← Back to results

Director, Public Sector Compliance

Lead compliance efforts to transition Blitzy from FedRAMP Moderate to High, unlocking public sector opportunities.

Location
Cambridge, MA, United States
Compensation
$215k–$230k/yr
Level
director
Type
full time · On-site

Posted by employer 1 day ago

First seen on Joblaze 19 hours ago

Last verified on the company career page 19 hours ago

Apply at Blitzy → Save job Scanned from blitzy.com

What you'll build

  • Own the roadmap and execution from FedRAMP Moderate to High
  • Partner with GTM on public sector opportunities
  • Replace point-in-time compliance with automated evidence
  • Identify internal compliance primitives with external value
  • Manage 3PAO and government security stakeholders

Must have

  • 8+ years in security, compliance, or GRC leadership
  • Hands-on experience taking a cloud system through FedRAMP authorization
  • Deep working fluency in NIST 800-53
  • Track record of managing 3PAOs and government security reviewers
  • Demonstrated impact on revenue

Nice to have

  • Existing relationships across the defense industrial base
  • Technical depth in cloud architecture
  • Excellent written communication

Requirements

Experience
8+ years

Not disclosed in this posting: visa sponsorship.

Benefits

Equity/Stock Options

Joblaze summary

The Director of Public Sector Compliance at Blitzy is responsible for advancing the company's compliance framework from FedRAMP Moderate to High, ensuring that the platform meets the stringent requirements of federal agencies. This role demands expertise in security and compliance, particularly with NIST 800-53 and FedRAMP standards, alongside a proven track record in managing federal authorization processes. Ideal candidates will have significant experience in GRC leadership and a technical background that facilitates collaboration with engineering teams. The position offers direct engagement with company founders and a focus on transforming compliance into a revenue-generating function.

Joblaze insights

  • Listed today — first seen on Joblaze September 23, 2026. Last confirmed on Blitzy's careers page September 23, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).

Quick facts

Is the Director, Public Sector Compliance role remote?
No — this is an on-site role in Cambridge, MA, United States.
What's the salary range?
Blitzy lists $215,000–$230,000 for this role.
How much experience is required?
At least 8 years of relevant experience for this Director, Public Sector Compliance role.
Where is the role based?
Blitzy is hiring for this position in Cambridge, MA, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: CMMC, DoD SRG, FedRAMP, NIST 800-53.
What seniority level is this role?
Blitzy targets director candidates for this position.
Is this full-time or contract?
Full-time for this Director, Public Sector Compliance role at Blitzy.

From the original posting

Our Culture

How we work:

  • We move Blitzy Fast: Time is both our company’s and our clients’ most precious asset. We move quickly and decisively to innovate internally and deliver exceptional software externally.

About the Role

Compliance is the single biggest blocker between Blitzy and the public sector market - and, handled correctly, one of our biggest product opportunities. Federal agencies, the defense industrial base, and the integrators who serve them want what our enterprise customers already have: an agentic platform that turns requirements into production-ready code. Getting there is an accreditation problem, and we’re hiring the leader who will own it.

The near-term mandate is clear. Drive Blitzy from FedRAMP Moderate to FedRAMP High as quickly as we can defensibly get there, because High is the baseline for DoD SRG IL2, IL4, and IL5. National security mission and business systems at the unclassified level — Advana among them — require IL5, and we intend to operate there.

The longer-term mandate is more interesting. Static authorization packages and POA&M bookkeeping are giving way to proactive, continuous security. You’ll build our posture that way from the start, and then help productize the internal primitives you create as part of the broader Blitzy Proactive Insights portfolio, aligned to the cyber security needs of the DIB.

This is a compliance title attached to a revenue mandate. Every control you land unblocks, closes, or expands a deal. You’ll work in person in Cambridge, MA with direct access to the founders and the engineers building the platform.

Responsibilities

  • Own the roadmap and execution from FedRAMP Moderate to High, then to DoD SRG IL4/IL5 — boundary definition, control implementation strategy, SSP quality, and the assessment calendar.

  • Partner with GTM on every public sector opportunity: security reviews, agency and prime questionnaires, ATO strategy, and the compliance narrative that turns a blocked deal into a landed and expanded one.

  • Replace point-in-time compliance with automated evidence, control monitoring, and drift detection so authorization is a byproduct of how we operate, not a project we run.

  • Identify which internal compliance and security primitives have external value, and work with product and engineering to bring them to market for the defense industrial base.

  • Manage 3PAO, sponsoring agency, FedRAMP PMO, and DISA engagement — and represent Blitzy credibly with government security stakeholders.

  • Own the unglamorous foundations — configuration baselines, vulnerability management, access control, incident response, supply chain — and make build-versus-buy calls that keep cost and dependency in check.

  • Give engineering clear, automatable requirements instead of compliance homework, and give GTM answers they can use on their own.

 

Qualifications

  • 8+ years in security, compliance, or GRC leadership, including ownership of a federal authorization program end to end.

  • Hands-on experience taking a cloud system through FedRAMP authorization, and direct familiarity with what FedRAMP High and DoD SRG IL4/IL5 actually require beyond Moderate.

  • Deep working fluency in NIST 800-53, the FedRAMP baselines, the DoD Cloud Computing SRG, and adjacent regimes such as CMMC.

  • Track record of managing 3PAOs, sponsoring agencies, and government security reviewers — and of getting decisions out of them.

  • Demonstrated impact on revenue: you’ve personally unblocked, accelerated, or expanded deals where security and compliance were the obstacle.

  • Technical depth sufficient to earn engineering’s respect — cloud architecture, infrastructure as code, CI/CD, and evidence automation are conversations you can hold your own in.

  • Excellent written communication. Control narratives, agency responses, and customer-facing security documentation are all writing problems.

  • Existing relationships and credibility across the defense industrial base, primes, or DoD program offices.

Salary Range: $215,000-$230,000 Bonus + Equity

Blitzy is an equal opportunity employer committed to building a diverse and inclusive team. We believe different perspectives make us stronger. Base salary ranges are determined by country, role, level, experience, and skills. The range displayed on each job posting reflects Blitzy’s good faith determination of the minimum and maximum targets for new hire salaries across all ocations. Individual pay is determined by related factors, including job skills, experience, and relevant education or training, which may impact a final offer. Your Talent Partner can share more about the specific salary range during the hiring process.

Standard company text repeated across Blitzy's postings is omitted here.

Similar positions

Blitzy
Strategy & Operations, Healthcare
Blitzy · Cambridge, MA
Blitzy
Blitzy
Senior Member of Technical Staff
Blitzy · Cambridge, MA
Blitzy
Principal Software Engineer
Blitzy · Cambridge, MA