changes that may affect FedRAMP scope, documented behavior, or control responsibilities. - Coordinate delivery and maintenance of required compliant system artifacts, including the approved operating-system image, by the teams responsible for engineering and implementation. - Identify gaps or ambiguity in responsibility between the company and external partners and drive resolution before those gaps create compliance or delivery risk. - Recommend program priorities and corrective actions based on FedRAMP requirements, organizational readiness, risk, external dependencies, and authorization objectives - Provide FedRAMP subject-matter input to Product, Legal, and other stakeholders, distinguishing documented requirements from partner preferences, interpretation questions, and internal risk decisions. - Continuously improve FedRAMP processes, documentation, evidence practices, ownership models, and operating routines to create a sustainable and repeatable compliance program Reporting and Escalation - Provide concise, decision-ready reporting to the Director of Security and Compliance on program status, upcoming deadlines, open findings, remediation progress, evidence quality, partner dependencies, and material risks. - Escalate early when a missed or threatened deadline, disputed requirement, repeated quality failure, unresolved ownership issue, or external dependency requires management or executive intervention. - Clearly identify decisions requiring management, risk-owner, partner, legal, or specialized technical input rather than allowing unresolved issues to delay program execution. - Other duties as assigned Required Qualifications - 7+ years of relevant professional experience in security, compliance, technical program management, risk management, cloud security, or related disciplines, including at least 3 years of direct FedRAMP program execution or ownership experience. - Demonstrated ownership of a substantial portion of at least one FedRAMP authorization lifecycle, including activities such as readiness or gap assessment, control implementation and evidence readiness, assessment support, findings or POA&M remediation, authorization activities, and transition into continuous monitoring. - Experience operating a FedRAMP program after authorization, including continuous monitoring, recurring evidence collection, remediation deadlines, scope or significant-change considerations, and assessment preparation. - Strong working knowledge of NIST SP 800-53 and the FedRAMP Moderate baseline, including the ability to interpret controls, implementation statements, control inheritance, shared responsibility, assessment findings, and evidence requirements. - Experience operating within cloud or compliance shared-responsibility models, including identifying control ownership, inherited versus customer responsibilities, evidence dependencies, and gaps between provider and customer obligations. - Demonstrated ability to translate FedRAMP requirements into clear, actionable expectations, owners, deadlines, evidence requirements, and acceptance criteria for technical and non-technical teams. - Experience evaluating whether evidence and remediation responses adequately address stated control requirements or findings, including the judgment to reject inadequate company submissions before external review. - Demonstrated ability to drive remediation and compliance commitments across Software Engineering, Cloud or Platform Engineering, IT, Security, Support, Product, and other teams without direct management authority. - Working technical knowledge of SaaS and cloud environments sufficient to understand and discuss identity and access management, CI/CD and deployment paths, vulnerability management, logging and monitoring, system boundaries, encryption, change management, software dependencies, and cloud infrastructure. - Ability to recognize when specialized technical validation is required and engage the appropriate subject-matter experts rather than serving as the hands-on implementer. - Demonstrated ability to independently establish program structure, determine required next actions from regulatory and partner requirements, resolve ambiguous ownership, establish priorities and deadlines, and appropriately escalate matters requiring management, risk-owner, partner, or technical-specialist decisions. - Experience effectively leveraging AI-enabled tools, automation, or other advanced systems to improve productivity, analysis, and program execution, with demonstrated judgment in validating outputs and determining when human or subject-matter-expert review is required. - Strong written and verbal