InfoSec Engineer III PM

Quivera Enterprises, LLC

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

14 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Quivera Enterprises LLC is seeking an Information Security Engineer III / Project Manager to lead RMF-based cybersecurity efforts and manage complex federal IT projects. The role combines technical cybersecurity leadership with project management duties, ensuring compliance with RMF, NIST 800-53, and related federal requirements.

Responsibilities include coordinating with CORs and senior government leadership, delivering security artifacts, and guiding multidisciplinary teams through SDLC and

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS, IS, Engineering, Business or Project Management and a minimum of six (6) years of relevant experience; OR Master’s degree and five (5) years; OR eight (8) years of relevant experience without a degree.

Responsibilities

  • Lead Project Manager for ITSS, RMF, cybersecurity, or related federal task orders.
  • Manage technical, contractual, administrative, operational, and financial aspects of projects.

Skills

RMF expertise
NIST SP 800-53
Project management
Cybersecurity engineering
Stakeholder communication

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

US

This position is contingent upon contract award.

Wichita Tribal Enterprises (WTE), a Quivera Enterprise company, is seeking an Information Security Engineer III / Project Manager. This position serves as a dual-role technical and project management leader responsible for delivering advanced cybersecurity engineering and Risk Management Framework (RMF) support across federal information systems while managing one or more complex cybersecurity and information technology projects in accordance with federal requirements, contract performance objectives, budgets, schedules, and task order obligations.

The Information Security Engineer III / Project Manager provides multidisciplinary security administrative and technical support to the Indian Affairs (IA) RMF program and project management leadership in support of the Office of Information Technology (OIT). Areas of cybersecurity responsibility include Physical, Computer, Personnel, Information, Administrative, Operational, and Communications Security analysis, assessment, implementation, and reporting.

This position requires expert-level proficiency with NIST RMF, NIST SP 800-53, security assessments, continuous monitoring, vulnerability and risk management, and enterprise security architecture combined with demonstrated expertise managing federal IT and cybersecurity projects. The role is responsible for the technical, contractual, administrative, and financial aspects of assigned projects and task orders.

As a customer-facing leader, the Information Security Engineer III / Project Manager manages cybersecurity engineers and technical professionals, coordinates contract deliverables, monitors project performance, resolves project and personnel issues, and regularly communicates program status, risks, recommendations, and technical information to senior federal and organizational leadership.

