cATO TECHNICAL PROJECT MANAGER (PM)

Zermount, Inc.

United States

Hybrid

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible working hours
Remote work options
Continuous learning opportunities

Job summary

Zermount, Inc. is seeking a cATO Technical Project Manager to lead cybersecurity architecture initiatives. You'll coordinate teams to deliver secure cloud solutions and enhance risk management outcomes.

This role demands over 5 years of experience in network and cloud security, alongside expertise in Agile environments. A Bachelor’s degree in a technical field and CISSP certification are mandatory. Remote work is authorized, with some travel required to Arlington and Alexandria, VA.

Qualifications

  • Strong attention to detail and ability to work with minimal guidance.
  • Ability to communicate technical risks to executives.
  • 5+ years of experience across network, systems, and application security.

Responsibilities

  • Lead planning and execution of cybersecurity architecture projects.
  • Develop Enterprise Security Reference Architecture and standards.
  • Conduct quality assurance for security architecture reviews.
  • Oversee automated evidence collection processes.

Skills

Excellent written and verbal communication skills
Project leadership experience
Experience in Agile environments
Network, systems, and application security
Cloud security expertise (AWS)
DevSecOps integration
Analytical and problem-solving skills

Education

Bachelor of Science in Computer Science

Tools

AWS Security Hub
Azure Defender
CI/CD tools

Job description

cATO TECHNICAL PROJECT MANAGER (PM)

Military Friendly & Preferred - HOH Sponsor

SUMMARY

The cATO Technical PM plans and drives delivery of cybersecurity architecture and engineering initiatives such as enterprise security and Continuous Authorization to Operate (cATO). This role coordinates cross-functional teams to deliver secure cloud and hybrid solutions, automate controls and evidence collection (including OSCAL), and improve risk management outcomes through repeatable standards, roadmaps, and Agile execution.

KEY RESPONSIBILITIES
  • Lead planning and execution across cybersecurity architecture and engineering workstreams to support the agency cybersecurity mission.
  • Develop, maintain, and evolve the Enterprise Security Reference Architecture (ESRA), security patterns, and standards for cloud and on prem environments.
  • Provide architectural input to the Cybersecurity Roadmap and Strategy, including cATO maturity, automated control testing, and improvements to ATO timelines.
  • Design and operationalize continuous monitoring and automated evidence collection pipelines (e.g., SIEM/XDR, scanners, cloud APIs, CI/CD) and integrate outputs into AO grade dashboards.
  • Develop and manage OSCAL artifacts (profiles, inheritance models) and evidence data contracts to support scalable, repeatable assessments.
  • Oversee and quality assure security architecture reviews (SAR), technical risk assessments/threat modeling, secure design reviews, and High Value Asset (HVA) assessments; ensure findings include practical mitigations and recommendations.
  • Support ATO intake and assessment workflows and vulnerability scanning programs (vulnerability, compliance, configuration, database, web application, continuous monitoring, and ad hoc) aligned to RMF and federal guidance.
  • Provide security architecture leadership for DevSecOps strategy and implementation, including integrating security scanning into pipelines and implementing security controls in accordance with RMF/CSF/FISMA/FedRAMP.
  • Design and deploy native cloud security services and reference implementations across AWS, Azure, and GCP, including security in Infrastructure as Code (IaC) templates/blueprints.
  • Evaluate and conduct proofs of value for cloud native, COTS, third party, and open source security tools; recommend improvements for coverage, efficacy, and efficiency.
  • Partner with operations teams to improve cloud monitoring, detection, and response (e.g., log ingestion/analysis, alert tuning, SOC visibility) and to identify/contain/remediate SDLC vulnerabilities.
  • Lead and mentor a team of security architects/engineers; coordinate cross functional stakeholders; provide briefings/presentations to technical and executive audiences.
  • Own delivery management: facilitate requirements gathering, backlog refinement, sprint planning, capacity planning, and retrospectives; ensure teams deliver high value increments meeting the Definition of Done.
  • Develop and maintain supporting documentation (e.g., SOPs, policies, procedures, review guides, and checklists) as required.
  • May be required to perform other tasks and activities associated with the Cybersecurity Architecture and Engineering contract or requested by Executive Leadership to assist with other solutions to support clients or teams.
REQUIRED QUALIFICATIONS
  • Excellent written and verbal communication skills; high attention to detail; able to work with minimal guidance.
  • Demonstrated ability to operate at both the strategic and hands on technical level; able to explain technical risks and options to executive audiences.
  • Proven project leadership experience coordinating cross functional teams and stakeholders; able to manage changing priorities and deliver to schedule.
  • Experience leading delivery in Agile environments (e.g., Scrum/Kanban), including backlog refinement, sprint planning, capacity planning, and retrospectives.
  • 5+ years (10+ preferred) experience across network, systems, and application security domains (e.g., LAN/WAN, WAF/CDN/DDoS, firewalls, IDS/IPS, virtualization, containers, CI/CD, microservices, serverless).
  • 5+ years designing and/or implementing security in cloud environments (AWS required; Azure strongly preferred; GCP a plus), including shared responsibility model and hybrid/multi cloud concepts.
  • Working knowledge/experience with cloud security services and tooling such as:
    • AWS: Security Hub, Config, GuardDuty, CloudTrail, CloudWatch, Lambda, IAM/KMS (or equivalent services).
    • Azure: Entra ID/AD, Key Vault, Monitor/Log Analytics, Policy, Defender for Cloud (or equivalent services).
  • Experience with DevSecOps security strategy and implementation, including integrating automated security assessments/scanning and evidence collection into CI/CD pipelines.
  • Experience designing and assessing architectures in accordance with RMF and federal security guidance (e.g., NIST, FISMA, FedRAMP); familiarity with CSF preferred.
  • Familiarity with Zero Trust (EO 14028), SCRM, ICAM, SASE/CASB/SWG/TIC 3.0 concepts and enterprise security operations (SIEM/SOC) preferred.
  • Strong analytical and problem solving skills; ability to research, evaluate, and recommend mitigations for threats and vulnerabilities.
  • Experience developing security documentation such as SOPs, procedures, guidelines, and assessment reports.
EDUCATION
  • Bachelor of Science (or higher) in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical field.
CERTIFICATIONS
  • CISSP is required. In addition, at least one of the following are also required CCSP; AWS Certified Solutions Architect (Associate or higher); AWS Certified Security - Specialty; Microsoft Certified: Azure Solutions Architect Expert; Google Professional Cloud Architect (or equivalent).
CLEARANCE
  • Minimum of an active Secret clearance.
LOCATION
  • Primary locations are Arlington and Alexandria, VA. Remote work is authorized. Occasional travel to the primary locations will be required.
  • Hours: 6:00 am ET – 6:00 pm ET.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

