About the Role
We are modernizing our vulnerability management program to meet the FedRAMP 2026 Vulnerability Detection & Response (VDR) and Vulnerability Evaluation & Reporting (VER) requirements, which become mandatory December 7, 2026 under CISA BOD 26-04.
This is a high-visibility, deadline-driven program touching security engineering, DevOps, GRC, and executive stakeholders.
The Technical Project Manager serves as the connective tissue across all workstreams — an overlay resource who keeps four specialized engineers, internal platform teams, and business stakeholders aligned and moving toward a fixed regulatory deadline.
Responsibilities
- Own day-to-day program management for a ~16-week implementation with a fixed, non-negotiable compliance cutover date
- Serve as the primary liaison between the implementation team, internal security/platform/DevOps teams, and business stakeholders; run weekly steering sessions and executive readouts
- Build and maintain the integrated project plan across two parallel workstreams (platform/integration build and evaluation/reporting/controls), tracking dependencies, milestones, and the critical path to the December 7 deadline
- Track SLAs, risks, and blockers; escalate early and drive resolution across teams that don''t report to you
- Coordinate access, environments, change windows, and internal approvals so engineers stay unblocked
- Manage scope against the ~22 VDR/VER requirements; maintain a control-to-requirement traceability view of "done"
- Coordinate the parallel-run and cutover from the legacy scanning toolchain to the new consolidated platform, including training and handoff to internal teams
- Prepare status reporting suitable for both engineering audiences and executive/audit audiences
Required Qualifications
- 5+ years of technical project/program management experience delivering infrastructure, security, or platform engineering projects
- Demonstrated success delivering projects with hard external deadlines (regulatory, contractual, or launch-driven)
- Ability to work fluently with engineers — comfortable discussing CI/CD pipelines, API integrations, cloud environments, and scanning tools at a working level
- Strong stakeholder management: experience aligning security, engineering, and business leadership with competing priorities
- Excellent risk management instincts; a track record of surfacing problems weeks before they become schedule threats
Strongly Preferred
- Direct experience with FedRAMP programs (ATO processes, 3PAO assessments, continuous monitoring, POA&M management) or other federal compliance frameworks (FISMA, CMMC, StateRAMP)
- Prior delivery of security tooling implementations (vulnerability management, SIEM, CNAPP, ASPM/aggregation platforms)
- Familiarity with the 2026 FedRAMP VDR/VER rule changes and CISA BOD 26-04
- PMP, PMI-ACP, or equivalent; experience running hybrid onshore/offshore delivery teams