Position DescriptionDeputy Program Manager - Cybersecurity Services (ISSO Support)
Position TitleDeputy Program Manager (DPM) - Key Personnel
Program / ContractCybersecurity Services Program (Information System Security Officer / ISSO Support)
ClientFederal Government Agency
LocationContractor facility within the National Capital Region (NCR); on-site presence required at
customer facilities in the Washington, DC metro area, with occasional travel to other domestic
and/or overseas locations as required
Clearance RequiredActive Secret personnel security clearance, to be maintained throughout the period of performance
StatusKey Personnel - full-time upon contract award; availability required within the timeframe
specified by the awarded contract (commonly within 10 calendar days of award)
Position SummaryThe Deputy Program Manager (DPM) serves as the secondary point of contact for all contractual, administrative, and performance matters on a federal cybersecurity services engagement providing Information System Security Officer (ISSO) support, standing ready to step into the Program Manager's (PM) role at any time to preserve continuity of leadership - and the mandate goes beyond steady-state compliance. We are looking for a cybersecurity leader who wants to help a federal customer genuinely modernize how it applies the Risk Management Framework (RMF): fully leveraging the customer's existing processes and investments, while identifying and recommending continuous monitoring and continuous authorization (cATO) models, streamlined Assessment and Authorization (A&A) processes, and automation or DevSecOps principles where appropriate, rather than simply maintaining the status quo. The DPM shares leadership of the effort alongside the PM, helps ensure deliverables and timelines are met, and interfaces with the customer's Contracting Officer (CO) and Contracting Officer's Representative (COR) - while also acting as a trusted advisor who brings forward-looking RMF practice into that relationship. This is typically a Key Personnel position: the individual named for this role is often a stated basis for contract award and, once under contract, generally may not be removed, replaced, or substituted without prior written Contracting Officer approval.
Minimum Qualifications (Required)Typical minimum qualifications for this labor category include:
- A Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- At least eight (8) years of experience in cybersecurity program management.
- A current Project Management Professional (PMP) or equivalent project management certification.
- A current Secret-level personnel security clearance.
- Experience with federal government cybersecurity requirements.
- Availability to begin within the timeframe specified at contract award.
Preferred / Distinguishing QualificationsCandidates who stand out for this role typically also bring:
- A demonstrated track record of modernizing or streamlining an RMF/A&A program - e.g., leveraging and extending existing continuous monitoring or continuous authorization (cATO) practices, or recommending automation of control assessment/POA&M workflows or integration of security into CI/CD pipelines (DevSecOps) where appropriate.
- Visible thought leadership in the RMF/cybersecurity-compliance community: published articles or white papers, conference or webinar speaking engagements, active participation in NIST or industry working groups, or contributions to public RMF tooling or methodology.
- Experience getting the most out of a customer's existing GRC platforms and automation tooling, and recommending new tooling only where it clearly reduces manual compliance burden for both the contractor and customer teams.
- A history of building, mentoring, and retaining strong ISSO or cybersecurity compliance teams.
- A Master's degree in a related field, and readiness to assume full Program Manager responsibilities if called upon.
Key ResponsibilitiesCore responsibilities of this role typically include:
- Serve as the secondary point of contact for all contractual, administrative, and performance matters under the contract, standing in for the Program Manager as needed.
- Provide overall leadership, resource planning, and coordination to ensure deliverables and timelines are met.
- Interface directly with the Contracting Officer (CO) and Contracting Officer's Representative (COR) to resolve issues and report status.
In addition, consistent with standard program management expectations for this type of engagement, the DPM is expected to:
- Support the program's staffing plan, including recruitment, retention, and timely substitution of personnel consistent with Key Personnel requirements.
- Assist with risk identification, issue resolution, and change-management processes.
- Help prepare and deliver periodic status reports (activities, progress against milestones, performance metrics, risks, resource utilization, financial status).
- Support quality assurance and quality control for all deliverables prior to customer submission.
- Assist with transition-in and, at contract completion, transition-out activities, including knowledge transfer to a successor contractor.
- Help ensure continuity of Key Personnel roles and support prompt notice to the customer of any proposed change.
- Identify opportunities to get more value from the customer's existing RMF practice, and recommend continuous monitoring/authorization approaches, automation, or other process improvements where appropriate, building the business case to bring them to the customer's stakeholders.