communication skills, including the ability to communicate requirements, deficiencies, risk, program status, and decisions clearly to engineers, business stakeholders, external partners, assessors, and leadership. - Must be a U.S. Person and reside in the United States. ## Preferred Qualifications - 5+ years of direct FedRAMP program execution experience and/or experience owning multiple authorization lifecycles. - Experience independently leading company-side execution through a FedRAMP authorization lifecycle, including establishing program structure, driving organizational readiness, coordinating assessment activities, and transitioning into continuous monitoring - Experience operating in a fully self-managed FedRAMP environment, particularly for a SaaS or cloud software provider. - Experience in a partner-managed FedRAMP implementation where the candidate owned company-side execution, evidence quality, remediation tracking, control ownership, and shared-responsibility coordination. - Experience working directly with FedRAMP assessors, 3PAOs, agency or authorization stakeholders, managed hosting providers, or other external authorization and compliance partners. - Experience supporting FedRAMP scope, authorization-boundary, significant-change, change-management, or continuous-monitoring decisions in a SaaS or cloud environment. Experience coordinating remediation of security findings across software engineering, cloud or platform engineering, IT, and security teams without serving Ensuring a diverse and inclusive workplace is our priority. We are committed to an environment of acceptance where you are free to bring your full self to work. All employment decisions at Agiloft are based on business needs, job requirements, and individual qualifications without regard to race, color, religion or belief, national or social ethnic origin, sex, age, sexual orientation, gender identity and/or expression, parental status, marital status, Veteran status, or any other status protected by the laws or regulations in the locations where we operate. If you have a need that requires accommodation during the recruiting process, please let us know by contacting Director, Talent Acquisition, Brad Toothman at brad.toothman@agiloft.com. Applicants from underrepresented groups such as minorities, veterans, or individuals with disabilities encouraged to apply. Applications will be reviewed as submitted. There will be no application deadline for this opportunity. ## About Agiloft ## Company Overview - **One-liner**: Agiloft provides a data-first Contract Lifecycle Management (CLM) and AI platform that helps enterprises automate, govern, and extract value from their contracts. - **Entity Type**: Private (Strategic investment from KKR, prior growth equity from FTV Capital) - **Headquarters**: Redwood City, California, United States - **Founded**: 1991 - **Founders**: Colin Earl ## Core Business - **Primary industry**: Contract Lifecycle Management (CLM) Software / Legal Technology - **Target customers**: Enterprise legal, procurement, and sales operations teams (B2B, Enterprise) - **Mission statement**: "To transform contracts from static agreements into powerful drivers of growth." ## Products & Services - **Agiloft CLM Platform**: The core enterprise-grade Contract Lifecycle Management solution that centralizes, automates, and governs every stage of the contract process—from request and negotiation to execution and value recognition. It features a flexible, no-code architecture that allows any approved team member to configure workflows, approval chains, and processes without writing code. - **Astra**: A contracts AI platform designed to help legal and procurement teams uncover answers, apply their standards, and make every contract improve the next. AI is embedded throughout the platform for extraction, risk analysis, and contract interrogation, with configurable agents that review, negotiate, and onboard contracts automatically. - **Data-First Agreement Platform (DAP)**: Extracts actionable intelligence from every agreement to drive smarter decisions on revenue, risk, and operations across the organization. - **Integrations**: Works with Salesforce, SAP, Oracle, and over 1,000 other pre-built connectors to sync data between Finance, Sales, Legal, and IT systems. ## Market Standing - **Valuation**: Not disclosed - **Key Metric**: Annual revenue of $36M (as per LinkedIn data); Total funding of $45M across prior rounds. - **Notable Investors/Partners**: KKR (strategic investment in 2024), FTV Capital (growth equity investment). Key leadership includes CEO Eric Laughlin, CTO John Pechacek, CPO Andy