Cyber Security Project Manager Level I
Blackwatch International
Blackwatch International Corporation (Blackwatch) is a small business founded in 2010 and dedicated to supporting Federal business and national security objectives. Our headquarters are in McLean, VA, with satellite offices in Sacramento, CA.
Blackwatch invests in innovation and quality for our customers and staff, holding corporate-level ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 and CMMI Level 3 certifications. We are a leading provider of information technology (IT) infrastructure, cybersecurity, DevSecOps, data exploitation, and engineering services, specializing in large and complex projects. Blackwatch is dedicated to growth and offers a dynamic working environment with multiple opportunities for advancement.Position Description: Oversees small IT related projects involving cybersecurity services and solutions. Responsible for developing the Project Management plans and other contract documents. Directs the day-to-day efforts of technical personnel. Ensures the quality of deliverable cyber documentation, software, engineering and testing plans, or network installations. Monitors activities under the contract to ensure that all activities are executed in accordance with contract requirements and the COR's direction. Possesses and applies expertise on multiple complex work assignments. Assignments may be broad in nature, requiring originality and innovation in determining how to accomplish tasks. Operates with appreciable latitude in developing methodology and presenting solutions to problems. Contributes to deliverables and performance metrics where applicable. Position Title: Cyber Security Project Manager Level I Position Location : On-site in Alexandria, VA; remote (if authorized) Position Type : Regular
Years of experience : 3 Security Clearance : Public Trust
US Citizenship Required : Yes, must have Real ID Summary The scope of work for effort includes infrastructure Hosting (On-premise internal cloud only) - Compute support provides vital services in the provision and maintenance of those resources through a focus on the workflows and methodologies of how compute is created, maintained, and recaptured to deliver timely compute resources to customers, faster, and right sized while ensuring products stay secure and stable. Compute services provide engineering, and security and operations maintenances support for Server Operating Systems, as well as, requirements analysis and design, to ensure adherence to standards & policies for any USPTO Product or Component. Objectives: Security Operations Information Assurance, RMF A&A, and documentation
- Combined scope: Provide NIST-based IA governance, full RMF A&A lifecycle support (Categorize → Authorize → Monitor), and produce/update required artifacts (SSP, PTA/PIA, CAW, FIPS-199, PIAs, Contingency Plans, and associated A&A artifacts where applicable).
- Rationale: RMF activities and IA documentation are tightly coupled-same knowledge, same deliverables.
- Acceptance criteria / metrics: SSP and associated artifacts updated within 30 calendar days of change; A&A artifacts produced for all major systems within 5 business days when requested.
- Combined scope: Perform vulnerability/compliance scan analysis, false-positive validation, REGEX/signature tuning, root-cause analysis, prioritization (KEV-first), and feed findings into POA&Ms and remediation actions. Track vulnerability lifecycle to ensure vulnerability closure ≤180 days unless exception approved.
- Rationale: Scan analysis, signature tuning, and KEV remediation are one continuous remediation workflow.
- Acceptance criteria / metrics: Help ensure at least 50% of KEVs remediated by associated CISA deadlines; For non-KEVs help ensure vulnerabilities are closed within timeframes dictated in the Vulnerability Management Policies; false-positive suppression documented with expiry.
- Combined scope: Maintain and update security configuration baselines for OS/network/middleware/databases; align with CIS/STIG/DISA; perform impact analysis and coordinate deployment of baseline changes with the OCISO Enterprise Scan Team. Time to notify OCISO Enterprise Scan Team should be within 15 calendar days of security configuration baseline release.
- Rationale: Baseline creation, STIG/CIS adoption, and coordination with scanning are the same change management activity.
- Acceptance criteria / metrics: Security Configuration Baselines should be at least 90% compliant to the associated DISA or CIS benchmark; time-to-deploy new benchmark ≤ 45 calendar days from approved release to OCISO scan policy change.
- Combined scope: Implement and support IdAM (e.g., Okta), Privileged Access Management (CAPAM or equivalent), and CDM program technical integration; produce integration runbooks and control evidence.
- Rationale: IdAM, PAM, and CDM are identity/credential posture functions that share controls and evidence requirements.
- Acceptance criteria / metrics: Integration runbook delivered; % of high-risk privileged accounts under vaulting/policy; CDM dashboard metrics updated per schedule.
- Combined scope: Support RMF/FedRAMP-tailored A&A for cloud systems, produce cloud responsibility/control matrices, collect cloud-native evidence, and maintain continuous monitoring for cloud environments.
- Rationale: Cloud A&A and cloud control mapping are a single domain of work and require different deliverables but the same ownership.
- Acceptance criteria / metrics: Cloud A&A packages
- Combined scope: Operate and integrate scanners and security tools (Tenable/DBProtect/HP WebInspect, CSAM repo), maintain detection rules and regex for signatures, provide scripting support (Linux/Windows/Python/PowerShell), and integrate network devices (Cisco/Juniper) and IPv6 assessments.
