You are the program manager for AegisCloud, a B2B SaaS provider of secure collaboration and document workflows used by regulated industries. AegisCloud has ~4.5M monthly active users globally and processes ~1.2B events/day (document views, edits, shares, permission changes). The company is pursuing a major expansion into US public sector and defense-adjacent customers.
AegisCloud has signed a conditional agreement with a prime contractor supporting a DoD program. The contract is contingent on delivering FedRAMP Moderate-aligned audit logging and immutable retention for key security events by the end of Q2 (16 weeks). Missing the date means the prime will select a competitor and AegisCloud will lose an estimated $18M ARR plus a strategic reference account.
The feature is not “just logging.” The customer requires: (1) tamper-evident audit trails, (2) role-based access to audit data, (3) retention policies (1 year default, configurable up to 7 years), (4) export to their SIEM (Splunk) in near real time, and (5) evidence artifacts suitable for an external assessor. The work touches core services that are shared with commercial customers, so any regression risks broad impact.
You will lead a cross-functional team:
| Function | Count | Notes |
|---|---|---|
| Backend engineers | 6 | Own event pipeline, storage, APIs |
| SRE/Infra | 2 | Own Kubernetes, logging infra, on-call |
| Security engineering | 2 | Own control mapping, threat modeling |
| Product/Program | 1 PM + you | PM owns requirements; you drive execution |
| Design | 1 | Admin UX for audit search/export |
| Legal/Compliance | 1 | FedRAMP artifacts, data residency, contracts |
| QA | 1 | Automation + performance test plans |
Walk through how your past projects have prepared you to execute in a government/defense environment by answering through this scenario:
Be prepared to discuss concrete artifacts you would create (e.g., RAID log, control mapping doc, RACI, cutover runbook), and how you would operate differently than in a purely commercial launch.
You are the program manager for AegisCloud, a B2B SaaS provider of secure collaboration and document workflows used by regulated industries. AegisCloud has ~4.5M monthly active users globally and processes ~1.2B events/day (document views, edits, shares, permission changes). The company is pursuing a major expansion into US public sector and defense-adjacent customers.
AegisCloud has signed a conditional agreement with a prime contractor supporting a DoD program. The contract is contingent on delivering FedRAMP Moderate-aligned audit logging and immutable retention for key security events by the end of Q2 (16 weeks). Missing the date means the prime will select a competitor and AegisCloud will lose an estimated $18M ARR plus a strategic reference account.
The feature is not “just logging.” The customer requires: (1) tamper-evident audit trails, (2) role-based access to audit data, (3) retention policies (1 year default, configurable up to 7 years), (4) export to their SIEM (Splunk) in near real time, and (5) evidence artifacts suitable for an external assessor. The work touches core services that are shared with commercial customers, so any regression risks broad impact.
You will lead a cross-functional team:
| Function | Count | Notes |
|---|---|---|
| Backend engineers | 6 | Own event pipeline, storage, APIs |
| SRE/Infra | 2 | Own Kubernetes, logging infra, on-call |
| Security engineering | 2 | Own control mapping, threat modeling |
| Product/Program | 1 PM + you | PM owns requirements; you drive execution |
| Design | 1 | Admin UX for audit search/export |
| Legal/Compliance | 1 | FedRAMP artifacts, data residency, contracts |
| QA | 1 | Automation + performance test plans |
Walk through how your past projects have prepared you to execute in a government/defense environment by answering through this scenario:
Be prepared to discuss concrete artifacts you would create (e.g., RAID log, control mapping doc, RACI, cutover runbook), and how you would operate differently than in a purely commercial launch.