Wishart, CRO Kevin Niblock, and CLO Jason Barnwell. - **Growth Signals**: Headcount of 313 employees (+17.5% YoY, +60 people); First acquisition completed in 2025 (Screens.AI); Launch of the Astra AI platform in 2025; 100+ product reviews averaging 4.7/5.0; Employer rating of 4.1/5.0 from 142 reviews. ## Competitive Advantages - **Data-first CLM approach**: Differentiates from competitors by not just storing contracts but extracting actionable intelligence to drive business decisions. - **Embedded AI (Astra)**: AI is not a bolt-on feature but is baked into the core platform for extraction, risk analysis, and automated negotiation, with auditable outputs and traceable decisions. - **No-code configurability**: The platform's flexible architecture allows rapid deployment and customization without IT support, lowering time-to-value. - **Deep enterprise integrations**: Over 1,000 pre-built connectors (with Salesforce, SAP, Oracle) ensure seamless workflow across an organization's existing tech stack. - **Strong partner backing**: Strategic investment from KKR signals confidence in the company's long-term growth trajectory. ## Strategic Focus - **AI-first expansion**: The launch of Astra and the acquisition of Screens.AI point to a strong push toward embedding advanced AI agents throughout the contract lifecycle. - **Continued M&A**: The first acquisition (Screens.AI) suggests a strategy of acquiring niche technologies to accelerate product capabilities. - **Scaling the customer base**: With a growing headcount and a focus on enterprise accounts (visible in current job postings), the company is aggressively expanding its market presence. - **Product-led growth**: The emphasis on a "data-first agreement platform" and configurable, no-code solutions positions them to win deals against legacy CLM providers. ## Why Work Here - **People-first culture**: The company explicitly states a people-first culture with a focus on diversity, equity, and inclusion, supported by dedicated Employee Resource Groups (ERGs). - **Fully remote and globally distributed**: Agiloft is a fully remote company with employees across 14 countries, including the United States, India, Canada, the United Kingdom, and Russia. - **Learning & development**: Employees receive a quarterly development budget, unlimited access to Udemy, and 24 hours of dedicated growth time per year. - **Comprehensive benefits**: Medical, dental, and vision coverage for employees and family; paid parental leave; 401(k) with company match; remote work stipend (internet reimbursements); annual company offsite. - **Strong employer rating**: 4.1/5.0 on LinkedIn (Work-Life: 4.2, Compensation: 4.1, Culture: 4.2, Career: 4.0), indicating a healthy work environment. - **Innovation at scale**: Working on a platform that processes millions of contracts, with the opportunity to shape how AI is applied in a critical enterprise domain. ## Sources 1. [Agiloft Official Site](https://www.agiloft.com/) 2. [Agiloft About Us](https://www.agiloft.com/about-us) 3. [Agiloft Careers Page](https://www.agiloft.com/careers) 4. [Agiloft Lever Job Board](https://jobs.lever.co/agiloft) 5. [Agiloft LinkedIn](https://linkedin.com/company/agiloft) ## Other roles at Agiloft - [Demand Generation and Account-Based Marketing Manager](https://feeny.ai/job/demand-generation-and-account-based-marketing-manager-agiloft-united-states-vfba1cyyh8kx) — United States - [Strategic Account Manager](https://feeny.ai/job/strategic-account-manager-agiloft-united-states-54hqbg4thmwx) — United States - [Senior Integration Engineer](https://feeny.ai/job/senior-integration-engineer-agiloft-canada-tq3p3vkn6fb9) — Canada - [Senior Integration Engineer](https://feeny.ai/job/senior-integration-engineer-agiloft-united-states-cjbzn2m1rkqf) — United States - [Strategic Customer Success Manager – Remote](https://feeny.ai/job/strategic-customer-success-manager-remote-agiloft-united-kingdom-1y7rkd2ckxke) — United Kingdom - [Senior IT Solutions Architect - Remote](https://feeny.ai/job/senior-it-solutions-architect-remote-agiloft-united-states-km5ke5dkep4j) — United States - [AI Ops Engineer GTM](https://feeny.ai/job/ai-ops-engineer-gtm-agiloft-united-states-0yz23zx2r4zd) — United States - [Senior Procurement Subject Matter Expert](https://feeny.ai/job/senior-procurement-subject-matter-expert-agiloft-united-states-ks2khwd9m51f) — United States - [Staff Software Engineer - Platform and Cloud Services](https://feeny.ai/job/staff-software-engineer-platform-and-cloud-services-agiloft-canada-4n5mbzgzkr6q) — Canada - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-agiloft-united-states-yrsw7yge4tfn) — United States