Ceribell, Inc · Sunnyvale, CA

Salary
$144,000–$195,000
Posted
Jul 12, 2026
Location
Sunnyvale, CA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior cybersecurity program management role focused on coordinating FedRAMP audits, continuous monitoring, and NIST 800-53 control maturity across an organization. Day-to-day work spans GRC collaboration, POA&M tracking, risk assessments, vulnerability management, and driving complex cross-functional security projects. Suited to an experienced professional with a background spanning cybersecurity compliance programs and IT program management.

Senior level · 10+ years · Remote

Must have (8)
FedRAMPNIST 800-53NIST 800-30NIST 800-161POA&M trackingHIPAASOX ITGCJira or Notion
Nice to have (5)
CISA, CISSP or PmpSplunkTenableTrend MicroAWS

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,900 people nationally plausibly meet what this posting asks for (information security analysts). range 400–2,900

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
NIST 800-5340%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

This role sits at the intersection of cybersecurity program management and GRC leadership, making it a genuine hybrid between 15-1212 (Information Security Analysts) and 11-3021 (Computer and Information Systems Managers). The day-to-day work leans toward hands-on security/compliance execution (FedRAMP audits, NIST controls, continuous monitoring) rather than pure people/budget management, so 15-1212 is the primary classification.

U.S. citizenship is explicitly required due to federal compliance obligations, but no specific security clearance is stated as a gate — only identity verification prior to start.

POA&M tracking is listed as a required responsibility in the core job description and is treated as a hard gate given the FedRAMP audit leadership context.

SOC 2 Type 2, HIPAA, and SOX ITGC appear in the requirements section as examples of compliance programs the candidate must have experience overseeing ('e.g.' qualifier means the specific frameworks are interchangeable, but the requirement for multi-framework compliance experience is a hard gate).

Jira is listed in the requirements section as a project management tool ('such as Jira or Notion'); Notion is captured as an alternative. Splunk, Tenable, and Trend Micro appear only under the Preferred section.

CISA, CISSP, and PMP certifications are listed under Preferred and are treated as interchangeable preferred credentials.

AWS and cloud architecture knowledge appear only under Preferred.

No compensation range is provided in the posting.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): SOC 2 Type 2.

This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