Get more replies from employers
Send a job-specific resume in minutes.
Since our founding in 2012, APTNEXUS has empowered federal agencies and commercial enterprises to navigate the complexities of the digital landscape. As a quality‑driven small business, we specialize in the seamless delivery of IT modernization and elite cybersecurity solutions. We help our clients modernize and fortify their technology stacks, ensuring their most critical data and assets remain resilient, optimized, and secure in an evolving threat environment.
Must be eligible for a Public Trust clearance. An active Treasury Minimum Background Investigation (MBI) is required or must be obtainable. Active MBI is strongly preferred.
APTNEXUS is seeking a Senior IT Project Manager – Cybersecurity Compliance to support our contract with the U.S. Department of the Treasury. In this critical role, you will serve as the primary project manager responsible for directing and coordinating all aspects of cybersecurity compliance activities for the Treasury customer. You will lead a highly skilled team of cybersecurity professionals responsible for ensuring the customer’s information systems maintain compliance with federal mandates, including FISMA, NIST Risk Management Framework (RMF), and Treasury‑specific cybersecurity policies. The ideal candidate brings deep expertise in cybersecurity governance, risk, and compliance (GRC) within a federal environment and possesses both the PMP and CISSP certifications. Your job responsibilities will include:
Bachelor’s degree in Computer Science, Information Technology, Business, or Management from an accredited institution with 10 or more years of progressively responsible experience in IT project management.
Active PMI Project Management Professional (PMP) certification – REQUIRED. Active ISC2 Certified Information Systems Security Professional (CISSP) certification – REQUIRED. Minimum of 10 years of IT Project Management experience, with at least 5 years managing cybersecurity compliance programs in a federal government environment. Demonstrated experience managing FISMA compliance programs, including A&A activities, SSP development, SAR preparation, and POA&M tracking for federal information systems. In‑depth working knowledge of NIST Special Publications, including SP 800‑37 (RMF), SP 800‑53 (Security and Privacy Controls), SP 800‑137 (Continuous Monitoring), and related FIPS publications. Experience managing cybersecurity compliance contracts for U.S. Department of the Treasury or equivalent federal agencies is strongly preferred. Experience overseeing IT General Controls (ITGC) assessments in support of Financial Statement Audits and A‑123 compliance reviews. Proven ability to manage Time & Materials (T&M) and Firm‑Fixed‑Price (FFP) contracts, including financial management, staffing, and performance reporting. Awareness of Federal Acquisition Regulation (FAR), Treasury Acquisition Regulation (TAR), and federal contracting compliance requirements. Familiarity with Treasury Directives and Publications along with Treasury Security policies governing cybersecurity across Treasury bureaus. Experience with GRC tools and platforms (e.g., Archer, CSAM, XACTA, ServiceNow GRC) for managing system authorization packages and continuous monitoring workflows. Strong analytical and problem‑solving skills with the ability to manage multiple competing priorities, complex issues, and high‑priority deadlines. Demonstrated ability to effectively communicate with senior and executive‑level government officials, both verbally and in writing. Proficiency in preparing professionally formatted deliverables using Microsoft Office Suite (Word, Excel, PowerPoint, Visio). Willingness to work onsite at the customer’s facility in Washington, DC as required per contract.
Experience managing cybersecurity programs at U.S. Department of the Treasury bureaus (e.g., IRS, OCC, FinCEN, BFS). Knowledge of industrial control systems (ICS) / operational technology (OT) cybersecurity standards (e.g., NIST SP 800‑82) relevant to Treasury bureau operations. Familiarity with FedRAMP authorization processes for cloud‑hosted systems.