Key Responsibilities
Project & Task Order Management
  • Serve as Project Manager for assigned ITSS, RMF, cybersecurity, or related federal task orders.
  • Manage the technical, contractual, administrative, operational, and financial aspects of assigned projects.
  • Manage one or more complex projects and ensure successful delivery of associated products and services in accordance with task orders, federal laws, regulations, policies, and procedures.
  • Develop and maintain project management plans, work breakdown structures, schedules, budgets, staffing plans, resource allocations, milestones, and performance metrics.
  • Monitor project objectives, budget, schedule, scope, quality, risks, and overall contract performance.
  • Review and analyze cost, schedule, and performance requirements for federal IT investments.
  • Identify project management issues and develop data-driven recommendations and corrective actions in coordination with applicable federal staff.
  • Track project progress against established milestones and proactively elevate risks, issues, dependencies, and schedule concerns.
  • Develop and implement mitigation and corrective action strategies to maintain project performance.
  • Ensure project activities comply with contract requirements, applicable regulations, and established program management practices.
  • Serve as a primary customer-facing representative for assigned cybersecurity and IT projects.
  • Lead project kickoff meetings, recurring status meetings, tag-up sessions, technical reviews, and stakeholder briefings.
  • Coordinate closely with federal Contracting Officer's Representatives (CORs), Federal Task Leads, program officials, OIT leadership, and other government stakeholders.
  • Prepare and deliver program status reports, executive briefings, performance metrics, risk information, and recommendations to senior government and organizational leadership.
  • Maintain proactive communication with federal representatives, program officials, external partners, subcontractors, and other stakeholders.
  • Facilitate resolution of technical, programmatic, contractual, and operational issues.
  • Coordinate with representatives and Subject Matter Experts (SMEs) from other federal agencies and commercial organizations to maintain awareness of emerging regulations, technologies, and cybersecurity practices.
Deliverable & Quality Management
  • Ensure the quality, accuracy, completeness, compliance, and timely delivery of all contract-required artifacts.
  • Manage cybersecurity authorization packages, engineering documentation, technical reports, project reports, status reports, and other contractual deliverables.
  • Implement quality assurance processes for documentation, reporting, risk tracking, security assessments, and package submissions.
  • Review Authorization to Operate (ATO) packages and supporting security artifacts for quality and completeness.
  • Maintain tracking mechanisms for contractual deliverables, milestones, action items, risks, and dependencies.
  • Ensure documentation and deliverables comply with applicable federal, Departmental, program, and contract requirements.
  • Manage and mentor Information Security Engineers, Information System Security Officers (ISSOs), security assessors, technical SMEs, and other project personnel as required by task order scope.
  • Provide leadership and direction to multidisciplinary cybersecurity and technical teams.
  • Delegate responsibilities effectively to maintain workload balance and alignment with contract requirements.
  • Coordinate personnel schedules, assignments, priorities, and resource requirements.
  • Provide performance feedback and staffing recommendations to organizational leadership.
  • Identify staffing gaps and resource constraints and recommend appropriate corrective actions.
  • Address personnel and performance challenges in coordination with organizational leadership.
  • Promote accountability, collaboration, knowledge sharing, and continuous improvement across project teams.
Risk Management Framework & Cybersecurity Engineering
  • Lead and support implementation and execution of the NIST Risk Management Framework in accordance with NIST SP 800-37 and applicable federal requirements.
  • Provide multidisciplinary administrative and technical cybersecurity support to the IA RMF program.
  • Implement, evaluate, assess, and document technical, management, and operational security controls in accordance with NIST SP 800-53.
  • Conduct comprehensive security assessments and develop required system authorization package deliverables.
  • Support system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring activities.
  • Evaluate security control effectiveness and identify deficiencies, vulnerabilities, risks, and required corrective actions.
  • Provide recommendations regarding system authorization readiness and cybersecurity risk.
  • Lead or support multi-team integration activities involving RMF-driven tasks and multi-system engagements.
Risk Assessment & Vulnerability Management
  • Develop Risk Assessments in accordance with NIST guidance and applicable federal requirements.
  • Deliver risk analyses, findings, recommendations, and strategic guidance to Associate Chief Information Officer (ACIO) leadership and other stakeholders.
  • Perform vulnerability analyses and evaluate identified weaknesses for potential mission, operational, technical, and cybersecurity impacts.
  • Develop mitigation plans and corrective action recommendations.
  • Assist senior management with establishing Plans of Action for remediation of organization-wide weaknesses.
  • Track security weaknesses and remediation activities through resolution.
  • Support contingency planning, disaster recovery, configuration management, and security assessment activities.
  • Identify systemic cybersecurity risks and recommend enterprise-level corrective actions.
Security Policy & Strategic Program Support
  • Provide recommendations to OIT and other offices and divisions regarding integration of cybersecurity processes and compliance with federal regulations and Departmental policies.
  • Provide strategic guidance supporting continued development and maturation of the IA security program.
  • Develop IT security policies, procedures, standards, architectures, directives, and Standard Operating Procedures (SOPs).
  • Review existing cybersecurity processes and recommend opportunities to improve effectiveness and efficiency.
  • Direct and support security efforts designed to increase operational efficiencies and reinforce a Zero Trust security architecture and enterprise-wide security mindset.
  • Support development and implementation of cybersecurity governance processes.
  • Provide strategic recommendations to senior federal leadership regarding cybersecurity risks, priorities, and remediation strategies.
System Development Life Cycle & Security Integration
  • Provide strategic guidance and continuous support for integrating cybersecurity throughout the System Development Life Cycle (SDLC).
  • Provide direct information assurance guidance regarding the development and modification of information systems and industrial control systems.
  • Evaluate new applications, technologies, projects, and changes to existing systems for potential cybersecurity impacts and gaps.
  • Recommend technical and procedural solutions to identified security deficiencies.
  • Assist OIT with cybersecurity recommendations regarding new and existing projects.
  • Provide project managers and technical teams with cybersecurity oversight throughout the project and system lifecycle.
  • Integrate security requirements into planning, design, development, implementation, operations, maintenance, and modernization activities.
  • Apply federal IT project and investment management principles throughout project execution.
  • Support Federal Enterprise Architecture (FEA), Capital Planning and Investment Control (CPIC), SDLC, IT Security Management, and Risk Management activities.
  • Maintain knowledge of federal IT investment laws, regulations, and processes, including FITARA, the Clinger-Cohen Act, the E-Government Act, FISMA, and applicable federal requirements.
  • Support applicable Office of Management and Budget (OMB) reporting requirements.
  • Adapt internal project and performance reporting to align with applicable federal reporting requirements.
  • Apply consistent IT Portfolio Management approaches designed to improve data quality, documentation, transparency, and decision-making.
  • Support governance reviews and investment management activities as required by the program.
Project Management Methodologies & Tools
  • Apply industry-standard project management principles and practices consistent with the Project Management Institute (PMI) and PMBOK.
  • Establish measurable project objectives, milestones, performance indicators, and reporting mechanisms.
  • Apply risk, schedule, cost, quality, communications, stakeholder, and resource management practices throughout project execution.
  • Maintain comprehensive project documentation and records.
  • Utilize appropriate project management, collaboration, reporting, and risk management tools.
  • Apply Human-Centered Design methodologies where appropriate, including Journey Mapping, Affinity Mapping, Storyboarding, and related techniques.
Required Qualifications
Education & Experience

