Deputy Cybersecurity Program Manager

Excentium, Inc.
Washington, DC, United States
14 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$99,000.0 - $103,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Security Management Zero Trust Network Access Information Technology RSA Archer Platform Devsecops Plan of Action and Milestones

Job description

Deputy Program Manager - Cybersecurity Services (ISSO Support), The Deputy Program Manager (DPM) serves as the secondary point of contact for all contractual, administrative, and performance matters on a federal cybersecurity services engagement providing Information System Security Officer (ISSO) support, standing ready to step into the Program Manager’s (PM) role at any time to preserve continuity of leadership - and the mandate goes beyond steady-state compliance. We are looking for a cybersecurity leader who wants to help a federal customer genuinely modernize how it applies the Risk Management Framework (RMF): fully leveraging the customer’s existing processes and investments, while identifying and recommending continuous monitoring and continuous authorization (cATO) models, streamlined Assessment and Authorization (A&A) processes, and automation or DevSecOps principles where appropriate, rather than simply maintaining the status quo. The DPM shares leadership of the effort alongside the PM, helps ensure deliverables and timelines are met, and interfaces with the customer’s Contracting Officer (CO) and Contracting Officer’s Representative (COR) - while also acting as a trusted advisor who brings forward-looking RMF practice into that relationship. This is typically a Key Personnel position: the individual named for this role is often a stated basis for contract award and, once under contract, generally may not be removed, replaced, or substituted without prior written Contracting Officer approval.

Why This Role

This position is built for a thought leader, not a caretaker. Excentium is looking for someone who wants to help leave the customer’s RMF program measurably better than they found it, with room to:

  • Help shape the customer’s RMF roadmap alongside the PM - leveraging what the customer already has in place and proposing better paths to authorization (continuous monitoring/cATO, control automation, RMF-as-code) where appropriate, rather than just executing a fixed scope of work.
  • Get the most out of the customer’s existing GRC and compliance tooling, and recommend modern tooling or automation where appropriate, to reduce the paperwork burden of traditional Assessment and Authorization work for the customer’s own security staff.
  • Represent Excentium’s cybersecurity practice externally - through publications, conference presentations, professional associations, or agency working groups focused on RMF modernization, Zero Trust, and continuous authorization.
  • Help build and mentor a high-performing ISSO/compliance team, elevating the program’s practice and setting a standard other engagements can point to.
  • Partner with Excentium’s broader Cybersecurity Professional Services practice - including its FedRAMP 3PAO assessors and CMMC advisors - to bring cross-program innovation back into this engagement.
  • Grow into the Program Manager role over time, with direct exposure to full contract accountability as the PM’s designated backup., Core responsibilities of this role typically include:
  • Serve as the secondary point of contact for all contractual, administrative, and performance matters under the contract, standing in for the Program Manager as needed.
  • Provide overall leadership, resource planning, and coordination to ensure deliverables and timelines are met.
  • Interface directly with the Contracting Officer (CO) and Contracting Officer’s Representative (COR) to resolve issues and report status.

In addition, consistent with standard program management expectations for this type of engagement, the DPM is expected to:

  • Support the program’s staffing plan, including recruitment, retention, and timely substitution of personnel consistent with Key Personnel requirements.
  • Assist with risk identification, issue resolution, and change-management processes.
  • Help prepare and deliver periodic status reports (activities, progress against milestones, performance metrics, risks, resource utilization, financial status).
  • Support quality assurance and quality control for all deliverables prior to customer submission.
  • Assist with transition-in and, at contract completion, transition-out activities, including knowledge transfer to a successor contractor.
  • Help ensure continuity of Key Personnel roles and support prompt notice to the customer of any proposed change.
  • Identify opportunities to get more value from the customer’s existing RMF practice, and recommend continuous monitoring/authorization approaches, automation, or other process improvements where appropriate, building the business case to bring them to the customer’s stakeholders.

Requirements

  • A Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • At least eight (8) years of experience in cybersecurity program management.
  • A current Project Management Professional (PMP) or equivalent project management certification.
  • A current Secret-level personnel security clearance.
  • Experience with federal government cybersecurity requirements.
  • Availability to begin within the timeframe specified at contract award., * A demonstrated track record of modernizing or streamlining an RMF/A&A program - e.g., leveraging and extending existing continuous monitoring or continuous authorization (cATO) practices, or recommending automation of control assessment/POA&M workflows or integration of security into CI/CD pipelines (DevSecOps) where appropriate.
  • Visible thought leadership in the RMF/cybersecurity-compliance community: published articles or white papers, conference or webinar speaking engagements, active participation in NIST or industry working groups, or contributions to public RMF tooling or methodology.
  • Experience getting the most out of a customer’s existing GRC platforms and automation tooling, and recommending new tooling only where it clearly reduces manual compliance burden for both the contractor and customer teams.
  • A history of building, mentoring, and retaining strong ISSO or cybersecurity compliance teams.
  • A Master’s degree in a related field, and readiness to assume full Program Manager responsibilities if called upon.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all