ASRC Federal Data Network Technologies
Posted 5d ago

Cybersecurity Program Manager

ASRC Federal Data Network Technologies
Reston, Virginia, United States
RemoteFull Time
Responsibilities
  • leading RMF activities
  • assessing security risks
  • coordinating remediation
Requirements
  • Bachelor's degree and 5–7 years in cybersecurity
  • Information assurance, RMF, or information system security. Requires federal cybersecurity and NIST RMF experience plus CISSP and CGRC or CCSP certification
Technical tools mentioned
NIST Risk Management Framework (RMF)NIST SP 800-37NIST SP 800-53FISMAFIPS 199Governance, Risk and Compliance (GRC)DevSecOps

Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™

ASRC Federal Data Networx is seeking a Cybersecurity Program Manager to oversee federal cybersecurity program.

Work Location: Remote

Key Responsibilities

  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.
  • Perform independent quality assurance reviews of program performance and deliverables to ensure that contractual obligations are being met.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.
  • Expertise in cybersecurity processes and protection of technical architecture.

Required Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.


EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

About ASRC Federal Data Network Technologies

Providing technology, engineering, and infrastructure solutions for federal missions.

Similar jobs

Cybersecurity Program Manager roles near Reston, Virginia
5d
Save
Mark Applied
Hide
Enterprise Cybersecurity Program Manager, Lead
McLean, Virginia, United States
$99k-$225k/yr HybridFull Time, Part Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
7+ years project management in cybersecurity or IT, 5+ years leading technical cybersecurity projects, executive communication experience, Agile and waterfall expertise, bachelor's degree, and PMP or CompTIA Security+ certification.
Jira, ServiceNow, Smartsheet, Confluence, Microsoft Word, Microsoft SharePoint, Microsoft PowerPoint, Microsoft Excel, Microsoft Teams
5d
Save
Mark Applied
Hide
Enterprise Cybersecurity Program Manager, Lead
McLean, Virginia, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
7+ YOERequires 7+ years of cybersecurity or IT project management, 5+ years leading technical cybersecurity projects, a bachelor's degree, and PMP or CompTIA Security+ certification. U.S. citizenship required.
Jira, ServiceNow, Smartsheet, Confluence, Microsoft Word, Microsoft SharePoint, Microsoft PowerPoint, Microsoft Excel, Microsoft Teams
1w
Save
Mark Applied
Hide
Cybersecurity Program Manager
Bethesda, Maryland, United States
$150k-$165k/yr HybridFull Time
Gunnison Consulting Group
Gunnison Consulting Group: Private federal IT consulting firm delivering cybersecurity, digital services, and intelligence solutions to U.S. government agencies.
5+ YOE5+ MgmtRequires 5+ years managing cybersecurity or enterprise IT programs, a technical bachelor's degree, PMP, CISSP, ITIL, team leadership, cloud and network security experience, and ability to obtain Public Trust.
Microsoft SharePoint
2w
Save
Mark Applied
Hide
Cybersecurity Program Manager
Laurel, Maryland, United States
$180k-$230k/yr RemoteFull Time
ERP International
ERP International: Private U.S. federal contractor providing military healthcare staffing, medical logistics, IT modernization, and business-process services.
8+ YOE5+ MgmtBachelor's degree and 8+ years supporting federal, cybersecurity, modernization, or transformation programs, including 5+ years in program or project management. Must obtain government public trust clearance.
Agile
3w
Save
Mark Applied
Hide
Senior Cybersecurity Program Manager (DC, Washington)
Washington, District of Columbia, United States
OnsiteFull Time
RiVidium
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
15+ YOEActive TS/SCI clearance, PMP and CISSP or CISM, 15+ years managing large IT/cybersecurity programs, bachelor\u0002s degree required, EM environments experience, strong governance and risk management skills.
JIRA, Confluence, Microsoft Teams, IT Service Management (ITSM)
2mo
Save
Mark Applied
Hide
Cybersecurity Program Manager
Washington, District of Columbia, United States
$160k-$230k/yr OnsiteFull Time
TestPros
TestPros: Independent IT compliance firm serving federal, commercial, and enterprise organizations with cybersecurity, accessibility, and privacy assessments.
10+ YOEBachelor's degree, 10+ years managing federal cybersecurity programs/contracts, oversight of RMF/ATO/continuous monitoring/vulnerability management, experience managing budgets and staff, strong leadership and communications, active Secret clearance required.
Tenable/Nessus, ACAS, Qualys, Rapid7, Splunk, AWS, Azure, GovCloud, NIST Risk Management Framework (RMF), NIST 800-53, NIST 800-37, FISMA, FedRAMP, DHS CDM
4mo
Save
Mark Applied
Hide
Cybersecurity Program Manager (AI Driven EASM & CTI Lead) (MD, Baltimore)
Baltimore, Maryland, United States
OnsiteFull Time
CyberLinx Solutions
CyberLinx Solutions: Service-disabled veteran-owned IT provider delivering cybersecurity engineering and mission-critical services to federal and defense agencies.
Lead EASM and CTI programs; manage stakeholders; govern programs; oversee AI-driven security services and vendor relationships.
AI, Threat Intelligence, EASM, Digital Risk Protection, Security Tools
4y
Save
Mark Applied
Hide
Cybersecurity Program Manager (93394)
Vienna, Virginia, United States
OnsiteFull Time
NetApp
NetAppNASDAQ: NTAP: Global cloud-led, data-centric software.
7+ YOELead and manage cybersecurity compliance programs (NIST 800-171, FAR/DFARS), drive assessments, handle government incident reporting, advise on contract terms, and collaborate with stakeholders; requires PMP and CISSP and 7+ years program/cybersecurity experience.
Microsoft Office, Microsoft Word, Microsoft Access, endpoint detection and response, firewalls, network intrusion detection, packet capture, data loss prevention, vulnerability scanning, proxy appliances, event collection tools, proprietary databases