cATO TECHNICAL PROJECT MANAGER (PM)
cATO TECHNICAL PROJECT MANAGER (PM)

Hiring Our Heroes • Arlington (VA)

On-site
USD 100,000 - 140,000
Remote work authorization
Flexible working hours
cATO TECHNICAL PROJECT MANAGER (PM)
cATO TECHNICAL PROJECT MANAGER (PM)

Zermount, Inc. • United States Virgin Islands

Hybrid
USD 120,000 - 150,000
Remote Cybersecurity Project Lead (cATO & Cloud Security)
Remote Cybersecurity Project Lead (cATO & Cloud Security)

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 100,000 - 140,000
Remote work authorization
Flexible working hours
SECURITY ARCHITECTURE & ENGINEERING SME
SECURITY ARCHITECTURE & ENGINEERING SME

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 120,000 - 160,000
Flexible work environment
Opportunities for professional development
CYBERSECURITY ARCHITECT
CYBERSECURITY ARCHITECT

Zermount, Inc. • Arlington (VA)

Remote
USD 110,000 - 150,000
Technical Project Manager
Technical Project Manager

ECS • Richmond (VA)

Hybrid
USD 110,000 - 125,000
Cybersecurity cATO Project Manager – Cloud & DevSecOps
Cybersecurity cATO Project Manager – Cloud & DevSecOps

Zermount, Inc. • United States

Hybrid
USD 120,000 - 150,000
Flexible working hours
Remote work options
Continuous learning opportunities
SECURITY ARCHITECTURE & ENGINEERING SME
SECURITY ARCHITECTURE & ENGINEERING SME

Zermount, Inc. • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Remote work authorized
Occasional travel to primary location required
CLOUD SECURITY ENGINEER - AWS GOVCLOUD / MULTI-CLOUD
CLOUD SECURITY ENGINEER - AWS GOVCLOUD / MULTI-CLOUD

Zermount, Inc. • Arlington (VA)

Hybrid
USD 155,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000