TECHNICAL IT SECURITY PROJECT MANAGER (PM)
TECHNICAL IT SECURITY PROJECT MANAGER
MILITARY FRIENDLY & PREFERRED - HOH SPONSOR
Zermount, Inc has a requirement for a Technical IT Security Project Manager (PM) who will be providing client support by delivering project management services and technical oversight for IT Security Engineering and Testing and Compliance services. The candidate will serve as key personnel and provide primary accountability to ensure LOC receives the appropriate support and resources required to deliver quality results, while maintaining productive and effective relationships with client leadership and stakeholders.
The PM will support the execution of two complementary task areas: (1) IT Security Engineering (ITSE) consisting of Architecture; Zero Trust, Engineering; Content Enablement and Development; and Administration and Maintenance support for a suite of enterprise security tools; and (2) IT Security Compliance and Testing (ITSC&T) consisting of providing hardening guide and secure configuration guide development and sustainment; Risk and Security Assessments; IT Security Testing services including Application Security Assessments (ASA's), Technical Testing (e.g., Software code analysis, Vulnerability and Compliance, Database, Web Applications, Security Control Assessments, and Mobile Application, and Identity Access Management (IAM) solutions); and Penetration Testing services.
The PM will provide management and quality assurance services across deliverables, schedules, reporting, and service performance, ensuring work is executed in accordance with client direction, required service levels, and government standards. The PM is expected to manage multiple concurrent efforts, develop, manage and integrate schedules across efforts, initiatives, and task areas identifying workstreams, tasks, sub-tasks, planned and actual dates, dependencies, risks, and resources and ensure the team produces clear, accurate, and audit-ready deliverables. While this role requires strong technical knowledge of cybersecurity domains and enterprise security capabilities, it is not intended to be hands-on execution. The PM provides management practices, leadership, coordination, and QA to ensure technical work is performed correctly and meets requirements.
RESPONSIBILITIES:
- Provide day-to-day project management oversight for enterprise IT Security services supporting an environment of approximately 5,000 users, 7,500 endpoints, and 10,000 network entities across on-premises data centers and AWS and Azure cloud environments.
- Provide primary accountability for delivery of task order outcomes and deliverables, ensuring appropriate management practices, to include resource, schedule, risk, quality, communication, performance, and delivery, is implemented and executed to meet the requirements of the client and the company.
- Develop, maintain, and update the Project Management Plan (PMP) and integrated project schedules, including task and sub-tasks, dependencies, resources, and dates (planned and actual) for all tasks and activities.
- Develops, maintains, and oversees integrated project schedules across all task order activities, ensuring alignment with program objectives, critical milestones, resource availability, and stakeholder expectations.
- Develop, maintain, and update Quality Assurance / Quality Control Plan (QAP / QCP) and Quality Assurance Surveillance Plan (QASP) and implement internal QA practices to ensure deliverables are accurate, complete, and audit ready.
- Provide schedule management and delivery oversight for ongoing security tool support activities including architecture planning, zero trust, content development and enablement activities, engineering services, and administration/maintenance support for tools such as SIEM, SOAR, EDR, Cloud, Scanning, GRC, firewalls, cloud security platforms, DLP, and CASB.
- Lead recurring status meetings and reporting in accordance with task order requirements, including weekly status meetings and monthly status reporting, and ensure required daily updates are provided when applicable to tasking.
- Coordinate intake, prioritization, and execution of work requests, including ServiceNow-driven guide development tasks and testing/scanning requests directed by the COR/CISO.
- Oversee performance against required timelines and SLAs, including (as applicable) responsiveness to tasking, delivery of scan/test outputs, and completion timelines for security assessments and guide deliverables.
- Ensure tool support activities include appropriate coordination with client teams and vendors for implementation planning, upgrades, patching, tuning, troubleshooting, and change/request tracking through successful completion.
- Oversee planning and execution coordination for IT Security Testing and Compliance Services, including monthly and ad-hoc vulnerability/compliance scanning, quarterly database scanning, application security assessment coordination, penetration testing support coordination, and required documentation of test plans and results.
- Ensure security hardening and configuration guide efforts are planned, tracked, and delivered, including review and update of approximately 100 hardening guides and 100 configuration guides, as well as creation of new guides as new technologies are introduced.
- Track risks, issues, dependencies, and resource constraints; develop mitigation plans; and brief client leadership on schedule impacts and options.
- Produce briefings, reports, and executive-ready communications as requested by LOC stakeholders, supporting decision-making, risk posture, and program progress.
- Ensure project execution aligns with client policies and directives, including protection of Controlled Unclassified Information (CUI) and adherence to government information security requirements.
- Enhance team performance by establishing clear processes, ensuring accountability, supporting continuous improvement, and mentoring team members on project execution and delivery standards.
QUALIFICATIONS:
- Must have at least 5 years of experience managing IT Security programs similar in size and scope to this requirement.
- Must have experience managing teams, minimally, of 10 direct reports and/or leading delivery teams with equivalent accountability for scope, schedule, and quality.
- Demonstrated ability to manage multiple projects simultaneously, work under pressure and tight deadlines, and communicate effectively with technical staff and executive stakeholders.
- Strong ability to develop and manage project schedules, deliverable plans, and reporting cadences, and to coordinate work across multiple technical workstreams.
- Proven experience producing high-quality written deliverables (plans, reports, briefings) that can withstand audit-level review.
- Solid technical knowledge of cybersecurity operations and enterprise security services sufficient to provide oversight and quality assurance of technical work products (not hands-on execution).
- Proficient in Microsoft® Office suite including Word®, Excel®, PowerPoint®, and Project®.
- Preferred technical familiarity with one or more of the following toolsets/areas: Splunk; Cribl; RSA Archer (GRC); Palo Alto NGFW/Prisma/CASB/Cloud DLP; Tenable/Nessus; AWS Inspector; Swimlane; Core Impact; Fortify; Carbon Black Cloud; Microsoft Defender for Endpoint; SQL/SSMS concepts as they relate to GRC platform administration and reporting.
- Excellent customer-facing skills and proven ability to build and maintain strong client relationships.
- Must have the ability to effectively communicate both orally (in common English narration) and in writing (to include technical documentation).
- Must be a United States citizen and able to pass a LOC Public Trust Background Investigation.
CERTIFICATION(S):
- Must have a minimum of one (1) IT Security certification at the IAM II or III Level referenced in the Department of Defense Approved 8570 Baseline list.
- Additional certifications preferred: PMI PMP; and ITIL
CLEARANCE:
- Public Trust Background Investigation
HOURS OF OPERATIONS
- Location: Primary location is Arlington, VA and Washington, DC. Remote work is authorized. Occasional travel to the onsite location may be required.
- Core Contract Hours: 8:00 am – 4:00 pm, Monday – Friday ET
- May require after-hours support in cases of emergency response and scheduled maintenance/support activities.