- Rationale: Tool operations, automation, tunings, and scripting are continuous SOC/scan support functions.
- Acceptance criteria / metrics: Tools and scans run per schedule; automation scripts stored in repo with versioning; mean time to validate scan findings. Assist Product Teams to integrate with Reference Pipeline.
- Combined scope: Maintain POA&M lifecycle (intake→assign→remediate→verify→close), provide remediation planning and translation for technical leads, and deliver training and job aids for sustainment.
- Rationale: POA&M administration and knowledge transfer are part of remediation operations and change acceptance.
- Acceptance criteria / metrics: POA&M aging distribution; 60% POA&Ms closed on schedule; number of training sessions and job aids delivered.
- Combined scope: Provide incident triage, forensic collection guidance, containment/eradication support, and follow-up lessons learned that feed POA&Ms and baselines.
- Rationale: Incident response is discrete but tightly linked to remediation and baseline updates.
- Acceptance criteria / metrics: Rally artifact coverage for security work; sprint predictability and throughput metrics; At least 90% data call submission timeliness.
- Combined scope: Provide Scrum Master services, create Rally artifacts for POA&M and remediation work, manage sprints/epics/stories, and support USPTO data calls with timely, quality submissions and SME coordination.
- Rationale: Agile management, reporting, and data-call delivery are governance and transparency functions supporting technical work.
- Acceptance criteria / metrics: Rally artifact coverage for security work; sprint predictability and throughput metrics; At least 90% data call submission timeliness.
- Combined scope: Monitor and assess DHS/OMB memos, CISA BODs, and other directives; map to controls and operational actions; track and report compliance status and exceptions.
- Rationale: Agile management, reporting, and data-call delivery are governance and transparency functions supporting technical work.
- Acceptance criteria / metrics: New BOD/memo assessed within 15 calendar days; compliance register updated; exceptions documented and approved.
- Developing the Project Management plans and other contract documents
- Directing the day-to-day efforts of technical personnel.
- Ensuring the quality of deliverables: cyber documentation, software, engineering and testing plans, or network installations.
- Monitors activities under the contract to ensure that all activities are executed in accordance with contract requirements and the COR's direction.
- Support of Operations Security and Remediation Team's role providing technical advice and National Institute of Standards and Technology (NIST) based information assurance governance guidance.
- Strong Knowledge of the NIST Risk Management Framework (RMF) to perform technical support for annual Assessment and Authorization (A&A) security assessments performed by Office of the Chief Information Security Officer (OCISO).
- Strong Understanding of all the NIST RMF Assessment and Authorization (A&A) documents and how to use the following but not limited to: Privacy threshold analysis (PTA), Privacy Impact Assessment (PIA), Control Assessment Worksheet (CAW), E-Auth, FIPS 199.
- Transfer of Knowledge on managing Plans of Actions and Milestones (POA&Ms) for weakness remediation.
- Strong Knowledge of the Department of Homeland Security (DHS) and the Office of Management and Budget (OMB) memo/Binding Operational Directives (BODs) impact assessment.
- Group to develop, update, and manage, cybersecurity documentation: System Security Plans, Privacy Assessments, Contingency Plans, Federal Information Processing Standard Publication 199 (FIPS-199) categorization changes Security Impact Assessments, etc.
- Perform Technical support for Department of Homeland Security (DHS) initiatives that require implementation (such as Continuous Diagnostics and Mitigation (CDM) using Okta and Certificate Management-Privileged Access Management (CA-PAM).
- Analyze vulnerability and compliance scans for false positive identification and evaluate in terms of operational system data in coordination with Product Team Leads.
- Track and establish cause of vulnerabilities that are precise but no more than 180 days.
- Review/Update/Create system security configuration baselines - revise as necessary as the Center for Internet Security (CIS) and Security Technical Implementation Guides (STIG).
- benchmarks are updated and coordinate changes with associated OCISO Enterprise Scan Team's compliance configurations upon three days of release.
- Support teams to define and prioritize actionable timely recommendations for addressing compliance and vulnerability issues for network, operating systems, middleware, databases, and application. With experience leading remediation of Known Exploitable Vulnerabilities (KEVs).
- Strong Understanding of the Federal Information Security Modernization Act (FISMA) systems, and National Institute of Standards and Technology (NIST) controls and support on how to implement them - potentially how to automate them whether through process, NIST OSCAL programming or other common scripting languages (e.g. Python).
- In depth knowledge with networking, operating system, and middleware builds (configuration baselines).
- In depth knowledge with CLOUD and Federal Information Security Management Act (FISMA) processes to include customer control metrics security tools and options.
- Provide support with the Regular Expression (REGEX) for understanding/editing scan signatures.