Candidates must meet one of the following combinations of education and relevant professional experience:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, Business, Project Management, or a related field and a minimum of six (6) years of relevant experience; OR
  • Master's degree in a related discipline and a minimum of five (5) years of relevant experience; OR
  • Minimum of eight (8) years of relevant professional experience without a degree.

An industry-recognized technical certification may be accepted in lieu of one (1) year of experience, subject to contract requirements.

Candidates must also possess
  • Minimum of seven (7) years of direct, full-time experience conducting security assessments and developing required deliverables within system authorization packages.
  • Minimum of five (5) years of project management experience.
  • Demonstrated experience managing complex cybersecurity or federal IT programs with cross-platform or multi-system impacts.
  • Experience managing project objectives, budgets, schedules, resources, deliverables, and performance.
  • Experience managing or leading cybersecurity engineers and other technical professionals.
  • Experience communicating program and project status to senior government and organizational leadership.
Required Certification
  • Project Management Professional (PMP) certification required.
Required Knowledge, Skills & Abilities
  • Expert-level knowledge and practical experience implementing the NIST Risk Management Framework.
  • Expert-level knowledge of NIST SP 800-53 security and privacy controls.
  • Extensive experience implementing, evaluating, testing, and documenting technical, management, and operational security controls.
  • Experience conducting security assessments and developing system authorization package deliverables.
  • Expert knowledge of risk assessment and risk management methodologies.
  • Experience performing vulnerability analysis and developing mitigation plans.
  • Knowledge of contingency planning, disaster recovery, configuration management, and continuous monitoring.
  • Experience developing federal IT security policies, architectures, procedures, and SOPs.
  • Knowledge of Zero Trust Architecture principles and federal cybersecurity initiatives.
  • In-depth knowledge of IT project management processes and PMI/PMBOK principles and practices.
  • Knowledge of FEA, CPIC, SDLC, IT Security Management, and Risk Management.
  • Knowledge of federal IT investment laws, regulations, and processes, including FITARA, Clinger-Cohen Act, E-Government Act, and FISMA.
  • Knowledge of OMB reporting requirements.
  • Ability to review and analyze cost, schedule, scope, quality, and performance requirements for federal IT investments.
  • Ability to manage multidisciplinary technical teams and multiple concurrent priorities.
  • Ability to identify project risks and develop effective mitigation strategies.
  • Strong leadership, decision-making, analytical, and problem-solving capabilities.
  • Excellent verbal and written communication skills.
  • Strong technical writing and documentation capabilities.
  • Ability to communicate complex cybersecurity and project information to technical and non-technical stakeholders.
  • Ability to develop and deliver executive-level presentations and program status briefings.
  • Ability to establish and maintain effective working relationships with senior government leadership, federal CORs, Task Leads, SMEs, subcontractors, and organizational leadership.
Preferred Qualifications
  • Experience supporting Indian Affairs, the Department of the Interior, or another federal agency.
  • Experience supporting federal OIT or CIO organizations.
  • Experience managing federal cybersecurity, RMF, or ITSS task orders.
  • Experience managing ATO and system authorization package development.
  • Experience implementing or supporting Zero Trust Architecture within federal environments.
  • Experience assessing information systems and industrial control systems.
  • Experience supporting federal continuous monitoring programs.
  • Experience developing or maturing enterprise cybersecurity programs.
  • Experience with federal IT Portfolio Management.
  • Experience applying Human-Centered Design methodologies.
  • Additional cybersecurity certifications such as CISSP, CGRC, CISM, SecurityX/CASP+, Security+, or equivalent are preferred.
Clearance & Security Requirements
  • Must have the ability to successfully complete the required federal background investigation.
  • Must have the ability to obtain and maintain the required Government security clearance, suitability determination, or Public Trust designation as required by the contract.
  • Must comply with all applicable federal customer security, privacy, confidentiality, cybersecurity, and information assurance requirements.
Physical Demands

