Manager, Government Compliance & Authorization
Company Description At Amwell, we’re transforming healthcare for all—powered by technology and inspired by people. Here, your ideas don’t just matter—they drive real change, improving lives on a global scale. We marry technology and innovation with clinical excellence to provide trusted solutions that solve the healthcare industry’s biggest pain points and are on a mission to enable greater access to more convenient, affordable, and effective care. We do this through our technology-enabled care platform that is designed to help our clients achieve their digital care ambitions – today and in the future. We offer programs spanning the full care continuum, including urgent, acute and specialty care, behavioral health, and services for the treatment of chronic conditions such as heart and cardiometabolic diseases. Programs are powered by Amwell as well as our growing partner network. For almost two decades, Amwell has proudly served some of the largest and most sophisticated healthcare organizations in the U.S. and worldwide. Our team is passionate about technology’s role in transforming care delivery and making it more equitable, accessible, efficient, cost-effective and navigable for all.Brief Overview The Manager of Government Compliance & Authorization will lead the strategy, implementation, and maintenance of Amwell’s federal and state authorization programs. While a primary focus remains achieving and sustaining FedRAMP High authorization, this leader will also architect the internal systems necessary to align with CMMC (Level 2/3), CMS MARS-E, and StateRAMP requirements. The Manager will mature Amwell’s government compliance program, oversee the authorization process, lead efforts to define resources and hire staff to support the program, manage continuous monitoring activities, and serve as the primary liaison with federal stakeholders and third-party assessment organizations (3PAOs). The ideal candidate will have deep expertise in FedRAMP High requirements, strong project management skills, and the ability to work cross-functionally to implement and maintain complex compliance frameworks. Core Responsibilities · Lead the end-to-end authorization process for FedRAMP High, while concurrently driving alignment with CMMC Level 2/3 for DoD contracts and MARS-E 2.2 for CMS/Medicaid engagements · Manage ongoing FedRAMP continuous monitoring requirements, including monthly deliverables, vulnerability management, and incident reporting to federal agencies · Collaborate with engineering, security, and operations teams to develop a "comply once, satisfy many" strategy by mapping NIST SP 800-53 Rev 5 controls to CMMC (NIST SP 800-171) and MARS-E requirements to minimize redundant engineering efforts · Own risk management of services provided to federal agencies, ensuring compliance with High-impact baseline · Coordinate with 3PAOs to manage security assessment and authorization (SA&A) activities, including annual assessments and s...