- Provide support, oversight, review, log data, network operation and security, and analysis for the following but not limited to: Scripting for Linux, Windows, Tenable, DBProtect, HP WebInspect, CSAM (the official cybersecurity repository), Juniper, CISCO, advance tools, IPv6.
- Cloud security: to manage Assessment and Authorization (A&A) work for those systems
- Use Rally to manage Epics, Features, and User Stories; provide Scrum Master services to create Rally artifacts and Agile documentation; translate Plan of Action and Milestones (POA&M) findings into clear, actionable guidance for technical leads and track remediation progress in Rally.
- Supporting USPTO Data Calls and ensuring timely and completed submission, collaborating with subject matter experts.
- Support incident response activities with Enterprise Operations Command Center.
- Support new tools as required.
- Experience with Rally and agile ceremonies.
- Python coding
- Experience using the Cybersecurity Asset Management (CSAM) system for customer base.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Cyber Security Project Manager Level I in McLean, VA vacancy
- ...Mid-Level Project Manager / Scrum Master Our client is seeking a Mid-Level Project Manager / Scrum Master to support enterprise data initiatives within a fast-paced delivery environment. This role is ideal for candidates with hands-on Agile project coordination experience...SuggestedLocal area
$144.9k - $265.8k
...Cybersecurity - Splunk Manager From strategy to execution... ...mission. The project includes continued enhancement... .... Splunk enterprise security, security incident and... .../development Cyber threat analysis, security... ...have an active Top Secret-level clearance or higher ~...SuggestedFor contractorsPrivate practiceSummer holidayWork at officeLocal areaImmediate startFlexible hours- ...Job Description Description: Senior Project Manager At B&A, we foster and embrace a distinct... ...and communicating with SES and Flag-level personnel Demonstrated ability to... ...Professional (PMP) certification required Security Clearance ~ Active Secret security...SuggestedFull timeContract workWork at officeLocal area
- ...and trust, we increase mission success for war-fighters and secure our nation for a better future. We are privately held, are... ...success. Credence has an immediate need for a Mid-level Capture Manager who will create and implement a defense and military strategy...SuggestedTemporary workImmediate start
$85k - $105k
...development pipelines to finance renewable energy projects with our partners. The Assistant Project Manager ("APM") role at MEI provides support to our Project... .... Compliance Monitoring: Support project-level compliance and incentive program execution by preparing...SuggestedTemporary workFor subcontractorWork at office- ...teamwork, and personal development! We are seeking enthusiastic and motivated individuals to step into the role of Entry-Level Client Success Manager. This is your chance to make a meaningful impact while growing your skills alongside a passionate team. **What You’...Weekly pay
- ...Senior Project Manager As Senior Project Manager, you will be part of a leadership team dedicated... ...of all parties involved Secure required permits and verify insurance coverage... ...kinds of weather and moderate to loud noise levels, and comfortable in elevated or confined...Contract workFor contractorsWork experience placementFor subcontractorWork at office
$77.6k - $176k
...Naval Project Manager The Opportunity: As a project management spe cia list, you know... ...civilians, all while ensuring consistent high-level product delivery to the APM. The... ...selected will be subject to a security investigation and may need to meet eligibility...Full timeContract workPart timeWork at officeLocal areaRemote work$146k - $234k
...Microsoft Dynamics 365 Project Manager Location: New York City, Washington DC - McLean The Protiviti Career provides opportunity to learn... ...our mission: We Care. We Collaborate. We Deliver. At every level, we champion leaders who live our values of integrity, inclusion...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours- ...Project and Program Comms Lead- AI and Marketing – Marketing will support client's Marketing... ...coordinating cross‑functional AI pilots, managing operating rhythms, synthesizing insights,... ...concise weekly summaries and executive‑level readouts Develop presentations, status...For contractors
$60 - $63 per hour
...Immediate need for a talented Project Manager (Mortgage). This is a 06+months contract opportunity with long-term potential and is located... ...skills with the ability to communicate across all levels of the organization, including executive leadership ~ Strong...Contract workLocal areaImmediate start$190k - $205k
...Capital Projects Manager Park Hotels & Resorts invests not only in properties, but also in people. We attract visionary and collaborative... ...further by joining a place that's powered by people. Enjoy a level of loyalty and comfort that inspires career fearlessness and...Contract workFor contractorsWork experience placementLocal area- ...Description: NDi is Seeking a Strong Program Manager with in-depth experience leading... ...per year to Philadelphia, PA for team or project coordination. Qualifications and... ...particularly within IT operations and network security. Excellent communication skills,...For contractors
- ...Senior Information System Security Officer Join our team at Core... ...a new application development project in the IC. This position requires... ...of security incidents. Manage account recertifications, access... ...awareness training at the system level. Serve as the primary...
