Security Authorization Lead

govsignals· Operations
Apply Now ↗
📍 New York📍 Washington, D.C.FullTime💰 USD 140K–190K

About this role

GovSignals is next-gen acquisition for the Department of War.

 

It can take the government longer to buy a capability than an adversary takes to field one, and we exist to close that gap.

 

We're the only startup managing government contract data with AI in both FedRAMP High and DoW Impact Level 5 environments. Our platform monitors 5,000+ live government data sources, 100,000+ federal and state agencies, and 2,000,000+ government contracts in real time. Our customers in government include offices like DIU and SOCOM, and our customers in industry range from small contractors to Fortune 500 primes with billions in annual awards.

Security Authorization Lead

Washington, DC or New York, NY • Full-time • Hybrid (3+ days/week in office)

ABOUT THE ROLE

We're hiring a Security Authorization Lead to get GovSignals deployments through government security approval and keep them approved. You'll work under the CISO with support from the CTO, and you'll be the first person here dedicated to this work full time.

Our customers cannot use GovSignals until their own security office says yes. Every deployment brings a different boundary, a different set of reviewers, and a different list of questions about how their data is handled. You'll plan that path with the customer before work starts, write documentation that survives a line-by-line read, answer reviewers directly, carry findings to closure, and keep the evidence current afterward so the next deployment starts ahead of where the last one did.

GovSignals operates at FedRAMP High and DoW IL5 today. Some deployments will require IL6. The work also covers CMMC Level 2, SOC 2, and whatever a specific customer asks for.

WHAT YOU'LL DO

  • Plan the authorization path for each customer deployment: scope the boundary, work out which controls we inherit and which we answer for, and agree the steps with the customer's security office before work starts.

  • Write and maintain what approval depends on: system security plans, control narratives, architecture diagrams, and the supporting artifacts reviewers ask for.

  • Prepare for assessments and reviews, answer reviewer questions directly, and track findings and POA&M items until they close.

  • Keep approvals in force once granted: continuous monitoring reporting, significant change requests, annual assessments, and the vulnerability and patch evidence behind them.

  • Own customer security questionnaires and security reviews, and keep a response library so each one starts from the last.

  • Work with engineering when a requirement has a technical consequence: say what the control means in the product, then follow it to done.

We deploy through Defense Unicorns, SecondFront GameWarden, and Palantir FedStart.

WHAT YOU BRING

  • You've personally taken a system through a DoW authorization and stayed with it through its ongoing obligations. What you did matters more than what your title was.

  • Direct experience with government security reviewers, assessors, or an authorizing official's staff. You've been the one answering the questions.

  • Working knowledge of NIST 800-53, RMF, and the DoW Cloud Computing SRG, including how control inheritance works when you run on an authorized platform.

  • Writing that holds up under close reading. A vague answer in a package or a questionnaire can hold a deployment for weeks.

  • Enough cloud fluency to read an architecture diagram, a Kubernetes manifest, or a CI configuration and ask the right question. You don't have to implement the control yourself.

Nice to have: CMMC Level 2 or SOC 2 experience; time inside a government program office, a 3PAO, or an assessment organization; a deployment you had to get approved more than once, in more than one place; familiarity with AWS GovCloud and Kubernetes.

Clearance: not required. An active or previous clearance is a plus.

THE TEAM

GovSignals was founded by four cofounders who lived with this problem from both sides (selling to the government and serving inside it) with backgrounds across the Defense Intelligence Agency, the Department of Energy, Palantir, Amazon, federal contractors building for missiles, and state contractors building for prisons. You'll work directly with all four. Other team members at GovSignals have shipped to defense companies, scaled venture-backed startups, and founded companies of their own.

HOW WE WORK

Design by HI (Human Intelligence), Work by AI (Artificial Intelligence). Human Intelligence takes responsibility for what we build and how we communicate to customers. Artificial Intelligence does much of the building. We provide unlimited Claude and ChatGPT credits for reasonable use, and we expect you to come in with extensive AI experience.

HOW WE HIRE

  • Intro conversation (30 min): your background and how you work.

  • Working session (1 hr): real-world inspired security exercises.

  • Co-founder conversations (15 min): meet the cofounders.

  • Meet the team in person (45 min): time with the team at our Washington, DC or Brooklyn, NY office.

  • Offer.

COMPENSATION & BENEFITS

  • Base Salary: $140,000 – $190,000

  • Equity: Meaningful stake in a well-funded, fast-growing startup

  • Benefits: medical, vision, and dental, unlimited PTO

  • Hybrid in our Washington, DC or Brooklyn Navy Yard offices, 3+ days a week in person. The Yard built ships for the Navy from 1801 to 1966, now we build systems for Navy program offices.

Due to the nature of our government work, this role is open only to U.S. citizens and other U.S. Persons. GovSignals is an equal opportunity employer

Frequently Asked Questions

What is the salary for the Security Authorization Lead role at govsignals?
The listed salary for this Security Authorization Lead position at govsignals is USD 140K–190K. This is an FullTime role.
Where is the Security Authorization Lead position at govsignals located?
This Security Authorization Lead role at govsignals is based in New York, Washington, D.C.. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Security Authorization Lead role at govsignals full-time or part-time?
This is listed as a FullTime position. It is posted as a Security Authorization Lead role in the Operations department at govsignals.
Which team or department does the Security Authorization Lead at govsignals belong to?
This Security Authorization Lead position is part of the Operations department at govsignals. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Security Authorization Lead position at govsignals?
Click the "Apply Now" button on this page. You will be redirected to govsignals's official application portal hosted on ashby where you can submit your application directly.
When was the Security Authorization Lead job at govsignals posted?
This Security Authorization Lead position at govsignals was posted on Jul 24, 2026. Apply as soon as possible — early applications are often reviewed first.
Security Authorization Lead
govsignals · 💰 USD 140K–190K
Apply for this role ↗

You'll be redirected to govsignals's official application page on Ashby ATS.