The physical demands described here are representative of those that must be met by an employee, with or without reasonable accommodation, to successfully perform the essential functions of this position.

This position is primarily performed in a professional office or technical environment and requires prolonged periods of sitting and working at a computer. The employee must be able to:

  • Frequently use computers and standard office equipment.
  • Communicate effectively through verbal, written, and electronic means.
  • Maintain visual acuity necessary for reviewing technical documentation, security assessments, project schedules, reports, system configurations, and computer displays.
  • Occasionally stand, walk, bend, reach, and lift or carry standard office or computer equipment.
  • Participate in meetings and presentations for extended periods.
  • Work extended or irregular hours when required to support project deadlines, security assessments, cybersecurity incidents, system implementations, or other mission requirements.

Quivera Enterprises LLC and its subsidiaries are 100% tribally owned and SBA-certified Small Disadvantaged Businesses. We are proud to be an Equal Opportunity Employer and are committed to creating an inclusive workplace where all qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.

As a tribally owned organization, Quivera Enterprises and its subsidiaries may apply Indian Preference in accordance with applicable tribal, federal, and contractual requirements where authorized by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer-Senior
Security Engineer-Senior

Quivera Enterprises, LLC • Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Engineer-Senior
Security Engineer-Senior

Quivera Enterprises, LLC • United States

On-site
USD 120,000 - 160,000
InfoSec Engineer III
InfoSec Engineer III

Quivera Enterprises, LLC • Northern (KY)

Hybrid
USD 90,000 - 140,000
Equal opportunity employer
Tribally owned
Cybersecurity Engineer Lead
Cybersecurity Engineer Lead

Quivera Enterprises, LLC • Reston (VA)

On-site
USD 120,000 - 170,000
Cybersecurity Analyst Senior
Cybersecurity Analyst Senior

Quivera Enterprises, LLC • Albuquerque (NM)

On-site
USD 110,000 - 150,000
Equal Opportunity Employer
Tribally owned company
Cybersecurity Analyst Senior
Cybersecurity Analyst Senior

Quivera Enterprises, LLC • Reston (VA)

On-site
USD 120,000 - 180,000
Cybersecurity Administrator Senior
Cybersecurity Administrator Senior

Quivera Enterprises, LLC • Albuquerque (NM), Northern (KY)

Hybrid
USD 120,000 - 150,000
Cybersecurity Administrator
Cybersecurity Administrator

Quivera Enterprises, LLC • Albuquerque (NM)

On-site
USD 110,000 - 150,000
Cybersecurity Engineer
Cybersecurity Engineer

Quivera Enterprises, LLC • Albuquerque (NM)

On-site
USD 110,000 - 150,000
Cybersecurity Analyst
Cybersecurity Analyst

Quivera Enterprises, LLC • Albuquerque (NM)

On-site
USD 85,000 - 120,000