Job at a glance
Position Description Program Manager - Cybersecurity Services (ISSO Support) Excentium, Inc. Position Title Program Manager (PM) - Key Personnel Program / Contract Cybersecurity Services Program (Information System Security Officer / ISSO Support) Client Federal Government Agency Location Contractor facility within the National Capital Region (NCR); on-site presence required at customer facilities in the Washington, DC metro area, with occasional travel to other domestic and/or overseas locations as required Clearance Required Active Secret personnel security clearance, to be maintained throughout the period of performance Status Key Personnel - full-time upon contract award; availability required within the timeframe specified by the awarded contract (commonly within 10 calendar days of award)Position Summary The Program Manager (PM) is the single point of accountability for the performance of a federal cybersecurity services engagement providing Information System Security Officer (ISSO) support - and the mandate goes beyond steady-state compliance.
We are looking for a recognized cybersecurity leader who wants to help a federal customer genuinely modernize how it applies the Risk Management Framework (RMF): fully leveraging the customer's existing processes and investments, while identifying and recommending continuous monitoring and continuous authorization (cATO) models, streamlined Assessment and Authorization (A&A) processes, and automation or DevSecOps principles where appropriate, rather than simply maintaining the status quo.
The PM leads all contractual, administrative, and performance aspects of the effort, ensures deliverables and timelines are met, and serves as the company's primary interface with the customer's Contracting Officer (CO) and Contracting Officer's Representative (COR) - while also acting as a trusted advisor who brings forward-looking RMF practice into that relationship. Why This Role This position is built for a thought leader, not a caretaker.
Excentium is looking for someone who wants to leave the customer's RMF program measurably better than they found it, with room to: Shape the customer's RMF roadmap directly - leveraging what the customer already has in place and proposing better paths to authorization (continuous monitoring/cATO, control automation, RMF-as-code) where appropriate, rather than just executing a fixed scope of work. Get the most out of the customer's existing GRC and compliance tooling, and recommend modern tooling or automation where appropriate, to reduce the paperwork burden of traditional Assessment and Authorization work for the customer's own security staff.
Represent Excentium's cybersecurity practice externally - through publications, conference presentations, professional associations, or agency working groups focused on RMF modernization, Zero Trust, and continuous authorization. Build and mentor a high-performing ISSO/compliance team, elevating the program's practice and setting a standard other engagements can point to. Partner with Excentium's broader Cybersecurity Professional Services practice - including its FedRAMP 3PAO assessors and CMMC advisors - to bring cross-program innovation back into this engagement.
Minimum Qualifications (Required) Typical minimum qualifications for this labor category include: A Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (Master's degree preferred). At least ten (10) years of experience managing large-scale cybersecurity programs. A current Project Management Professional (PMP) or equivalent project management certification.
A current Secret-level personnel security clearance. Experience managing contracts of similar size and complexity. Experience with federal government cybersecurity requirements. Availability to begin within the timeframe specified at contract award. Preferred / Distinguishing Qualifications Candidates who stand out for this role typically also bring: A demo