{"schemaVersion":"jobsearcher.job.v1","id":"1b86ab984d6f14a66e6d9dc3","url":"https://jobsearcher.com/jobs/1b86ab984d6f14a66e6d9dc3","canonicalUrl":"https://jobsearcher.com/jobs/1b86ab984d6f14a66e6d9dc3","title":"Security Program Manager","description":"About Massed Compute\n\nMassed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. Customers choose us when they need high-performance infrastructure with more flexibility, visibility, and support than they get from traditional options. Our work sits at the intersection of AI infrastructure, product design, systems thinking, and customer obsession.\n\nDescription\n\nMassed Compute is looking for someone for a Security Program Manager role. This job involves owning the security program day-to-day, pursuing and obtaining ISO 27001 certification and leading FedRAMP readiness efforts.\n\nThis is a hands-on GRC seat. You run the queue: controls, evidence, auditors, vendors, questionnaires, and abuse. Engineering still patches systems. You make sure the evidence is real and the auditor has a named owner.\n\nWe will train you on the tools (Vanta), vendor reviews, and SOC 2 audits. You need good judgment, follow-through, and clear writing.\n\nWhat you will do\n\nOwn GRC Tool (Vanta): failing controls, evidence, and following up with the people who actually fix things\n\nBe the primary contact for our SOC 2 auditor and the ISO 27001 certification body\n\nMaintain SOC 2 Type II compliance through audits (PBC lists, walkthroughs, findings response)\n\nRun vendor security reviews on a weekly cadence\n\nAnswer customer security questionnaires; stand up and maintain a current Trust Center\n\nOwn abuse / acceptable-use intake and enforcement process\n\nOwn spam reporting and email blocking\n\nKeep HIPAA, GDPR, and EU AI Act documents accurate\n\nFinish our ISO 27001 ISMS package: procedures, Statement of Applicability, internal audit, management review\n\nBuild a FedRAMP readiness folder (inventory, authorization boundary, control map from SOC 2/ISO to NIST 800-53). We start a 3PAO only if a named federal deal requires it\n\nUse AI to draft, research, and speed up routine GRC work; verify accuracy before any output is treated as auditable proof\n\nOwn employee security onboarding and offboarding (accounts and access, Vanta tasks, MDM, background-check evidence, timely leaver cutoff)\n\nWhat you need\n\nYou write clearly. This job is evidence, auditor email, and customer questionnaires\n\nYou can own a queue: pick up work, follow up professionally, close the loop, and see items through to completion\n\nYou work AI-first: you use automation to move faster, and you personally review the output before it becomes audit evidence or customer-facing material\n\nYou are willing to be the named contact for auditors and customers once trained\n\nBackground in security, compliance, IT, operations, or similar process work helps. Direct SOC 2 / Vanta / vendor-review experience is not required.\n\nNice to have\n\nSOC 2, ISO 27001, HIPAA, or GDPR exposure in any role\n\nVanta, Drata, Secureframe, Sprinto, or another GRC tool\n\nVendor security reviews or customer security questionnaires\n\nPolicies or procedures you wrote that someone else actually used\n\nNIST 800-53 or FedRAMP as a contributor\n\nCloud, IaaS, GPU cloud, or colocation familiarity\n\nTrust-and-safety, AUP, or abuse handling\n\nWork Authorization\n\nApplicants must be legally authorized to work in the United States and obtain security clearance. We are unable to sponsor work visas for this position.\n\nWhy join us?\n\nWe are a lean, ambitious team operating in one of the most important technology markets in the world. If you want ownership, pace, and the opportunity to do career-defining work alongside practical, high-agency teammates, MassedCompute is a great place to build.\n\nBenefits\n\nMarket competitive compensation\n\nWe are a remote-first company. You’ll get a stipend to dial in your setup and additional opportunities to connect with your peers during periodic in person team gatherings\n\nFlexible PTO policy with the expectation that you take the time you need to recharge\n\n100% coverage of medical, dental, and vision insurance for employees, 30% of premiums for dependents, plus a tax-advantaged Flexible Spending Account\n\nCompany-facilitated 401(k) retirement plan\n\nParental leave for all new parents\n\nEqual Opportunity\n\nMassed Compute is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by law.","company":"Massed Compute","rawCompany":"massed compute","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-04T09:59:25.299Z","occupations":[{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Program Manager","description":"About Massed Compute\n\nMassed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. Customers choose us when they need high-performance infrastructure with more flexibility, visibility, and support than they get from traditional options. Our work sits at the intersection of AI infrastructure, product design, systems thinking, and customer obsession.