Jobs and Careers
AR

Security Project Manager

Aretum
United Statesfull_timeVerifiedPosted 1 Dec 2023

About the role

ARETUM, a leading government contracting company specializing in technology-enabled mission support services, is seeking an experienced Security Project Manager to join our team. As a Security Project Manager, you will be responsible for overseeing the planning, execution, and successful completion of security projects for our clients in the government sector.

ARETUM LLC (ARETUM) is known for providing cutting-edge solutions and outstanding service to Federal clients in various sectors, including Next Generation Analytics, Engineering Services, Training Services, IT Systems, Cyber Security, PMO Support, and Financial Consulting. Our mission is to deliver technology-driven solutions that meet the unique needs of our government clients, enabling them to achieve their objectives effectively and efficiently.

The Security Project Manager will lead and manage a small team, manage all required contract PWS tasks, ensure the quality of deliverables, and coordinate directly with client and corporate leadership and system stakeholders.

• Implement effective project management of all team initiatives.

• Manage and coordinate with other team members to effectively execute tasks to ensure high quality deliverables and timely delivery.

• Develop and maintain project plan.

• Develop status reports and provide briefings to both client and corporate management.

• Serve as a skilled technical security advisor and security officer to business owners and stakeholders.

• Develop documentation as the primary author on RMF A&A documents including but not limited to the System Security Plan, Privacy Threshold Analysis, Privacy Impact Assessment, Contingency Plan, Configuration Management Plan, and Incident Response Plan.

• Implement quality assurance procedures to ensure high level of quality in all deliverables submitted by the team.

• Perform and support security operations tasks including vulnerability management, implement role-based access controls, data-masking and analytics, audit log analysis, secure configuration management, etc.

• Provide tactical and strategic guidance to improve organizational security program.

• Provide security design and impact analysis for enterprise operations and solutions.

• Provide assistance in various assessment activities including A&A security control assessments.

• Coordinate and communicate with system stakeholders as required to complete all aspects of the A&A process.

• Understand and articulate security architecture of systems and how it integrates with the enterprise security stack.

• Provide security design and security impact analysis on agency systems.

• Perform both technical and documentation continuous monitoring tasks.

• Keep abreast of changing audit guidelines, Federal guidance, and regulations.

• Lead and advise on POA&M remediations and control finding closures using evidential matter or other required closure evidence.

• Support security controls assessment activities.

• Perform all required tasks in a timely and proficient manner while exercising sound time and task management.

• Work effectively with other team members to complete required tasks.

Requirements

• Citizenship: Must be US citizen or Green Card Holder with ability to obtain Public Trust Clearance (High Risk)

• 5 (+) years of technical experience in cybersecurity.

• 5 (+) years of experience with Federal certification and accreditation A&A.

• 5 (+) years of experience with maintaining IT security policies, processes, and guidance.

• Strong leadership experience leading small teams and interacting with client leadership.

• Professional experience with a solid understanding of incident response, insider threat investigations, forensics, cyber threats and information security.

• Experience with applying the NIST Cybersecurity Framework.

• Experience with Federal Risk and Authorization Management Program (FedRAMP).

• Proficient understanding of the NIST RMF 800-137 Rev2 processes and the NIST security control set (800-53 Rev4, 800-53 Rev5).

• Experience with developing and managing continuous monitoring and plans of action and milestones (POA&M).

• Strong communication (verbal and written) skills and experience.

• Strong attention to detail.

• Ability to effectively articulate and advise security requirements to various audiences including management, business stakeholders, and technical staff.

• Ability to work alone and in a team environment equally proficiently.

MUST HAVE AT LEAST ONE:

• Security Certification: CISSP, CISM, CAP or equivalent certification highly preferred.


Benefits

ARETUM is an equal opportunity employer, committed to diversity and inclusion

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Aretum

View company profile →