Principal Technical Program Manager
AI summary of the role
Principal-level technical program manager to build and lead Oracle Health's Product Authorization Team, owning FedRAMP authorization strategy, readiness, and continuous assurance for cloud offerings.
What you’ll do
- Stand up and lead the Oracle Health Product Authorization FedRAMP team, defining charter, service model, governance, and metrics.
- Own multi-year FedRAMP authorization and certification roadmap for assigned cloud offerings, including scope, sequencing, and transition to continuous assurance.
- Establish scalable assessment operating model covering readiness reviews, evidence planning, 3PAO engagement, testing, and remediation validation.
- Partner with architecture and security engineering to evaluate service boundaries, data flows, multi-tenancy, identity, encryption, and control inheritance.
What you’ll bring
- Bachelor's degree in CS, Engineering, Info Systems, Cybersecurity, or equivalent practical experience.
- 7+ years in technical program management, security program leadership, cloud delivery, compliance engineering, or related field.
- Demonstrated end-to-end FedRAMP certification or authorization leadership, or comparable regulated cloud-assurance program.
- Deep knowledge of FedRAMP processes, NIST SP 800-53 Rev. 5, FIPS 199, and federal risk management.
Technologies
FedRAMP · NIST SP 800-53 · FIPS 199 · OSCAL · Kubernetes · OCI · AWS · Azure · CI/CD · infrastructure as code
About Oracle
Oracle sells database software, enterprise applications (ERP/HCM/CX), and Oracle Cloud Infrastructure to large enterprises and governments.
Public · 5000+ people
Source and classification
Internal deployment & tooling · Evidence for this classification:
Oracle Health is seeking a Principal Technical Program Manager to establish and lead the Product Authorization Team responsible for FedRAMP assessment readiness, authorization strategy, and continuous security assurance for cloud service offerings. This role combines principal-level technical program leadership with deep cloud security and compliance-engineering expertise. You will create the operating model that turns federal security requirements into sustainable engineering practices, trusted evidence, measurable security outcomes, and clear executive decisions. You will work at the intersection of cloud architecture, security engineering, product delivery, and federal authorization. Success requires the ability to move comfortably between architecture and control discussions, third-party assessment strategy, remediation execution, and senior-leadership tradeoffs. This is a
More from the job description
Oracle Health is seeking a Principal Technical Program Manager to establish and lead the Product Authorization Team responsible for FedRAMP assessment readiness, authorization strategy, and continuous security assurance for cloud service offerings. This role combines principal-level technical program leadership with deep cloud security and compliance-engineering expertise. You will create the operating model that turns federal security requirements into sustainable engineering practices, trusted evidence, measurable security outcomes, and clear executive decisions. You will work at the intersection of cloud architecture, security engineering, product delivery, and federal authorization. Success requires the ability to move comfortably between architecture and control discussions, third-party assessment strategy, remediation execution, and senior-leadership tradeoffs. This is a hands-on leadership role. You will not serve as the independent assessor; however, you must have sufficient security-engineering depth to challenge design assumptions, assess evidence quality, identify material gaps, and drive practical remediation with technical teams. Responsibilities Stand up the Oracle Health Product Authorization FedRamp Team and define its charter, service model, roles, intake and prioritization process, governance cadences, quality standards, metrics, and escalation paths. Own [... source excerpt omitted ...] g teams to evaluate service boundaries, data flows, interconnections, multi-tenancy, identity, encryption, logging, resilience, supply-chain dependencies, control inheritance, and customer-responsible controls. Translate FedRAMP, NIST, and federal risk-management requirements into owned, testable, time-bound engineering and operational deliverables; set acceptance criteria for evidence, security decisions, and remediation plans. Design reusable evidence and assurance patterns using security telemetry, infrastructure as code, CI/CD controls, configuration validation, GRC workflows, machine-readable data, and automation where appropriate. Lead strategic engagement with 3PAOs, Fe [... source excerpt omitted ...] rtners, publish playbooks and reusable patterns, and raise the organization's capacity to deliver federal authorizations consistently without weakening security outcomes. Minimum Qualifications Bachelor's degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related discipline, or equivalent practical experience. Seven or more years of experience in technical program management, security program leadership, cloud delivery, compliance engineering, security engineering, or a related technology field, including responsibility for complex cross-organizational programs. Demonstrated experience leading an end-to-end FedRAMP certification or authorization, fede
Employer postings · Data from · Sources