ISSO Program Manager; PgM
Listed on 2026-06-20
-
IT/Tech
Cybersecurity, IT Consultant
ISSO PROGRAM MANAGER (PgM)
MILITARY FRIENDLY & PREFERRED - HOH SPONSOR
Zermount, Inc has a requirement for an ISSO PM who will support our client by providing project management and Information Security expertise for our ISSO Team. The ISSO PM is expected to provide advisory in securing enterprise information and systems, by determining security requirements; planning, designing, implementing, and testing systems and security technologies; developing security standards, policies, and procedures; and mentoring team members.
The ISSO Program Manager serves as the senior cybersecurity lead responsible for managing all security compliance, RMF activities, and continuous monitoring for all systems within the client's enterprise while also providing full lifecycle program management support. This role integrates IT and Information Security subject matter expertise with project management responsibilities to ensure secure, compliant, and mission-aligned delivery for our federal client.
The ISSO PM manages security operations, reporting, deliverables, stakeholder communication, resources, schedules and technical oversight of cybersecurity governance, risk, and compliance (GRC) activities to meet agency and contract requirements.
- Provide day-to-day management of the ISSO Team, develop project schedules, reports, and briefings in accordance with the contract requirements.
- Provide primary accountability to ensure the task orders receives the appropriate support and resources required to deliver quality results.
- Provide strategic direction, vision, leadership, and management to the team(s) assigned to the task order.
- Contribute to organizational direction through regular involvement with client leadership and team members.
- Maintain productive and effective client relationship with the most senior levels of the client organization.
- Manage numerous project schedules simultaneously.
- Develop, maintain and update project management plans, project schedules, and an Integrated Master Schedule (IMS).
- Develop, maintain and update Quality Assurance Surveillance Plans (QASP).
- Conduct assessments of threats and vulnerabilities, determine deviations from acceptable configurations, enterprise, or local policy, assess the level of risk, and develop and recommend appropriate mitigations.
- Ensure ISSO team meets contract requirements and client established KPI's and performance metrics.
- Provide risk analysis for vulnerabilities, incidents and change requests and advise on the impact of new or changing applicable federal policy changes.
- Conduct research and present analyses to evaluate and/or determine emerging industry technology trends, government agency best practices, and security issues.
- Determine security requirements by evaluating strategies / requirements; research IT security standards; conduct security and vulnerability analyses and risk assessments; review architecture/platform; identify integration issues; prepare cost estimates.
- Provide expertise and guidance to OCIO on Dev Sec Ops / secure development, operational systems, and enhancements in support of the client's mission.
- Assist business owners, system owners, and system engineers with selecting and implementing controls that maintain a high level of security and protect patron privacy.
- Monitor and ensure compliance with standards, policies, and procedures; support IR activities; develop and conducting training programs.
- Prepare security reports by collecting, analyzing, and summarizing data and trends.
- Enhance company and client's reputation by accepting ownership for accomplishing new and different requests, exploring opportunities to add value to job accomplishments.
- Lead ISSOs for assigned systems in accordance with NIST RMF, FISMA, agency policy, directives, Zero Trust and cybersecurity requirements.
- Ensure quality requirements are met for system security documentation development and maintenance, including SSPs, Security Assessment Packages (SAP), SARs, POA&Ms, and continuous monitoring artifacts.
- Ensure all systems maintain ongoing authorization by implementing continuous monitoring, monthly artifact updates, vulnerability remediation, log…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).