\n\nDescription\n\nMassed Compute is looking for someone for a Security Program Manager role. This job involves owning the security program day-to-day, pursuing and obtaining ISO 27001 certification and leading FedRAMP readiness efforts.\n\nThis is a hands-on GRC seat. You run the queue: controls, evidence, auditors, vendors, questionnaires, and abuse. Engineering still patches systems. You make sure the evidence is real and the auditor has a named owner.\n\nWe will train you on the tools (Vanta), vendor reviews, and SOC 2 audits. You need good judgment, follow-through, and clear writing.\n\nWhat you will do\n\nOwn GRC Tool (Vanta): failing controls, evidence, and following up with the people who actually fix things\n\nBe the primary contact for our SOC 2 auditor and the ISO 27001 certification body\n\nMaintain SOC 2 Type II compliance through audits (PBC lists, walkthroughs, findings response)\n\nRun vendor security reviews on a weekly cadence\n\nAnswer customer security questionnaires; stand up and maintain a current Trust Center\n\nOwn abuse / acceptable-use intake and enforcement process\n\nOwn spam reporting and email blocking\n\nKeep HIPAA, GDPR, and EU AI Act documents accurate\n\nFinish our ISO 27001 ISMS package: procedures, Statement of Applicability, internal audit, management review\n\nBuild a FedRAMP readiness folder (inventory, authorization boundary, control map from SOC 2/ISO to NIST 800-53). We start a 3PAO only if a named federal deal requires it\n\nUse AI to draft, research, and speed up routine GRC work; verify accuracy before any output is treated as auditable proof\n\nOwn employee security onboarding and offboarding (accounts and access, Vanta tasks, MDM, background-check evidence, timely leaver cutoff)\n\nWhat you need\n\nYou write clearly. This job is evidence, auditor email, and customer questionnaires\n\nYou can own a queue: pick up work, follow up professionally, close the loop, and see items through to completion\n\nYou work AI-first: you use automation to move faster, and you personally review the output before it becomes audit evidence or customer-facing material\n\nYou are willing to be the named contact for auditors and customers once trained\n\nBackground in security, compliance, IT, operations, or similar process work helps. Direct SOC 2 / Vanta / vendor-review experience is not required.\n\nNice to have\n\nSOC 2, ISO 27001, HIPAA, or GDPR exposure in any role\n\nVanta, Drata, Secureframe, Sprinto, or another GRC tool\n\nVendor security reviews or customer security questionnaires\n\nPolicies or procedures you wrote that someone else actually used\n\nNIST 800-53 or FedRAMP as a contributor\n\nCloud, IaaS, GPU cloud, or colocation familiarity\n\nTrust-and-safety, AUP, or abuse handling\n\nWork Authorization\n\nApplicants must be legally authorized to work in the United States and obtain security clearance. We are unable to sponsor work visas for this position.\n\nWhy join us?\n\nWe are a lean, ambitious team operating in one of the most important technology markets in the world. If you want ownership, pace, and the opportunity to do career-defining work alongside practical, high-agency teammates, MassedCompute is a great place to build.\n\nBenefits\n\nMarket competitive compensation\n\nWe are a remote-first company. You’ll get a stipend to dial in your setup and additional opportunities to connect with your peers during periodic in person team gatherings\n\nFlexible PTO policy with the expectation that you take the time you need to recharge\n\n100% coverage of medical, dental, and vision insurance for employees, 30% of premiums for dependents, plus a tax-advantaged Flexible Spending Account\n\nCompany-facilitated 401(k) retirement plan\n\nParental leave for all new parents\n\nEqual Opportunity\n\nMassed Compute is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by law.","datePosted":"2026-09-04T09:59:25.299Z","dateModified":"2026-09-04T09:59:25.299Z","hiringOrganization":{"@type":"Organization","name":"Massed Compute","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"1b86ab984d6f14a66e6d9dc3"},"url":"https://jobsearcher.com/jobs/1b86ab984d6f14a66e6d9dc3"}}