Demo

Security Compliance & Assurance Manager

Port.io
Boston, MA Full Time
POSTED ON 12/24/2025 CLOSED ON 1/5/2026

What are the responsibilities and job description for the Security Compliance & Assurance Manager position at Port.io?

At Port, we are pioneering a new dimension of the Developer Experience. Our innovative platform for Internal Developer Portals has been designed with the ultimate aim of enhancing developer satisfaction, increasing productivity, and ensuring the highest standards of engineering output.

Port brings everything a developer needs together, encapsulated within a single user-friendly interface. From comprehending the software development lifecycle, executing tasks, to adhering to the organization's development standards, Port ensures that every aspect of software development is within easy reach for every developer.

As a team, we personify the values that underpin our product: openness, transparency, resourcefulness, community orientation, and kindness. We are on the lookout for like-minded individuals who share our ethos to join us on our exciting journey of revolutionizing the platform engineering sector. By joining Port, you'll be a part of a team that's changing how developers collaborate, enabling them to work faster, smarter, and more efficiently. Join us, and be a part of this transformation.

Why we're looking for you 😎

We're seeking a Security Compliance & Assurance Manager to own the hands-on documentation, policy writing, and evidence management across Port's security and compliance programs. This is a technical writing and audit readiness role supporting our FedRAMP authorization and broader GRC initiatives.

As Port grows and pursues FedRAMP authorization, we need someone who can translate complex technical controls into clear, comprehensive documentation. You'll be the expert who writes the SSP, maintains policies, collects evidence, and ensures our compliance programs are audit-ready - working closely with our GRC team and supporting both FedRAMP and ongoing compliance frameworks (SOC 2, ISO 27001, GDPR).

Who You'll Work With πŸ‘―β€β™€οΈ

You'll report to the CIO and work closely with the GRC Manager and FedRAMP Program Manager as part of the Security & Risk team. You'll collaborate cross-functionally with Engineering, DevOps, IT, and Product teams to document technical controls and collect evidence.

You'll also partner with Legal, HR, and external auditors (3PAOs, SOC 2 auditors) to ensure Port maintains and demonstrates the highest levels of security and compliance.

What You'll Do πŸ’Ό

  • Write, maintain, and update the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and all compliance documentation for FedRAMP authorization.
  • Develop and maintain security policies and procedures including access control, incident response, data classification, encryption, and acceptable use policies.
  • Lead evidence collection and audit readiness activities across multiple frameworks (FedRAMP, SOC 2, ISO 27001, GDPR).
  • Partner with Engineering, IT, and the GRC Manager to document technical control implementations and translate controls into clear policy language.
  • Support continuous monitoring activities, control testing, and remediation tracking.
  • Manage customer security questionnaires, RFPs, and Trust Center content to support sales and customer assurance efforts.
  • Maintain compliance tooling and dashboards (e.g., Drata, Tugboat Logic) for continuous visibility into control status.
  • Support internal and external audits with timely, complete evidence packages and coordinate with 3PAOs and auditors.
  • Build and maintain the compliance evidence repository and artifact management system.
  • Over time, evolve into a core GRC & Assurance leader supporting enterprise certifications and customer trust programs.

Requirements:

What We're Looking For πŸ“

  • 5 years in security compliance, audit, or assurance roles in SaaS or cloud environments.
  • Deep expertise in compliance frameworks (FedRAMP, SOC 2, ISO 27001) and control requirements.
  • Excellent technical writing and documentation skills - ability to translate complex technical controls into clear, comprehensive policies and procedures.
  • Hands-on experience building and maintaining compliance evidence repositories and control testing programs.
  • Strong understanding of technical security controls (encryption, access management, logging, monitoring, network security).
  • Experience supporting audits and working with external assessors (3PAOs, SOC 2 auditors, ISO auditors).
  • Strong organizational skills and attention to detail with ability to manage multiple compliance workstreams simultaneously.
  • Collaborative communication style - able to work effectively with technical and non-technical stakeholders.

Nice to have 🌟

  • Direct FedRAMP authorization experience (SSP development, POA&M management, continuous monitoring).
  • Experience with customer-facing security programs (Trust Center management, security questionnaires, vendor security assessments).
  • Hands-on experience with GRC automation platforms (Drata, Tugboat Logic, Vanta, OneTrust, Secureframe).
  • Background in technical security controls, risk management, or security engineering.
  • CISSP, CISA, CISM, or other security/compliance certifications.
  • Familiarity with GDPR, CCPA, or other privacy frameworks and regulations.
  • Experience in high-growth SaaS or cloud infrastructure companies.
  • Technical background or ability to read/understand code and infrastructure configurations.

Salary.com Estimation for Security Compliance & Assurance Manager in Boston, MA
$152,328 to $189,497
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Compliance & Assurance Manager?

Sign up to receive alerts about other jobs on the Security Compliance & Assurance Manager career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$123,739 - $165,355
Income Estimation: 
$163,270 - $214,905
Income Estimation: 
$150,417 - $183,047
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$187,890 - $240,773
Income Estimation: 
$208,393 - $280,632
Income Estimation: 
$217,249 - $295,152
Income Estimation: 
$155,218 - $198,966
Income Estimation: 
$188,900 - $249,994
Income Estimation: 
$187,890 - $240,773
Income Estimation: 
$136,714 - $171,621
Income Estimation: 
$151,231 - $194,242
Income Estimation: 
$155,218 - $198,966
Income Estimation: 
$153,752 - $200,235
This job has expired.
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Port.io

  • Port.io Boston, MA
  • About Port At Port.io, we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M S... more
  • 3 Days Ago

  • Port.io Austin, TX
  • About Port At Port.io , we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M ... more
  • 3 Days Ago

  • Port.io Austin, TX
  • About Port At Port.io , we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M ... more
  • 3 Days Ago

  • Port.io Austin, TX
  • About Port At Port.io, we are building an open and flexible Agentic Engineering Platform for modern engineering organizations. Following our recent $100M S... more
  • 3 Days Ago


Not the job you're looking for? Here are some other Security Compliance & Assurance Manager jobs in the Boston, MA area that may be a better fit.

  • JMD Technologies Inc. Boston, MA
  • About the job Title: Quality Assurance Manager – GDP Compliance Location: Boston, MA (Hybrid – 2–3 Days Onsite) Employment Type: Contract (12 Months) Statu... more
  • 2 Days Ago

  • Alnylam Pharmaceuticals Cambridge, MA
  • Overview This candidate will be responsible for managing and providing quality and compliance oversight for implementing, validating and maintaining digita... more
  • 2 Months Ago

AI Assistant is available now!

Feel free to start your new journey!