$140k - $160k
...Information Systems Security Officer (ISSO), Mid (MCSES... ...Category IT / Cyber Security / Network Systems... ..., maintain a high level of operational availability... ...Systems Security Managers (ISSM), Program Security... ...and to ensure assigned projects deliver desired results...Full timeFor contractorsRemote work- ...Information System Security Officer LOCATION Tysons, VA 22182... ...compliance with security policies, and managing risk through the... ...Manager, Security Risk Analyst, Cyber Risk Manager, Security Architect... ...Security Engineer, etc. DEGREE (Level Desired) Bachelor's Degree...Temporary workFor contractorsImmediate startFlexible hours
$90k - $140k
...Senior?Information Systems Security Officer (ISSO) on our... ...that ensure the level of security documented... ...assist in the effective management of?system risks Conduct... ...degree and 4 years of cyber & FISMA experience; OR... ..., and experience. The projected compensation range for...Local areaFlexible hours- ...government. Federal Information System Security Officer (ISSO) Location: McLean, VA... ..., CMMC, RMF) into actionable system-level controls and implementation guidance... ...evidence collection, reporting, and risk management tracking Assist in security briefings...
- ...Project Controller **Must have SECRET clearance, proficiency in QuickBooks and experience... ...to assist in the direction and management of program's executive support group. The... ...and finance as part of a team. Upper-level professional capable of fulfilling the project...Contract workFor contractorsFor subcontractorRemote work
- ...Providing interpretation of contract terms and conditions to management and other functional groups. Identifying and managing contract... ...Excellent interpersonal skills; ability to work with a team at all levels of an organization, including ability to effectively interact...Full timeContract workWork at office
- ...Information Systems Security Manager (ISSM) Location: McLean, VA Clearance: TS/SCI... ...Managers (ISSMs) across multiple discipline levels to oversee the cybersecurity of... ...will safeguard critical systems, manage cyber risks, and ensure compliance to protect...
$187.3k - $213.7k
...Director, Project Manager, Debit Products Capital One, a Fortune 500 company and one of the nation's top 10 banks, offers a broad spectrum... ...governance forums, portfolio reviews, and executive-level reporting to enable transparency, informed decision-making, and...Full timePart timeLocal area- ...Service Coordinator - Multi Levels Location: McLean, VA JMark... ...Lead (TPL) to support knowledge management initiatives. Provide... ...internships, or mission-related projects. Why Join JMark? At JMark... ...grow your career in national security support. JMark Services Inc....InternshipWork at office
$119.1k - $239.3k
...Government Contracting team within the Management Consulting practice provides specialized... ...contracting solutions, managing teams to deliver projects on time, on budget, and in line with... .... RSM does not intend to hire entry level candidates who will require sponsorship...Contract workFor contractorsWork experience placementInternshipLocal area$81k - $120k
...and teamwork? At Ntiva, we’re more than a Managed Services Provider, we’re a community... ...the senior technical advisor for high-risk security remediation, planned security infrastructure... ...What you will be doing Provide senior level technical recommendations and execution...Contract workTemporary workRemote work- ...Senior Cyber Access Analyst The Space and Intelligence Division provides professional... ...Joint Warfare Analysis Center (JWAC), Space Security and Defense Program (SSDP), National... ...operational, Combatant Command and national levels ~ Extensive working knowledge of Very...Full timeWork at officeLocal areaImmediate startLong distance
- ...: Contract Job #3080 0Title: Cyber Security Analyst Location: McLean, VA *Clearance... ...and nation-state organizations Manage, share, and receive intelligence on APT... ...of the current security threat level by monitoring related Internet postings,...Contract workWork at officeShift work
- ...Description: Program/Contract Manager Location: Defense Health Agency Headquarters... ...Region Military Treatment Facility. Project Management Professional (PMP)... ...within the National Capital Region. Senior-level federal contractor salary commensurate with...Full timeContract workFor contractorsFor subcontractorWork at officeLocal areaRemote workWorldwideMonday to Friday
$150k - $220k
...capabilities are our top-tier program and project management, data analytics, and audit services,... ...decisions; build durable relationships at all levels. Thrive in an autonomous, empowering... ...rates, and promotes your financial security and personal well-being. The annual...Temporary workWork experience placement- ...Senior Technical Project Manager - TS/SCI with Polygraph Required Job Locations... ...deep technical implementations with high-level, non-technical leadership to connect solutions... ...experience with architecture, security, cyber and data infrastructure TS/SCI with...Full timeFor contractorsLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Project Manager Level I. Be the first to apply!
Related searches
- aerospace project manager McLean, VA
- national project manager McLean, VA
- entry level pmp project manager McLean, VA
- project manager government McLean, VA
- power generation project manager McLean, VA
- project manager hospitality McLean, VA
- project manager science McLean, VA
- localization project manager remote McLean, VA
- office furniture project manager McLean, VA
- onsite project manager McLean, VA



