- Workplace
- Onsite
- Education
- Master
- Clearance
- Required
- Source
- ApplicantStack
Description
Position Description
Program Manager — Cybersecurity Services (ISSO Support)
Excentium, Inc.
|
Position Title |
Program Manager (PM) — Key Personnel |
|
Program / Contract |
Cybersecurity Services Program (Information System Security Officer / ISSO Support) |
|
Client |
Federal Government Agency |
|
Location |
Contractor facility within the National Capital Region (NCR); on-site presence required at customer facilities in the Washington, DC metro area, with occasional travel to other domestic and/or overseas locations as required |
|
Clearance Required |
Active Secret personnel security clearance, to be maintained throughout the period of performance |
|
Status |
Key Personnel — full-time upon contract award; availability required within the timeframe specified by the awarded contract (commonly within 10 calendar days of award) |
Position Summary
The Program Manager (PM) is the single point of accountability for the performance of a federal cybersecurity services engagement providing Information System Security Officer (ISSO) support — and the mandate goes beyond steady-state compliance. We are looking for a recognized cybersecurity leader who wants to help a federal customer genuinely modernize how it applies the Risk Management Framework (RMF): fully leveraging the customer's existing processes and investments, while identifying and recommending continuous monitoring and continuous authorization (cATO) models, streamlined Assessment and Authorization (A&A) processes, and automation or DevSecOps principles where appropriate, rather than simply maintaining the status quo. The PM leads all contractual, administrative, and performance aspects of the effort, ensures deliverables and timelines are met, and serves as the company's primary interface with the customer's Contracting Officer (CO) and Contracting Officer's Representative (COR) — while also acting as a trusted advisor who brings forward-looking RMF practice into that relationship.
Why This Role
This position is built for a thought leader, not a caretaker. Excentium is looking for someone who wants to leave the customer's RMF program measurably better than they found it, with room to:
- Shape the customer's RMF roadmap directly — leveraging what the customer already has in place and proposing better paths to authorization (continuous monitoring/cATO, control automation, RMF-as-code) where appropriate, rather than just executing a fixed scope of work.
- Get the most out of the customer's existing GRC and compliance tooling, and recommend modern tooling or automation where appropriate, to reduce the paperwork burden of traditional Assessment and Authorization work for the customer's own security staff.
- Represent Excentium's cybersecurity practice externally — through publications, conference presentations, professional associations, or agency working groups focused on RMF modernization, Zero Trust, and continuous authorization.
- Build and mentor a high-performing ISSO/compliance team, elevating the program's practice and setting a standard other engagements can point to.
- Partner with Excentium's broader Cybersecurity Professional Services practice — including its FedRAMP 3PAO assessors and CMMC advisors — to bring cross-program innovation back into this engagement.
Minimum Qualifications (Required)
Typical minimum qualifications for this labor category include:
- A Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (Master's degree preferred).
- At least ten (10) years of experience managing large-scale cybersecurity programs.
- A current Project Management Professional (PMP) or equivalent project management certification.
- A current Secret-level personnel security clearance.
- Experience managing contracts of similar size and complexity.
- Experience with federal government cybersecurity requirements.
- Availability to begin within the timeframe specified at contract award.
Preferred / Distinguishing Qualifications
Candidates who stand out for this role typically also bring:
- A demonstrated track record of modernizing or streamlining an RMF/A&A program — e.g., leveraging and extending existing continuous monitoring or continuous authorization (cATO) practices, or recommending automation of control assessment/POA&M workflows or integration of security into CI/CD pipelines (DevSecOps) where appropriate.
- Visible thought leadership in the RMF/cybersecurity-compliance community: published articles or white papers, conference or webinar speaking engagements, active participation in NIST or industry working groups, or contributions to public RMF tooling or methodology.
- Experience getting the most out of a customer's existing GRC platforms and automation tooling, and recommending new tooling only where it clearly reduces manual compliance burden for both the contractor and customer teams.
- A history of building, mentoring, and retaining strong ISSO or cybersecurity compliance teams.
Key Responsibilities
Core responsibilities of this role typically include:
- Serve as the primary point of contact for all contractual, administrative, and performance matters under the contract.
- Provide overall leadership, resource planning, and coordination to ensure deliverables and timelines are met.
- Interface directly with the Contracting Officer (CO) and Contracting Officer's Representative (COR) to resolve issues and report status.
In addition, consistent with standard program management expectations for this type of engagement, the PM is expected to:
- Own the program's staffing plan, including recruitment, retention, and timely substitution of personnel consistent with Key Personnel requirements.
- Lead risk identification, issue resolution, and change-management processes.
- Prepare and deliver periodic status reports (activities, progress against milestones, performance metrics, risks, resource utilization, financial status).
- Oversee quality assurance and quality control for all deliverables prior to customer submission.
- Coordinate transition-in and, at contract completion, transition-out activities, including knowledge transfer to a successor contractor.
- Ensure continuity of Key Personnel roles and provide the customer prompt notice of any proposed change.
- Identify opportunities to get more value from the customer's existing RMF practice, and recommend continuous monitoring/authorization approaches, automation, or other process improvements where appropriate, building the business case to bring them to the customer's stakeholders.